Full Disk Access on Mac and the AI Agents That Want It

Apple is adding new controls around macOS Full Disk Access because AI agents make that permission far riskier. Here is what the setting really does and how to audit your office laptops.

Apple said it will add new controls around a macOS setting called Full Disk Access, because AI agents have raised the risk of handing an app that level of permission. As reported by TechCrunch, the announcement followed a columnist's claim that Meta's Muse app on Mac knew the contents of his private messages, a claim Meta disputed. If anyone in your company has installed a desktop AI assistant on a work laptop, this is worth thirty minutes of your attention.

What Full Disk Access actually is

macOS normally keeps apps fenced off from each other. An app can see its own files and whatever you explicitly hand it. Full Disk Access removes most of that fence. According to Apple's description, an app with this permission can reach files, mail, messages and browsing history.

The setting was not built for AI. It exists so that backup software can do its job, which genuinely requires reading everything. The problem is that the permission is coarse. There is no way to say "read my documents folder but not my messages." It is all or nothing.

Apple said some developers are using Full Disk Access in ways that put users at risk, exposing everything on a system without the user fully understanding what they agreed to. Going forward, the company says granting this access will require very explicit user action. Apple also wrote that as AI agents become more capable and autonomous, the risks tied to this level of access will grow substantially. Apple did not respond to TechCrunch's questions about the change.

TechCrunch also noted a separate Wired report about a flaw in the ChatGPT Mac app that could have let attackers reach sensitive data. Different incident, same underlying theme: desktop AI apps sit close to everything you have.

Why this matters for a small business

A desktop AI agent with Full Disk Access is not just reading your files. It is usually sending parts of what it reads somewhere else so a model can process it. That is the point of the product. The moment an employee grants that permission on a work laptop, your client contracts, invoices, salary spreadsheets, password reset emails and internal chats are all inside the blast radius of one app's security decisions.

The second issue is that nobody in your company made this decision as a company. An employee installed something useful, clicked through a permission dialog, and the exposure happened quietly. There is no purchase order, no vendor review, no record. If a client later asks how you handle their data, you will not have an answer because you do not know what is installed.

This applies to anyone whose staff handle customer records on a laptop: an accountant's files, a clinic's patient lists, a shop's order history. The data does not have to be dramatic to cause a problem if it leaks.

A short audit you can run this month

  • Check every Mac in the office. Open System Settings, go to Privacy and Security, then Full Disk Access. You will see a list of apps that have it. Backup tools and some security software belong there. An AI chat app probably does not.
  • Revoke first, ask later. Turn off anything you do not recognise or cannot justify. If something breaks, the person affected will tell you within a day, and then you can make a deliberate decision.
  • While you are in that panel, check the neighbours. Screen Recording, Accessibility and Automation grant similar power in different shapes. An agent that can watch your screen and click buttons does not strictly need file access to see your data.
  • Write down which AI tools are approved. A one-page list of allowed apps, and a rule that new ones get asked about first, removes most of this risk without blocking anyone from working.
  • Separate the sensitive work. If one machine holds financial records or client contracts, keep experimental AI tools off it entirely. Cheap, boring, effective.

The pattern to remember

Desktop AI agents are useful precisely because they can see your context. That is also exactly why they are risky. Apple is responding by making the permission harder to grant by accident, which is a reasonable fix, but it will not retroactively clean up laptops where the switch is already on. That part is yours. Treat Full Disk Access the way you treat a key to the filing cabinet: few people get one, you know who they are, and you take it back when they no longer need it.

SourceWritten from reporting by TechCrunch. Read the original: Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents ↗

More articlesAll articles →