All posts
2 min readby Romiel Inolino

Apple is tightening Full Disk Access on Macs because of AI agents. Audit what your desktop agents can read

AI agentssecuritymacOSpermissionsautomation

Apple just said out loud what every agent builder should already assume: broad access plus an autonomous agent is a bigger risk than either alone.

What happened

On Friday, Apple said it will add new controls to Full Disk Access (FDA) on macOS. According to TechCrunch, the setting was designed so backup apps could work properly, and it gives an app access to files, mail, messages and even browsing history.

Apple's statement to developers: "Some developers are using Full Disk Access in ways that could put users at risk." It added that "as AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially." Going forward, users who want to grant that level of access will only be able to do it with "very explicit user action." Apple has not said when the change ships.

The timing follows a dispute over Meta's Muse agent. Inc. columnist Jason Aten reported that Muse referenced one of his Apple Messages threads without him granting permission. Meta said Messages access is opt in and requires both FDA and a Messages connector. Ars Technica spoke with macOS security researcher Patrick Wardle, who said that with FDA, any non-root file is readable, including browsing history, cookies and chats. Apple did not name any app.

My take

The lesson is not about one app. It is about how permissions stack. A connector toggle inside an app is a promise. An operating system permission is what the code can actually reach. When those two disagree, the OS wins.

When I set up an agent or automation on a client machine or account, I ask three questions:

  1. What is the narrowest permission that still does the job? A folder, one mailbox label or one API scope, never "everything" for convenience.
  2. Who else's data does this touch? Apple called this out for messaging: your agent reading a thread also reads the other person's words.
  3. Can I prove what it read? If there is no log of which files or records an agent opened, you cannot answer a client who asks.

Desktop agents are useful. Give them a work folder, not your whole disk. Expect more platforms to follow Apple and make broad access harder to grant, and design your workflows so they never needed it in the first place.

This is the kind of scoped, auditable setup I build into every agent project. More at romielwillautomate.dev.

More posts