Skip to content
English
FikirPilot content

Apple says it is tightening ‘Full Disk Access’ controls in macOS due to new risks posed by AI agents

Updated: 5 Eki 2026 · 3 min read · 414 words

Published: · Story reached us: · Processing time: 38 min

Apple says it is tightening ‘Full Disk Access’ controls in macOS due to new risks posed by AI agents
A lock on a laptop

Apple announced that it will introduce additional controls to the “Full Disk Access” setting in macOS due to new risks posed by AI agents. The announcement came days after journalist Jason Aten claimed that Meta knew the content of private messages in its Muse app. Meta denied the claim. Aten’s article raised questions about the security of AI tools running on desktops that can access personal content such as files and messages.

Initially designed to ensure that backup processes worked properly, Full Disk Access can give apps permission to access files, emails, messages and browsing history. In Muse, this access can be enabled at the user’s discretion. Apple said some developers were using this permission without ensuring that users fully understood everything on their systems.

The company said it would introduce controls to ensure that users who want to grant this level of access can do so only through “a very explicit user action.” Apple said the risks would increase as AI agents become more capable and autonomous, and that users need to clearly understand the data and privacy risks before granting access. The change is intended to strengthen informed consent rather than limit permissions.

The decision also came under discussion after Wired reported that a vulnerability in the Mac app for ChatGPT could allow access to sensitive data. Apple did not respond to TechCrunch’s questions about the change.

Why it matters

The main consequence of the change will be to tie broad access to files and communications on macOS more directly to the user’s decision rather than to a technical setting. This issue concerns not only people who use AI tools that work with personal data, but also developers who build their applications around this permission, because the scope of access can include email, messages and browsing history in addition to files. Meta’s denial of the claim about Muse and the report about the vulnerability in the ChatGPT app show that the debate is not limited to a single application. However, it has not yet been explained in which situations Apple’s new controls will apply or how well users will be able to understand the risks.

Background

Apple is not a new name in the FikirPilot archive: we have published 77 stories mentioning the name in the last 90 days; the most recent is dated 4 October 2026.

Term: agent

An AI agent is software that calls tools and carries out multi-step tasks to achieve a goal rather than producing a single response.

Source: TechCrunch AI