On October 2, Apple announced that it will add new controls to macOS Full Disk Access. The powerful permission was designed for apps such as backup tools, but Apple says the risks grow as AI agents become more capable and autonomous. Granting it will require a clearer, more deliberate action from the user than before.

With Full Disk Access, an app can in some cases reach a wide range of data, not just files but also mail, messages, and browsing history. For messaging apps, this can affect not only the Mac's owner but also the privacy of the people they communicate with.

macOS already has mechanisms that ask for the user's permission. What Apple is now looking at is whether users truly understand how much power they are handing to an app when they grant it.

AD

A permission that is already required, made more explicit

Full Disk Access has always required explicit user approval. Apple's security guide explains that apps needing access to the entire storage must be added manually in System Settings. Accessibility, and automation, which uses Apple Events to control other apps, also each require the user's permission.

Apple's new approach adds another layer of control on top of this. In its October 2 announcement, Apple said that only users who want to give an app very broad access will be able to do so, and only after taking a "highly explicit action." The aim is to let users make the decision themselves, with an understanding of which data becomes accessible and what the risks are.

However, only the policy has been made public so far. Apple has not said when it will be introduced, which macOS versions it will apply to, or how apps that have already been granted access will be handled. The new settings screen and the specific steps involved have not been revealed either.

This is therefore not an announcement that the permissions of AI apps that currently hold Full Disk Access will be revoked immediately, or that particular apps will stop working. The actual changes will need to be confirmed through future OS releases and developer information.

What matters is that having a permission prompt is not the same as users fully understanding what they are agreeing to. Someone who grants broad access just to start using an app does not necessarily know which features will read which data afterward. Apple sees this problem becoming more important as AI agents grow more autonomous.

A permission built for backups, now available to AI too

Backup apps need to read a wide range of the data they are saving. Apple describes Full Disk Access as a mechanism that lets apps such as backup tools run by largely bypassing the normal access controls that protect personal data.

The October 2 announcement gave files, mail, messages, and browsing history as examples of what can be accessed. Still, it would be wrong to assume that the name "Full Disk Access" means every security protection built into macOS is switched off.

With an AI agent, accessible data is not just something to be read; it also becomes material for deciding what to do next.

For example, if a user asks an AI to "organize my schedule for next week," it might look at emails and files the user never intended it to use while searching for the information it needs. This is not a story about a problem with a specific AI app. It is a design risk that arises when broad data access is combined with an AI that decides its own next actions.

The data the AI reads can also be used as a means of attack. In the WWDC26 privacy and security session, Apple explained the risk of "indirect prompt injection."

This is an attack in which malicious instructions are embedded not in what the user types directly, but in emails, web pages, documents, or other content the AI reads, steering the AI's behavior.

Even if a user grants permission to an app they trust, they cannot necessarily trust every email or web page the app reads later. Apple therefore lists measures such as not treating externally obtained content as commands and limiting the actions the AI can perform.

Xcode's AI agent also has mechanisms that restrict the commands and tools it can use and ask the user for permission when needed. Allowing broad data access and deciding what operations the AI may perform with that data need to be considered separately.

AD

Permission to read data, to act, and to send data out are different things

macOS manages reading files and controlling other apps under separate permissions. And when data that has been read is sent to an external AI service, you also need to check how the destination handles that data, which is a separate question from macOS permissions.

Organizing Apple's existing guides and developer documentation, the points users should check can be divided as follows.

What to check Related permission or mechanism What to consider before allowing it
Reading protected data Files and Folders, Full Disk Access Is the scope of access too broad for this feature?
Controlling other apps Automation, Accessibility Beyond reading, which operations are you allowing?
Letting AI run commands and tools In Xcode, per-command and per-tool permissions Is it limited to the necessary operations, and can you review it later?
Sending information that was read to an external AI Data-handling terms of the AI service used What is sent, and how is it handled afterward?

This table organizes several mechanisms Apple has published by what to check. It is not a list of new Full Disk Access features announced this time.

The last item in particular, sending data to an external AI, cannot be judged from the Full Disk Access setting alone. Allowing data to be read on the Mac and sending that data to an external service are separate processes.

Apple itself distinguishes the scope of its cloud-processing guarantees. At WWDC26, it explained that the privacy guarantees provided by Apple's Private Cloud Compute do not carry over when data is sent to an arbitrary third-party AI service.

Developers who integrate third-party services are asked to understand how those services handle data and to explain this appropriately to users.

The fact that a Mac app "uses AI" therefore does not tell you where personal data is processed or how it is protected. Whether a developer can explain which data is processed on the device and which is sent out is an important factor in judgment, alongside the size of the permission.

Conversely, using a third-party AI service does not mean that the data sent is necessarily stored or used to train models. The actual handling depends on each service's terms.

It is not only the problem of the person who grants permission

In its October 2 announcement, Apple pointed out that giving a communication app Full Disk Access can affect not only the person using the Mac but also the privacy of the people they communicate with.

Emails and messages contain not only what the user wrote but also information received from family, friends, colleagues, and business partners. When a Mac owner decides to give an app broad access, that effectively allows access to the information of the people they communicate with.

For example, the data needed to "find only the schedule in a conversation" is very different from what is needed to "read and analyze past conversations broadly."

The fact that a user granted permission does not reveal how far the app will actually use the data. And just because the Mac's owner approved it does not mean the other party has agreed to their information being used for the same purpose.

That is why it matters for developers to separate and explain "data that is technically accessible" and "data a feature actually uses."

What is read when each feature is used, and what is sent if an external AI is involved? Even if broad access is needed to deliver a convenient feature, it does not follow that every task needs to use that permission to the fullest.

It is not yet known what form the new controls will take. Even so, what matters is a system in which the user can understand what they are allowing, not merely the fact that they granted permission once.

AD

What to watch next: how AI behaves after permission is granted

Apple already offers a mechanism in Xcode's AI agent for managing in detail which operations it can perform. According to the developer documentation, the Intelligence settings in Xcode let you review commands and tools you previously allowed the AI agent to use.

You can add or remove permitted commands and revoke access to tools later, so users can adjust the range of operations they allow the AI.

This is specific to Xcode and does not describe the specifications of the controls being added to macOS Full Disk Access. Still, it is a concrete example of managing "granting an app broad access" separately from "letting the AI carry out each individual operation."

Even if the procedure for granting Full Disk Access is made stricter, risk remains if what the AI can do afterward is unlimited. Conversely, if an app can reach the data it needs but must ask for confirmation before important operations, users gain more control.

In future versions of macOS, what to watch for is the specific content and timing of the additional controls, as well as how apps that have already been granted Full Disk Access will be handled.

When users review permissions, it is also important to be able to tell whether what they want to stop is the reading of data, the operation of other apps and files, or the sending of the data that was read to outside parties.

If developers clearly state the scope of the data and operations their work requires, and that scope can also be enforced technically, users will be better able to judge concretely what they are giving up in exchange for the convenience of AI.