Apple is preparing to tighten one of macOS's most sensitive privacy permissions as it responds to a new class of threat: AI agents that can operate with enough autonomy to expose or misuse a user's most personal data. The company said it will introduce additional controls around Full Disk Access, a setting that already grants broad visibility into files, messages, mail and browser history, but now looks even riskier in an era of software that can reason, act and chain together tasks across applications.
The warning is notable not only for what Apple plans to change, but for what it reveals about the company's view of the next phase of computing. Full Disk Access has long been treated as a high-trust permission reserved for backup tools, security software and a narrow set of utilities. Apple's concern is that AI agents, unlike traditional apps, may not simply read data once and stop. They can be prompted, delegated or manipulated into searching, summarising, moving or transmitting information in ways that users may not fully anticipate.
New Risk Model
Apple's move reflects a broader industry reckoning with agentic AI, a category that goes beyond chatbots and image generators. These systems are designed to take actions on behalf of users, often by interacting with operating systems, browsers, email clients and productivity tools. That capability is what makes them useful, but it is also what makes them dangerous when paired with expansive permissions. A tool that can inspect a document is one thing; a tool that can scan a mailbox, correlate messages with browsing history and then act on that information is another.
For Apple, the issue is especially acute because macOS has historically marketed itself as a privacy-conscious platform. The company has repeatedly positioned itself as a guardian of user data, using permission prompts and sandboxing to limit what applications can access. But AI agents complicate that model. They may need broad access to function well, yet broad access is precisely what increases the blast radius if the software is compromised, misconfigured or tricked by malicious prompts.
The company's decision also underscores a tension that is now emerging across the technology sector: the same permissions that enable powerful automation can also collapse long-standing security assumptions. In a conventional app model, access is typically tied to a single function. In an agent model, access can become dynamic, persistent and difficult to audit. That makes old permission frameworks look increasingly blunt.
Privacy Meets Automation
Apple has not framed the change as a rejection of AI agents, but rather as an attempt to adapt macOS to a more capable and potentially more intrusive software environment. The practical effect is likely to be more friction for developers building agentic tools, especially those that rely on deep system access to deliver seamless experiences. It may also force companies to design more narrowly scoped features, clearer consent flows and stronger on-device safeguards.
The announcement comes at a time when regulators, security researchers and platform owners are all asking similar questions about how much autonomy AI should have and what guardrails are necessary when it is allowed to operate on a person's behalf. The concern is not theoretical. If an agent can read a user's mail, search local files and inspect browser activity, it can assemble a highly detailed portrait of that person's life, contacts, habits and intentions. In the wrong hands, that information could be used for surveillance, fraud or targeted manipulation.
Apple's approach suggests that the company sees permission design as one of the main battlegrounds in the AI era. Rather than waiting for a major breach or scandal, it is moving to narrow exposure before agentic tools become ubiquitous. That is consistent with Apple's broader product strategy: constrain the system, preserve trust and make powerful features work within a tightly controlled environment.
For developers, the message is clear. The age of broad, implicit access is ending, and the burden is shifting toward proving why an AI agent needs sensitive data in the first place. For users, the change may mean more prompts and more decisions, but also a stronger barrier between experimental automation and the deepest parts of their digital lives. In a market racing to make AI more capable, Apple is betting that restraint will remain a competitive advantage.
