Your Mac’s Full Disk Access Is About to Get Tighter

If you’ve given an app Full Disk Access on your Mac, it may be able to read nearly everything on the machine. That includes your files, mail, messages and browsing history. Apple now says that much access becomes more dangerous as AI agents get more capable. According to The Verge AI, Apple plans to limit Mac disk access because autonomous AI agents “substantially” increase the risk.

Apple’s warning is blunt. “Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems, including files, mail, messages, and even browsing history, without users’ full knowledge and understanding,” the company said, as detailed in The Verge AI. It added: “As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.”

🔐 What Full Disk Access actually is

Full Disk Access is a macOS permission you’ll find in System Settings under Privacy & Security. It lets an app skip many of the privacy walls macOS puts around sensitive data. Backup tools, antivirus software and some developer utilities have good reasons to ask for it.

The trouble is how easy it is to grant. You flip a toggle once, and most people forget about it. From then on the app can reach your most private data without asking again. That was a manageable risk when the apps were static programs doing predictable jobs.

🤖 Why AI agents change the math

I think this is the most important part of the story. A traditional app with disk access does what its code says. An AI agent decides what to do on the fly, based on prompts, context and whatever content it reads along the way.

That opens up new kinds of failure:

  • Prompt injection: An agent reading a malicious email or webpage can be tricked into following hidden instructions, such as gathering and sending out sensitive files.
  • Overreach: Agents with broad access may touch data you never meant them to use, just because it was there.
  • Opacity: Users often can’t see what an agent read, copied or sent during a task.
  • Compounding access: When an agent with full disk access also has network access, a single bad instruction can quickly turn into a data leak.

Agent-style tools have spread fast over the past year. Coding assistants, desktop automation tools and “computer use” agents all work better with deep system access, so developers have a strong reason to ask for the broadest permission available. Apple is clearly trying to step in before that becomes the norm.

📉 What changes for developers

The source doesn’t spell out the exact technical details or timeline. Still, the direction is clear. Apple wants apps to stop using Full Disk Access as an easy all-access pass.

If you build Mac software, especially anything with agent features, expect:

  • More scrutiny of why your app needs broad disk access
  • Pressure to switch to narrower, scoped permissions
  • Possible changes to how and when users get asked to grant access
  • Workflows that break if they assume unrestricted file system reads

This fits Apple’s long-running privacy playbook. The company has steadily tightened permissions on iOS and macOS, from location tracking to app tracking transparency. AI agents are just the newest reason to keep going.

🛡️ What you should do now

You don’t need to wait for Apple’s changes to protect yourself. Here’s a quick defensive checklist:

  1. Audit your list. Open System Settings, go to Privacy & Security, then Full Disk Access. Check every app that’s there.
  2. Revoke what you don’t need. If you don’t recognize an app or no longer use it, turn it off.
  3. Be careful with agents. Think twice before giving any AI tool system-wide access. Give it a specific folder when you can.
  4. Separate sensitive work. Keep agents away from machines or accounts that hold confidential client data, credentials or financial records.
  5. Watch for updates. When Apple ships the new restrictions, check which of your tools need reconfiguring.

🔭 What comes next

This likely won’t be the last move of its kind. Operating system makers are realizing that permission models built for predictable software don’t hold up well against autonomous agents. Expect Microsoft, Google and others to face the same question soon.

For developers, the message is to build agents that work with the least access they need. For users, it’s to treat every permission prompt as a real decision. You can find more details in the original report from The Verge AI.

Scroll to Top