Apple plans to add new limits to the Full Disk Access permission on macOS, saying the broad system-level grant poses a growing danger as AI agents become more capable. The company outlined the move in an update on Friday, according to The Verge, which reported the change earlier.
Full Disk Access is a macOS permission that lets an application reach a user's entire system. Apple says the feature was originally built so that backup apps could work properly on the Mac, and that it "largely sidesteps" the privacy controls the operating system otherwise offers users.
In its statement, Apple said some developers are using Full Disk Access in ways that could expose everything on a user's machine — files, mail, messages and browsing history — without the user's full knowledge and understanding. The company framed the tightening as a way to ensure that people who genuinely want to grant an app that level of access can only do so through very explicit user action.
Apple tied the change to AI agents. According to the company, the risks associated with this level of access will grow substantially as those agents become increasingly capable and autonomous. The statement does not elaborate on what specific agent behaviors prompted the concern.
According to The Verge's account, the announcement came not long after Jason Aten of Inc published a report. Aten's findings indicated that Muse AI, made by Meta, had knowledge of what his messages contained, despite the fact that on his iPhone or Mac he had never granted the chatbot explicit permission to reach them.
That report drew a rebuttal from Andy Stone, a Meta spokesperson. Muse can only read Messages content, he said, if a user turns on the Messages connector along with Full Disk Access, since access to Messages is "entirely opt-in." The Verge's report contains both the original discovery and Meta's response.
Apple has not said when it intends to roll out the update for Full Disk Access, and the company did not immediately respond to The Verge's request for comment. That leaves the practical shape of the change — whether it applies to new permission grants, existing ones, or both — undocumented in the available reporting.
For freelancers and developers who build or rely on Mac tooling, the significance is straightforward: Full Disk Access is the permission that lets utilities index files, sync folders, back up data or read message and mail stores. Any tightening of how it is granted can change onboarding flows, support scripts and setup documentation for apps that depend on it.
The stated rationale is not that Full Disk Access is being removed, but that the path to obtaining it should require deliberate, explicit consent. Apple's wording puts the emphasis on the moment of granting rather than on revoking the capability outright, though the company has not described the mechanism it will use.
There is also an unresolved question about scope. Apple's statement refers generally to "some developers" using the permission in risky ways, without naming them or describing specific behaviors. The Verge's account does not establish that any particular app violated Apple's rules, and Meta disputes the characterization of the Muse episode.
The timing is notable because it follows public reporting about an AI assistant apparently reaching message content, but the evidence supplied here does not establish that Apple's policy change was caused by that episode. The two events are close in time; the reporting does not document a causal link, and Apple's statement does not mention Meta or Muse by name.
For designers and developers shipping Mac software, the practical planning implication is to treat Full Disk Access as a permission that may soon demand a more deliberate user decision. Teams that currently instruct users to flip the setting during setup should expect that instruction to need clearer justification and possibly a different flow, though the exact requirements remain unknown until Apple publishes them.
Backup and sync tools are the category Apple itself cites as the original justification for the permission. If the grant becomes harder to obtain, those apps face the most immediate friction, since their core function depends on reading data across the system rather than within a sandboxed container.
What remains unknown is substantial: the rollout date, the technical mechanism, whether existing grants are affected, and how Apple will distinguish legitimate backup and utility use from the riskier patterns it describes. Apple's statement also does not say whether developers will get new APIs, prompts or review requirements to accompany the change.
The Verge's piece also notes that Apple did not immediately respond to a request for comment, so the company's position is drawn from its written update rather than from follow-up answers. Readers should treat the specifics of enforcement as unsettled until Apple documents them.
The broader signal for this audience is that a major platform vendor is treating AI agents as a distinct permission risk rather than as ordinary apps. Apple's language about capability and autonomy suggests the concern is not only what an app reads today, but what an agent might do with that access later.
Until Apple publishes details, the responsible reading is narrow: a major platform owner has said it will restrict how the broadest macOS permission is granted, has given a rationale centered on AI agents, and has not said when or exactly how. Everything beyond that — timelines, affected apps, migration behavior — is not yet supported by the available evidence.