Apple is preparing to tighten one of macOS's most sensitive privacy permissions as it confronts a new class of risk created by AI agents that can operate across a user's digital life. The company said it will introduce additional controls around Full Disk Access, a setting that can grant software sweeping visibility into files, messages, email and browser history, arguing that the rise of more capable autonomous tools makes such broad permissions harder to justify.
The change is notable because Full Disk Access has long been treated as a high-trust gatekeeper inside Apple's desktop security model. It is the kind of permission typically reserved for backup tools, enterprise security products and system utilities that need deep visibility to function. Apple's warning suggests that AI agents, which can increasingly read, summarize and act on behalf of users, may now be powerful enough to turn that same access into a serious privacy and security liability.
New Risk Profile
Apple's move reflects a broader shift in how the technology industry is thinking about agentic AI. Early generative AI products were mostly limited to chat interfaces and document drafting. The newer wave of agents is designed to connect to calendars, inboxes, browsers, cloud drives and local files, then take actions with minimal supervision. That capability is what makes them useful ā and what makes them dangerous if they are granted broad system permissions.
In practical terms, Full Disk Access can expose far more than a user might expect from a productivity assistant. If an AI agent can scan email archives, message threads, downloaded documents and browser sessions, it may be able to reconstruct sensitive personal, financial or professional information. Apple's warning indicates that the company sees the threat not as a theoretical edge case but as an emerging platform-level issue.
The company has not framed the change as a rejection of AI agents themselves. Instead, it is drawing a line around how much of the operating system such software should be allowed to see by default. That distinction matters. Apple has spent years marketing privacy as a core product feature, and any perception that macOS is becoming a permissive environment for always-on AI access would cut against that brand promise.
Apple Draws Boundaries
The new controls are also consistent with Apple's long-standing preference for permission-based access rather than open-ended system reach. On iPhone and iPad, the company has repeatedly forced apps to ask before accessing photos, microphones, location data and tracking identifiers. Extending that philosophy to macOS's deepest file-access layer suggests Apple is trying to get ahead of a problem before AI agents become ubiquitous on the desktop.
The timing is important. The industry is racing to embed AI assistants into operating systems, browsers and workplace software, often with the promise that they will reduce friction by reading context and acting on behalf of users. But the more context an agent can ingest, the more attractive it becomes as a target for misuse, credential theft or accidental overreach. A compromised agent with broad disk access could become a shortcut into a user's most sensitive data.
For developers, Apple's decision may create additional friction. Some AI tools will likely need to redesign how they request access, narrow the scope of what they can inspect or rely more heavily on explicit user prompts. That could slow down some workflows, but it may also force the market toward more disciplined security architecture, where agents are granted only the minimum access required for a specific task.
Wider Industry Signal
Apple's warning is likely to resonate well beyond macOS. It underscores a central tension in frontier AI: the same systems that become more useful as they gain autonomy also become more dangerous as they gain reach. The challenge for platform owners is to decide how much trust to place in software that can reason, search, summarize and execute across multiple applications.
The company's stance may also influence enterprise buyers, many of whom are already cautious about letting AI tools into email systems, file shares and internal messaging platforms. If Apple is tightening controls at the operating-system level, it may reinforce a broader corporate argument for stricter governance, audit trails and least-privilege access rules for AI deployments.
At a policy level, the move adds to the growing debate over whether existing permission frameworks are adequate for autonomous software. Traditional app security models assume a relatively static program with a narrow function. AI agents are different: they can adapt, chain actions and operate across domains in ways that blur the line between assistant and actor. Apple's response suggests that consumer operating systems may need a new generation of safeguards to keep pace.
For now, the message from Cupertino is clear. As AI agents become more capable, the cost of granting them broad access rises sharply. Apple is moving to make that access harder to obtain ā and easier to question.
