Apple will tighten Full Disk Access after AI agents started reading everything
Apple says it will redesign the macOS permission that hands an approved app the keys to a user's files, mail and browsing history, after finding that AI assistants are quietly using it to hoover up personal data.

Key points
- Apple will tighten controls on a macOS setting called Full Disk Access, which lets an approved app read nearly everything on a Mac including files, messages and browsing history.
- The company says some developers, specifically those building AI assistants, are abusing the permission to pull personal data off users' machines without clear consent.
- Full Disk Access currently works as an all-or-nothing switch: once a user clicks Allow, the app can see the lot.
- Apple has not published a date, a macOS version number, or technical detail for the planned changes.
- Mac users can review which apps hold the permission today under System Settings, Privacy & Security, Full Disk Access.
Apple is going to tighten one of the most powerful switches on a Mac, and it's doing it because of AI.
The switch is called Full Disk Access. It tells macOS that an app is trusted enough to read almost anything on the computer: documents, saved mail, iMessage history, Safari browsing, Time Machine backups. Users turn it on manually, usually because a backup tool or antivirus product asked them to.
That design has always been blunt. You either grant the app the keys to the whole house, or you don't. There's no middle setting for "you can see my downloads folder but not my messages."
Apple now says that bluntness is a problem. In a statement reported by The Hacker News, the company said some developers are using Full Disk Access "in ways that could put users at risk, exposing everything on their systems, including files, mail and even browsing history, without users' full knowledge." Apple singled out AI agents, the new generation of assistants that read a user's data to answer questions or take actions on their behalf.
What is Full Disk Access, and why does it matter?
It's the macOS permission that lets one app see almost every file belonging to the user. Apple's own support documentation describes it as access to system configuration files and private data that other permissions deliberately wall off.
Most Mac permissions are narrow. An app has to ask separately for the camera, the microphone, the contacts list, the calendar. Full Disk Access skips all of that. Grant it once and the app can read your mail store, your Messages database and your Safari history, along with the contents of other apps' private folders.
That's useful for a backup program. It's also useful for an AI assistant that wants to know everything about you to be more helpful. Apple's complaint is that the second category is piggy-backing on a permission designed for the first, which is exactly the pattern our 3 September story on AIR Security flagged: AI tools acquiring overly broad permissions before anyone has thought carefully about the consequences.
How are AI agents abusing it?
Apple's position is that users don't understand the full scope of what they're agreeing to. An AI tool asks for Full Disk Access to "work properly." The user clicks Allow. The tool then reads mail and browsing history and ships summaries, or the raw text, to a server for processing.
None of that is a software bug. There's no CVE here, no exploit chain, no patch string to track. It's the permission working exactly as designed, used by a category of app the design never anticipated.
That's the uncomfortable part for defenders. The fix can't be a patch. It has to be a redesign of how the permission is granted, probably something closer to the per-folder prompts macOS already shows for Documents or Desktop access.
Should you worry about what's already on your Mac?
Check what already has the permission. Open System Settings, click Privacy & Security in the sidebar, scroll to Full Disk Access, and look at the list. Any app you don't recognise, or any AI tool you installed and forgot about, can be switched off with the toggle. The app will still run; it'll just lose the all-areas pass.
Apple hasn't said when the tighter controls will ship, which macOS version will carry them, or what the new consent flow will look like. Until it does, that toggle is the only real control a user has.
My read: Apple's right that the permission is being misused, and late to say so. Full Disk Access has been a known over-broad switch for years. It took a wave of AI assistants treating personal data as training fuel to force a redesign that enterprise security teams have been quietly asking for since the setting shipped.



