Apple posted something on its developer site this week that’s worth paying attention to, even without a single concrete detail attached to it. The company says it’s planning changes to how macOS handles Full Disk Access, the permission that essentially hands an app the keys to everything on your Mac, and the timing isn’t coincidental. AI agents are getting more capable and more autonomous by the month, and Apple is apparently worried about what that combination means once paired with unrestricted system access.
Full Disk Access was never meant to be handed out casually. Apple built it for backup software, the kind of app that genuinely needs to see every file on a drive to do its job. But the permission works by bypassing most of the usual privacy guardrails macOS puts up around sensitive data. That’s fine when a backup tool is the one asking. It’s a different story when something else wants the same level of access, and according to Apple, that’s exactly what’s starting to happen.
The company didn’t mention any names in its post, but it didn’t need to. Reading between the lines, Apple’s “some developers” line lands right around the same moment that always-on AI assistants like Meta’s Muse and OpenAI’s Dots have been climbing in popularity. These aren’t apps you open occasionally. They sit there running in the background, often requesting exactly the kind of sweeping access Apple is now flagging as risky: mail, messages, browsing history, files – basically the full contents of someone’s digital life. Reports have already surfaced of people regretting what they granted Muse access to, which makes Apple’s timing here feel less like a coincidence and more like a direct response.
What Apple actually plans to build remains vague. The company says new controls are coming that will require “very explicit user action” before anyone can grant an app this level of access, but there’s no timeline, no screenshots, nothing beyond the promise itself. Still, the language in Apple’s statement is pointed. It specifically calls out how AI agents complicate the privacy equation in a way static apps never did, since an autonomous agent can act on access in ways a user might not anticipate or fully understand when they first approved it.
No release date has been given for any of this. For now, it’s a warning shot and a promise, with the actual mechanics still to come.





0 comments
No comments yet. Start a thoughtful conversation.