By This Hour Technology Desk

Apple says it plans to tighten the way Mac applications obtain Full Disk Access, a powerful permission that can expose material across a user’s system. The company’s stated concern is that the permission’s risks will rise sharply as AI agents become more capable of acting with limited human intervention.

The proposed change would require a more deliberate and unambiguous action from the user before an application can receive Full Disk Access. Apple has not described the precise mechanics of the revised controls or said when they will arrive, leaving an important gap between its stated direction and the practical experience Mac users and software makers can expect.

The stakes lie in the unusual breadth of the permission. Full Disk Access can let an app reach well beyond the information normally compartmentalized by macOS privacy settings. Apple has said that, when used broadly, the access can put files, email, messages and browsing history within reach of an application without a user fully appreciating the consequences. In Apple’s account, the setting exists in substantial part because backup software needs that wide view of a Mac. Yet the same scope that makes it useful for that task creates an opening for software that handles far more personal material than a person intended to disclose.

A permission designed for broad access faces a different software environment

Apple’s announcement is not a claim that every app with Full Disk Access is unsafe, nor is it a declaration that such access will disappear. Its focus is the process by which users grant an exceptional level of permission. The company’s position is that people who truly want to give an app that reach should have to make the choice in a particularly explicit way.

That distinction matters. A Mac owner may reasonably expect an app to work with a selected folder, a particular document or a clearly identified service. Full Disk Access is different in kind: it can extend across the system. Apple says the permission largely bypasses the privacy protections otherwise offered through macOS, because backup apps must be able to operate properly. The challenge in the planned update is therefore to preserve a path for software with a legitimate need while making it harder for a broad grant to be made casually, ambiguously or without adequate understanding.

Apple is framing AI agents as the reason that balance has become more urgent. The company says the danger associated with sweeping disk access will increase substantially as such agents gain capability and autonomy. Its concern, as described in the report, is not confined to a single product or a named developer. Rather, it is about what follows when software that can take actions and work through information is paired with access to a large share of a person’s digital record.

The wording leaves several boundaries undefined. Apple has not publicly set out which types of AI-enabled apps prompted the policy, how it will distinguish a legitimate request from an inappropriate one, or whether the control will apply in the same manner to all existing and future applications. Nor has it explained whether apps that already hold Full Disk Access will face a new confirmation step. Those unanswered questions determine whether the change will chiefly affect new installations, change ongoing access, or do both.

Reported Messages episode sharpened the debate, but its facts are contested

The announcement follows a reported episode involving Meta’s Muse AI and access to Messages content. The account described an observation that the chatbot appeared to know the contents of messages even though explicit permission to access them had not been given on an iPhone or Mac. That observation helped bring attention to the practical consequences of expansive software access, particularly when an AI tool is involved.

Meta disputes the implication that Muse could reach Messages without a clear user choice. A company spokesperson said the capability is opt-in and maintained that a user must enable both Full Disk Access and a Messages connector before Muse can read message content. The disagreement is material. One version suggests access was obtained without an explicit permission step; Meta’s version says two separate settings must be activated.

Neither account, on the information available here, resolves how the reported result occurred. There is no further technical explanation of the devices’ settings, the sequence of actions, the version of the software involved, or the precise basis on which the content was said to be known. It would therefore be wrong to treat the episode as established proof either that a permission was bypassed or that Meta’s description fully accounts for the observation. Apple’s planned policy should not be read as a formal finding about that specific episode.

Still, the dispute illustrates why the language and design of consent screens matter. A company may regard several settings as a sufficient opt-in process, while a user may understand their choices much more narrowly. When access concerns files, email, message history and browsing activity, the difference between an available control and an understood control becomes consequential. Apple’s stated emphasis on very explicit action appears aimed at that divide, though the company has not yet shown what the action will look like.

More friction could change both user choice and app design

For Mac users, a more demanding consent process could make broad access requests more noticeable. That could provide a clearer moment to assess why an app wants system-wide reach and whether the benefit justifies it. It may also make users less likely to approve a request simply to move through setup quickly. Apple’s account suggests that this is the intended effect: a decision of unusual consequence should not resemble an ordinary, routine prompt.

For developers, the proposal may place greater weight on asking only for the access their software genuinely needs. Applications built around backup functions may have an evident reason to seek broad access. Other software may need to explain more clearly why it requires it, or redesign features so that they rely on narrower permissions where possible. Apple has not specified any technical requirements, exemptions or enforcement consequences, so the scale of that adjustment cannot yet be measured.

AI developers face a particularly sensitive version of the same question. An agent intended to search, organize or act on behalf of a user may become more useful when it can examine a wide range of local information. But the usefulness of broad context and the privacy cost of broad context rise together. Apple’s warning rests on the proposition that agents able to do more with information also make an expansive permission more consequential. The company has not alleged that AI software as a category is misusing the permission; it has identified a growing risk associated with the combination of powerful access and more autonomous behavior.

The announcement also places a limit on how far readers can infer Apple’s plans. The headline description of tighter limits may suggest an imminent, fully defined rollout. The underlying account says Apple has not provided a release date. “Plans to introduce” is more precise than claiming the controls are already available. Until Apple identifies a software release, a timetable or detailed documentation, users cannot know when the altered process will appear on their Macs.

Apple has set a direction, not yet a timetable

Apple’s policy statement contains a clear principle: Full Disk Access is exceptional and should require an exceptionally clear decision by the person granting it. It also contains a clear rationale: access that can reach a user’s personal data becomes more hazardous when software can operate with greater capability and autonomy. Those points establish the company’s direction even without a release schedule.

What remains unknown is just as important to the near-term impact. Apple has not said whether the controls will be part of a specific macOS update, how existing permissions will be handled, what exact user interface will appear, or how developers will adapt. The company also has not offered public detail that settles the conflicting accounts surrounding Muse’s alleged access to Messages. Users evaluating an app’s request for Full Disk Access must therefore continue to judge the request based on the information presented by the app and the permissions they choose to enable.

The reported plan is based on a single published account and Apple’s reported statements within it. The report has not been independently corroborated. That limitation is especially important because the timing is undisclosed and the most prominent example of disputed access involves competing accounts rather than a publicly resolved technical record.

For further context on this subject, see Altman says OpenAI will delay IPO until it can support stronger safety claims.

Reporting notes

What is confirmed: Apple has stated the policy direction and its concern about broad access. It has not announced a rollout date or detailed implementation.

Why this matters: The permission can reach highly personal material across a Mac, while Apple has not said how or when the new controls will be implemented.

What remains unclear: The release timing, treatment of existing permissions, technical design and the facts behind the disputed Muse episode remain unclear. This report is based on one source and has not been independently corroborated.

Sources