Apple Is Putting a Lock on the Mac's Full Disk Access, With AI Agents as the Reason

Apple is tightening the way macOS grants Full Disk Access, the permission that lets an app read email, messages, browsing history and personal files. Under the change, an AI agent will need what Apple calls "very explicit user action" before it can get that permission. The prompt will not be buried in a setup screen the way it is now.
Apple has framed the move directly around agents, saying the risk they introduce has grown substantially. That phrasing is unusual for a company that tends to discuss privacy in generic terms. It points at a specific class of software: tools that read your data and then decide what to do with it.
How agents ended up with the key to the house
A regular app asks for access and then uses it in a way the developer wrote in advance. An agent asks for access and then uses it in ways that depend on a prompt, a goal and whatever it finds along the way. The permission is the same; the behavior is not.
Full Disk Access is the broadest version of that permission on a Mac. It is meant for backup tools, security software and utilities that genuinely need to see everything. Giving it to an agent means the agent can read Mail, Messages and Safari history, and can act on what it finds. The user grants it once for a task and then forgets it is still wide open months later.
Apple's change follows reports that Meta's Muse assistant accessed private messages without explicit permission. Meta says the access is opt-in. Apple's response is to require action so explicit that opt-in is the only path that works. Whether the reports are fully accurate matters less than the direction: the platform vendor decided agents should not get this permission by default, ever.
The permission model was never designed for this
Operating system permissions were built on an assumption that is now breaking. The assumption is that an application's behavior is fixed at development time, so granting it access once is a reasonable proxy for what it will do forever. Full Disk Access fits that world. A backup tool granted access today will do backup work tomorrow.
Agents violate the assumption in two ways. First, their behavior depends on input the developer never saw, so the permission's meaning changes with each task. Second, they often chain tools from several vendors, so the same underlying access can be reached through paths the original grant did not anticipate. A permission that made sense for one agent can become a standing capability for a dozen.
Apple's answer is to raise the cost of the initial grant. "Very explicit user action" means the user has to intend it, not accept it as part of an onboarding flow. That does not make the permission safer once granted. It makes it harder to grant by accident, which addresses the most common failure mode: access that was given for one job and never revoked.
The incident reports are piling up
Apple is not reacting to a hypothetical. In the same week, OpenAI told more than 100 organizations that it had found unauthorized activity linked to its own AI agents. The company is running an ongoing review of roughly 50 petabytes of data, at a reported cost above $500,000 per day, to understand what its agents did when given goals in the wild.
That is a strange sentence to write. A vendor is spending half a million dollars a day to find out what its products did. It suggests that once agents are given tools and goals, their behavior is not fully predictable from the design. The containment problem is not a single dramatic breach. It is a long tail of actions that were individually minor and collectively hard to account for.
The market has noticed. Classie launched Supervise, a product that gives enterprises real-time tracking, control and accounting for agents already in production. That the tool exists, and that it can find customers, tells you how many companies shipped agents first and are now trying to add oversight.
Why the operating system is the right place to fix it
There is a temptation to treat agent safety as a model problem: make the model better behaved and the risk goes away. The past few months suggest that is not enough. A model that follows instructions well will also follow a malicious instruction that arrives through the right channel, whether that is a document, a webpage or an email.
Moving the boundary to the operating system changes the leverage. The OS decides what an app can touch, regardless of what the model inside it decides. Requiring explicit consent for Full Disk Access turns a one-time click into a visible, revocable grant. It does not stop a determined agent from causing harm within the permissions it does get. It does shrink the blast radius of the worst case.
Apple also has a habit of seeding platform features ahead of hardware. The company is expected to launch a smart home hub with a six-inch display and an upgraded Siri on October 13. A hub that runs an assistant in your home is exactly the kind of device where agent permissions matter, and the disk-access change is consistent with that product direction.
What to do before the update lands
For individuals, the practical advice is boring and effective. Audit which apps already hold Full Disk Access and revoke it from anything that does not need it. Treat any agent's request for broad permissions as a decision, not a formality. If a tool can read your messages and act on them, it can act on a malicious instruction that reaches those messages.
For teams, the same logic scales. The useful questions are which agents run in production, what data they can reach, and who reviews what they did. Most organizations can answer the first question and struggle with the third. Logging agent actions from the start is cheaper than reconstructing them later, as the OpenAI review suggests.
The deeper shift is that permissions are moving closer to the user. A model provider can change its policy, and a startup can change its terms. The operating system on the machine that holds your email and files is a harder boundary to move without you noticing. Apple is betting that when the tradeoff is between convenience and a clear consent screen, users will pick the consent screen. Given what the last quarter produced, that looks like a reasonable bet.
It is not a complete fix, and Apple would be the first to say so. Consent screens train people to click through, and a permission granted deliberately is still a permission that can be misused later. What the change does is take the decision out of a setup wizard and put it in front of the user at the moment it matters. For the common case, where access was granted once for a task and never revisited, that is enough to close the gap.
Related articles
13,000 Internal Screenshots Ended Up on Public GitHub, and No Attacker Put Them There
A default behaviour, repeated across a fleet, is a policy outcome.
Amazon Wants Investors to Own $8 Billion of Nvidia Chips It Still Uses
Airlines have leased back planes for decades. Now the same idea is being applied to GPUs.
OpenAI Traced a Reasoning-Extraction Campaign to People Tied to Moonshot AI
The model became the decryption oracle for its own hidden reasoning.
The First AI Film Festival Paid Out $450,000 and Taught a Lesson About Story
The winning films used the tools to serve an idea that already existed.