So Apple just quietly admitted something a lot of us have been thinking for a while: giving an AI agent the keys to your entire Mac is probably not a great idea. Shocking, I know. The company announced new restrictions on Full Disk Access this past Friday, and if you’ve never thought twice about…
So Apple just quietly admitted something a lot of us have been thinking for a while: giving an AI agent the keys to your entire Mac is probably not a great idea. Shocking, I know. The company announced new restrictions on Full Disk Access this past Friday, and if you’ve never thought twice about that permission popping up in a dialog box, well, now’s the time to start.
Wait, What Even Is Full Disk Access?
Quick refresher for anyone who’s been clicking “allow” on every macOS prompt without reading it (no judgment, we’ve all done it). Full Disk Access is basically the nuclear option of permissions on a Mac. It hands an app the ability to see everything – your files, your Mail, your Messages, your browsing history, the whole digital diary of your life. Historically this existed so backup apps and some security tools could actually do their jobs without macOS’s normal privacy walls getting in the way.

The thing is, that kind of access made sense in a world where the apps asking for it were, you know, backup software. Boring, predictable, doing one job. Now we’ve got AI agents running around that are “increasingly capable and autonomous,” as Apple put it, and suddenly that same permission looks less like a convenience and more like handing a stranger your house keys because they promised to water your plants.
The Muse Problem (Yeah, That One)
This didn’t come out of nowhere. A few weeks back, Inc’s Jason Aten found that Meta’s Muse AI somehow knew what was in his messages – despite him never explicitly telling the chatbot it could peek at them. Not great! Meta spokesperson Andy Stone pushed back pretty hard on that framing, insisting access to Messages is “entirely opt-in” and that users have to specifically enable both Full Disk Access and the Messages connector for Muse to read anything. It's part of a broader pattern of AI agents building secret dossiers on everyone you know, often without you realizing it.

Okay, sure, technically that might be true. But here’s my issue with that defense – “technically opt-in” and “something a normal person actually understands they’re opting into” are two very different things. I’ve watched plenty of people (smart people!) blow through permission screens without reading a word. If the opt-in process is confusing or buried, calling it “opt-in” starts to feel like a technicality rather than real consent. We've already seen how badly this can go, like the Florida woman who ended up facing a felony charge over an AI chatbot she thought was private.
“Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems – including files, mail, messages, and even browsing history – without users’ full knowledge and understanding.”
That’s Apple’s own language from Friday’s update, and honestly? It reads like a company that saw a mess forming and decided to get ahead of it before it became a full-blown scandal. Smart move, even if it’s a little late.
Why This Actually Matters
Look, I get why people roll their eyes at another “Apple tightens privacy controls” headline. We’ve seen a hundred of these over the years – some meaningful, some just PR dressed up as policy. But this one feels different because of the timing. AI agents aren’t just chatbots anymore. They’re being built to take actions on your behalf, read your stuff, make decisions, maybe even order things or send messages for you. That’s a fundamentally different risk category than, say, an app wanting to back up your photos.
And Apple seems to actually get that. Their statement specifically calls out how “as AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.” That’s not just corporate boilerplate – that’s Apple basically saying “we see where this is headed, and we’re not comfortable with the current guardrails.” Which, fair. That risk isn't theoretical either – OpenAI is currently spending half a million dollars a day just to figure out how badly its own AI agents went rogue.
The Backup App Problem
Here’s where it gets a little messy though. Apple admits Full Disk Access “largely sidesteps” the privacy controls that normally protect users, specifically so backup apps can function properly. So now Apple’s stuck threading a needle – they need to keep that door open wide enough for legitimate tools like Time Machine alternatives or disk utilities, while slamming it shut on AI agents that want the same level of access for very different reasons. That’s not a simple fix. That’s an architecture problem.
From what I can tell, Apple’s answer is to make the permission harder to grant accidentally – requiring “very explicit user action” instead of a casual click-through. Which, I mean, is probably the right call. But it does make me wonder how many legitimate apps are going to get caught in the friction too. Nobody wants to sit through five confirmation screens just to back up their laptop.
What This Actually Means
Not gonna lie, I think this is the first real sign that the big tech companies are starting to realize AI agents break a lot of the old assumptions baked into how permissions work. The entire permission model on phones and computers was built around apps doing one specific, predictable thing. An AI agent doing fifteen different unpredictable things with the same blanket access? That’s a different animal entirely, and the old rules just don’t hold up.
Apple tightening this now feels less like overcaution and more like common sense that’s arriving right on schedule – before things get worse, not after. The real question is whether other companies follow suit, or whether we end up with a patchwork where some platforms protect you and others just shrug and let the AI agents do whatever they want as long as you clicked “allow” once, three menus deep, at 11pm while half paying attention.
Because that’s usually how these things go, isn’t it.