Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents
Apple says it s tightening macOS Full Disk Access controls due to new risks from AI agents | TechCrunch Last day to exhibit your breakthrough to 10,000+ tech leaders at Disrupt is on Oct 2 . Book Exhibit Table Now.

- Apple says it s tightening macOS Full Disk Access controls due to new risks from AI agents | TechCrunch Disrupt doors open Oct.
- Get your pass and bring someone with you at 50% off.
- The feature was designed to allow backups to function properly, but AI agents have now increased the risks associated with this level of access, Apple said.
Apple says it s tightening macOS Full Disk Access controls due to new risks from AI agents | TechCrunch Disrupt doors open Oct. 13. Get your pass and bring someone with you at 50% off. REGISTER NOW. Apple says it s tightening macOS Full Disk Access controls due to new risks from AI agents Days after a journalist claimed that Meta s Muse app on Mac read their private messages a claim that Meta disputed Apple announced that it s introducing additional controls around a setting called Full Disk Access on macOS. The feature was designed to allow backups to function properly, but AI agents have now increased the risks associated with this level of access, Apple said. Apple s statement comes shortly after Inc. columnist Jason Aten reported that Muse knew the content of his private messages even though he claimed to have not given the AI agent permission. The report raised questions about the level of security and trust users have in desktop-based AI, which can control things on their systems and read their files and messages. The decision also comes after a Wired report cited that a flaw in ChatGPT s Mac app could have allowed hackers to access sensitive data. AI agents that run on the desktop allow users to provide their respective apps with greater access to the files, messages, and other personal content on their computers by adjusting macOS settings. In Muse s case, the AI optionally allows users to enable Full Disk Access. This setting, Apple explains, gives an app permission to access files, mail, messages, and even browsing history. Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems without users’ full knowledge and understanding, Apple said in a new blog post aimed at developers. The company says that, going forward, it will introduce new controls aimed at ensuring that users who genuinely wish to grant an app this extraordinary level of access can do so only with very explicit user action. Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy, Apple wrote. Apple did not respond to TechCrunch s inquiry about the feature change. Correction: Due to an editorial error, the change was described as Apple “limiting” permissions. After publication, the author of this article updated the wording to reflect their original intent: the change reflects informed consent, but is not a new limit. AI , AI agents , Apple , Apps , Meta , Security When you purchase through links in our articles, we may earn a small commission . This doesn’t affect our editorial independence. Sarah has worked as a reporter for TechCrunch since August 2011. She joined the company after having previously spent over three years at ReadWriteWeb. Prior to her work as a reporter, Sarah worked in I.T. across a number of industries, including banking, retail and software. You can contact or verify outreach from Sarah by emailing sarahp@techcrunch.com or via encrypted message at sarahperez.01 on Signal. The Disrupt experience is meant to be shared. Get your pass and bring a colleague, partner, or peer at 50% off. Cover more ground by making connections, building momentum, and discovering what’s next in the startup ecosystem. Federal judge calls Flock ‘indiscriminate mass surveillance’ Amazon responds to data center backlash, says it no longer uses NDAs Google thinks SpaceX s Starship has to launch 1,800 times before space data centers get off the ground World’s first enhanced geothermal power plant completed in just 23 months Google releases Gemini 4 Argon, called its most powerful model yet The Pentagon taps Elon Musk and Palmer Luckey to help decide what the military should do next OpenAI launches Dots, its bubbly agentic avatar
Sources
Related stories

Vulnerabilities in AI Agents Expose Trust Gap Flaw
Google and other organizations have acknowledged vulnerabilities in their AI agents, which exploit trust gaps in the Model Context Protocol.

Google researchers find a way to keep self-improving AI agents from memorizing their tests
Google researchers find a way to keep self-improving AI agents from memorizing their tests AI agents that keep optimizing their own working environment quickly tend to overspecialize on their test tasks. A new method from Google Cloud AI Research and several universities aims to prevent that while also cutting compute costs.

All the AI agents that can live in your text messages
All the AI agents that can live in your text messages | TechCrunch Last day to exhibit your breakthrough to 10,000+ tech leaders at Disrupt is on Oct 2 . Book Exhibit Table Now.

Meta wants your next gadget to be Muse-infused
Meta wants your next gadget to be Muse-infused | TechCrunch Last day to exhibit your breakthrough to 10,000+ tech leaders at Disrupt is on Oct 2 . Book Exhibit Table Now.