Software · 3 October 2026 · 3 min read

Apple Tightens macOS Security: Full Disk Access Faces New Curbs Over AI Agent Risks

In brief: Apple has announced a strict overhaul of Full Disk Access permissions on macOS, driven by the escalating privacy risks associated with autonomous desktop AI agents. The intervention follows backlash against Meta's Muse, which accessed private chat threads in Apple Messages through broad system-level privileges originally intended for backup software. Cupertino will mandate explicit user actions and granular warnings to stop third-party agents from scraping sensitive data without meaningful consent.

by Team Mocchi's

Apple Tightens macOS Security: Full Disk Access Faces New Curbs Over AI Agent Risks

The end of blind trust in system permissions

For years, Full Disk Access (FDA) on macOS remained an advanced technical permission reserved for a narrow set of utilities: backup tools like Time Machine, antivirus scanners, and data migration software. The rapid arrival of autonomous AI agents on desktop operating systems has completely altered that paradigm. Apple announced it is deploying substantially stricter controls on this setting, citing direct risks that stem from software agents operating locally across user machines.

Cupertino's move follows immediate controversy surrounding Meta's newly deployed AI agent, Muse. Columnist Jason Aten reported that Muse had proactively surfaced details from a private conversation inside Apple Messages, despite him never intentionally granting the assistant access to his chats. Although Meta defended itself by arguing that reading messages requires both macOS-level Full Disk Access and an opt-in toggle within Muse, the incident triggered intense pushback over how easily invasive permissions can be obtained under the guise of agentic productivity.

What an agent actually sees with Full Disk Access

Meta's explanation relied on the premise that users understand what granting system-wide access entails. However, as Ars Technica pointed out, macOS security researchers quickly dismantled that defense. Once an application is granted Full Disk Access, it is under no technical obligation to use official APIs: it can read any non-root file directly from local storage. This encompasses browser cookies, browsing history, local email archives, and unencrypted SQLite databases storing message histories.

In a developer-facing notice, Apple took a firm stance without explicitly naming Meta: abusing sweeping permissions exposes entire systems without the user's informed consent, while simultaneously compromising the privacy of anyone communicating with them. As AI models gain stronger reasoning and task-execution autonomy, broad read privileges turn minor interface ambiguities into severe data leaks.

Raising the barrier for desktop agentic software

As reported by The Verge, Apple will soon require deliberate, multi-step user actions before granting broad storage access, explicitly penalizing applications that request full disk visibility simply for engineering convenience. The scrutiny on desktop agents is intensifying across the industry: a separate vulnerability in ChatGPT's macOS desktop client, recently covered by TechCrunch, demonstrated how easily malicious actors could extract sensitive conversational records from local machines.

Apple's policy adjustment signals a clear paradigm shift for developers building AI workflows. Desktop agents will no longer be permitted to bypass sandboxing mechanisms through system-level shortcuts; integrations must instead rely on scoped APIs, directory-specific permissions, and traceable audit trails. The operating system is asserting its authority as an active gatekeeper against overreaching AI software.

Mocchi's take

For businesses deploying desktop AI agents into daily operations, Apple's intervention serves as a critical wake-up call. Empowering models to automate workflows must never mean giving them unmonitored read access across enterprise file systems, where API keys, session tokens, and confidential communications reside. When developing custom software and agentic workflows, adhering to the principle of least privilege remains non-negotiable: sandboxing agents and scoping their context solely to the specific data they need is the only sustainable way to adopt AI safely.

Further reading

All articles on the Mocchi's blog