Apple plans to tighten one of macOS’s broadest privacy permissions as AI agents make access to an entire Mac more consequential. In an October 2 notice to developers, the company said future controls will require a more deliberate user action before an app receives Full Disk Access.
The change targets a permission originally intended for software such as full-system backup tools. Full Disk Access can let an app reach data normally protected by macOS, including files, mail, messages and browsing history. Apple now argues that some developers are requesting this access in ways users may not fully understand, and that increasingly autonomous agents substantially increase the risk.
Apple has not yet identified the macOS release that will carry the controls, given a rollout date or explained exactly what the new approval flow will look like. The announcement is therefore a policy commitment rather than a feature readers can switch on today. Mac users can, however, review and reduce existing access now.

Why Full Disk Access is unusually powerful
macOS normally separates sensitive resources through its Transparency, Consent, and Control system, commonly known as TCC. An app may need individual approval to use a camera, microphone, contacts, calendars or a protected folder. Sandboxed apps are also limited to their own containers unless a user selects files or grants another scoped permission.
Full Disk Access is the exception built for workflows that cannot operate one file or folder at a time. Apple’s developer documentation uses a backup app as the canonical example: a genuine full backup must read files wherever they reside. An app cannot silently acquire the permission through an entitlement or code. The user must enable it in System Settings.
Once enabled, however, the permission cuts across many of the boundaries that make the rest of macOS’s privacy model useful. It can expose databases and application data that were never selected for the app’s immediate task. That distinction becomes sharper when software can plan actions, call tools and process large amounts of local context without the user directing every step.
An ordinary utility with excessive permissions presents a familiar data-exposure risk. An agent adds another path: untrusted text from a webpage, document, email or repository can influence what the software tries to read or send. Full Disk Access does not by itself grant network access or prove that an app is malicious, but it can greatly enlarge the material available if the app, one of its components or its instructions are compromised.
What Apple has confirmed, and what remains unknown
Apple’s notice is narrow. The company says apps should receive this “extraordinary level of access” only after very explicit user action
. It also links the change directly to the growth of autonomous AI software and warns that communication apps can expose not only the Mac owner’s privacy but also information belonging to other people.
The company has not said whether users will see an additional confirmation dialog, authenticate with Touch ID or a password, approve individual data classes, renew access periodically, or receive clearer warnings about what an app can read. It has also not explained how managed Macs, backup products, endpoint-security tools or developer utilities will be handled.
Those omissions matter. A harder confirmation step can reduce accidental approvals, but it does not solve the underlying all-or-nothing nature of Full Disk Access. The more durable answer would be for apps to rely on narrower permissions, file pickers, app integrations or isolated working directories whenever their job permits it. Apple has not promised such a redesign in this announcement.
How to audit Full Disk Access on a Mac now
Mac users do not need to wait for Apple’s future control to review which software already has the permission:
- Open System Settings.
- Select Privacy & Security.
- Open Full Disk Access.
- Review every enabled app and helper. Disable access for software you no longer use, do not recognize or cannot justify.
- Reopen apps you changed and confirm that their essential functions still work.
Removing access is a permission change, not an uninstall. A backup or security product may stop working correctly until access is restored, so users should verify its status afterward. Apple’s Mac user guide also notes that information collected by third-party apps is governed by those apps’ own privacy practices.
For an AI desktop app, the key question is specific: which feature requires visibility into the whole disk? A tool that works on one selected project folder, imports chosen documents or connects to Mail through a defined integration should be able to explain why those narrower routes are insufficient. Requests for Full Disk Access merely to make setup easier deserve extra scrutiny.
Users should also check adjacent panels in Privacy & Security. Files and Folders, Accessibility, Automation, Screen & System Audio Recording and Developer Tools can each give an agent meaningful reach. Reviewing Full Disk Access alone will not reveal the app’s complete authority.
Developers should plan for a more demanding consent flow
Apple’s announcement puts macOS developers on notice even without an API or release schedule. Apps that currently tell users to enable Full Disk Access as a catch-all workaround may face more friction and more prominent warnings. Teams should inventory the exact paths and data classes their software reads, then separate essential access from optional convenience features.
Apple’s App Sandbox documentation already points toward user-selected documents, app groups and constrained containers as alternatives for many workflows. System extensions can also move certain networking and endpoint-security functions out of legacy kernel components, though they do not eliminate the need for appropriate user approvals.
Agent developers have an additional design problem: permission at installation time is not the same as consent for every later action. A broad grant can remain in place while the model’s instructions, connected tools and data sources change. Useful safeguards include restricting agents to named workspaces, placing confirmation gates before sensitive reads or outbound transfers, logging tool activity, and keeping secrets outside an agent’s reachable directories.
A warning now, implementation later
Apple’s decision is notable because it treats desktop AI agents as a platform-security concern rather than only an app-policy issue. It also acknowledges that an existing permission model, even one that already requires manual approval, may not communicate the consequences clearly enough when software can act autonomously.
The practical response today is modest: review existing grants, remove unnecessary ones and demand a concrete explanation from any agent that asks for the whole disk. The larger test will come when Apple shows whether its new controls merely add another warning or give users meaningfully narrower choices.