Apple plans to strengthen macOS Full Disk Access controls, warning that increasingly capable AI agents create new risks when applications have unfettered access to user files, messages, mail and browsing history. The move signals a shift in how the company balances software flexibility with data security in the age of intelligent automation.

What You Need to Know

Full Disk Access is a macOS permission that lets trusted apps read nearly all user data without restrictions. Apple says AI agents, which can autonomously act on behalf of users, raise the danger that a compromised or malicious app could extract sensitive information at scale. The coming changes will likely require apps to request narrower, per-category access rather than blanket permission.

What Changed With Full Disk Access

Apple has not yet detailed the exact technical changes but confirmed it will introduce new controls to limit how applications use Full Disk Access. Developers who build tools relying on broad file system access will need to adapt. The company framed the update as a direct response to the growing prevalence of AI-powered software agents that can read, summarize and act on personal data.

Currently, Full Disk Access allows authorized apps to bypass normal file system sandboxing. Apple grants this privilege sparingly but once granted, an app can access everything from email archives to browser histories. The new controls are expected to narrow this scope significantly.

  • Messages and Mail: AI agents could read private conversations and attachments if Full Disk Access remains unchecked.
  • Browsing history: Access to Safari profiles and cookies exposes extensive user behavior data.
  • File synchronization: Tools that index or back up entire drives would be affected by tighter scope.

Why AI Agents Raise the Stakes

The shift reflects a broader industry reckoning with the power of agentic AI. Unlike traditional apps that perform predefined tasks, AI agents can set goals, make decisions and execute sequences of actions without direct human oversight. When such an agent gains Full Disk Access, the potential for unintended data exposure multiplies.

Apple’s warning specifically cites the risk that an AI agent could be tricked into exfiltrating data through prompt injection or be compromised by a supply chain attack. These threats are not hypothetical: security researchers have demonstrated that large language models integrated into desktop apps can be manipulated to leak files.

Why This Matters

The new controls mean developers building AI-driven productivity tools, automation scripts or local search utilities on macOS will face stricter permission gates. Users, however, gain stronger guarantees that an app cannot silently harvest their entire digital life. For enterprises, the change could reduce the attack surface available to malware that abuses legitimate permissions.

Apple’s move also sets a precedent. If other operating systems follow, the era of blanket file system access may end, forcing the AI industry to design agents that work with far less data. That could slow some product features but also build the trust needed for broader adoption.

What Developers Need to Know

Developers should prepare for a more granular permission model. Apple may require apps to declare exactly which data categories they need and justify each one during review. Temporary entitlements or runtime prompts could replace permanent grants. Apps that currently rely on Full Disk Access for legitimate purposes, such as backup software or system utilities, will need to document their use cases carefully to retain approval.

The timeline for implementation has not been announced, but Apple typically previews major security changes at WWDC in June. Developers should monitor the next macOS beta for new entitlement keys and required user-facing explanations.