Apple Is Rewriting the Mac Permission Slip Because of AI Agents
On October 2, Apple announced changes to how macOS handles Full Disk Access, a setting that gives apps nearly unlimited reach across your files, messages, and browsing history. The announcement named AI agents explicitly as a reason to act. That is a notable step: a major platform vendor acknowledging, in a developer-facing document, that the agent wave is already straining the privacy assumptions baked into Mac software.
This article covers what Full Disk Access actually is, why AI tools are hungry for it, what Apple is changing and why, and what you can do right now to see which apps have it on your machine.
What Full Disk Access is, and why it is powerful
Most of the time, macOS controls which data each app can reach. An app has to declare what it wants, Apple surfaces a permission dialog, and you say yes or no. Full Disk Access is a special bypass of that whole system. It was designed so that backup apps like Time Machine and utility software can reach every file on the drive without being blocked at every turn.
The trade-off was always understood: you only gave Full Disk Access to tools you trusted completely, because they genuinely needed it. The catch is that "trusted completely" is a meaningful standard, and not every app that asks for it meets it.
In its developer announcement, Apple raised concerns about how some developers use Full Disk Access. For communication apps, it also compromises the privacy of the people on the other end of your conversations, people who never installed the app and never agreed to that access.
Why AI agents specifically want it
An AI agent is software that takes actions on your behalf, often over time, without you doing each step manually. To do that well, it is useful to know things: what files you are working on, what emails you have sent, what your calendar looks like, what you have been browsing. Full Disk Access is the fastest path to all of that in one permission.
This is not a hypothetical concern. OpenAI reported that more than 35 million people now use its agent products, ChatGPT Work and Codex, up from 10 million as recently as July. Meta's Muse, an AI assistant app, hit the top of app store charts after its September launch.
Some early incidents have surfaced in reporting. Inc. columnist Jason Aten wrote that Meta's Muse surfaced details from his private messages after he said he had declined the app Messages access; Meta disputed aspects of that account. Wired documented a flaw in the ChatGPT Mac app that could have exposed sensitive data. These are reported incidents, not established facts, and the details are contested in some cases. But they illustrate the category of problem Apple says it is trying to prevent.
In Apple's words: "As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially."
What Apple is changing
Apple's announcement does not specify a macOS version number or a rollout date. What it describes is a shift in how granting Full Disk Access works. Currently it is possible to give an app this permission in ways that are easy to overlook. Under the new approach, Apple says users who "genuinely wish to grant an app this extraordinary level of access" will only be able to do so "with very explicit user action."
The phrase "extraordinary level of access" is not boilerplate. Apple is signaling that the default expectation is changing. Full Disk Access should be unusual, granted rarely, and only after you understand what you are doing.
How to check which apps have it right now
You do not have to wait for any update to audit what is already on your machine. Here is the path:
Open System Settings.
Go to Privacy and Security.
Scroll down to Full Disk Access.
You will see a list of every app that has been granted this permission. Some of them may surprise you. Go through the list with skepticism: does each app genuinely need access to your entire drive to do its job?
How to revoke it
Toggling off Full Disk Access for an app is straightforward. In the same Full Disk Access list, click the toggle next to any app to turn it off. The app will lose that access immediately. Some apps will complain, or certain features will stop working. That feedback is useful: it tells you whether the app actually needed the permission or just collected it.
If an app stops functioning entirely without Full Disk Access, consider whether that function is worth the trade-off. A note-taking app that needs all your files to work is a different product than a backup tool that genuinely needs them.
Least-privilege habits for the agent era
The principle of least privilege is old and simple: give software only the access it needs to do the specific job you hired it for, no more. That principle has always been good hygiene. It matters more now because agents are designed to act broadly and repeatedly, not just once when you click a button.
A few habits worth building:
Review permissions when you install anything new. If an app asks for Full Disk Access on first launch, ask why. Most apps have no legitimate reason to need it.
Audit regularly, not just at install time. Apps can request permissions they did not initially ask for. A quarterly check of the Full Disk Access list takes two minutes.
Prefer scoped alternatives. Many agents can work with access to a specific folder rather than the entire drive. If the app offers a narrower option, take it.
Treat "it asked so I said yes" as a flag, not a reason. An agent that requests Full Disk Access is making a significant ask. Frictionless permission grants are exactly what Apple's new requirement is designed to interrupt.
Questions to ask before granting an agent broad access
When any AI tool asks for Full Disk Access, or broad permissions of any kind, a few questions help cut through the marketing:
What specific files or data does this feature actually need?
Does the app offer a more limited permission that would accomplish the same thing?
What happens to the data after the agent reads it? Is it sent to a server?
What is the app's track record on privacy? Has it been audited?
If something went wrong with this access, what would be at risk?
If an app cannot answer those questions clearly in its documentation, that is an answer in itself.
What to do
Right now, today: Open System Settings, go to Privacy and Security, and open Full Disk Access. Read every app on that list. Revoke access for anything you do not recognize or that has no obvious reason to be there.
Before installing any AI agent: Read its privacy policy specifically for language about what it reads, what it sends remotely, and how long it stores data. If that language is vague, treat the whole app with more caution.
When an app asks for Full Disk Access: Pause before clicking yes. The new friction Apple is building in is not a bug. It is the point. Apple's own framing calls this an "extraordinary level of access." If that sounds dramatic for a productivity tool, that is a reasonable instinct to trust.
The agent era is not slowing down. But the permissions you grant are still yours to control.
A few things to check before you publish:
Truncated text in the original. One sentence was cut off mid-word ("in ways that exp…") and the next ended at "never agreed," with a heading running into it. I couldn't know what Apple actually said, so I wrote a neutral version. Please compare it to Apple's announcement and adjust.
Links. I turned the stray URLs into inline links. The Wired claim links to a Storyboard18 article, which looks like a mismatch, so you may want to swap in the original Wired link.
Headings. I added the section headings as H2s. In Squarespace, select each heading line and set it to Heading 2 if they don't carry over when you paste.

