Ai Agents 4 min read

Apple Moves to Lock Down Full Disk Access, Citing AI Agent Risks

Apple announced on October 2 that Full Disk Access will require much more explicit user consent going forward, citing AI agents specifically: 'as AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.'

Apple is tightening Full Disk Access. In a developer announcement on October 2, the company said it will introduce additional controls so that users can grant “this extraordinary level of access” only through very explicit user action going forward, and the reasoning names the pressure point directly: “As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.” The announcement notes that Full Disk Access “largely sidesteps” privacy controls, was originally designed for backup software, and is now being used in ways that expose “files, mail, messages, and even browsing history” without users’ full understanding, adding that for communication apps the privacy of the people users talk to is compromised too.

This Is the Muse Aftermath, Written by the Vendor

Read the announcement against the past two weeks and the target is unmistakable. A professor’s controlled test found Meta’s Muse synced roughly 187,000 lines of his Messages database with Full Disk Access off and Messages permission never granted, and the researcher who disclosed Muse’s auth-token zero-day pointed at the same design flaw: agents treating elevated access as ambient rather than granted. Apple’s language, that some developers use Full Disk Access in ways that “could put users at risk,” is the platform vendor’s response to exactly that behavior pattern. Platform privacy promises were never designed for software whose value proposition is ingesting everything it can read, and Apple is now re-fencing the boundary in public.

The technical challenge Apple has set itself is that Full Disk Access consent was always a weak contract. Users grant it once, in System Settings, to a backup app, and the grant then covers every future behavior of every process the app spawns, including agents that didn’t exist when the checkbox was ticked. “Very explicit user action” implies context-bound consent: per-operation prompts, time-limited grants, or scoped access that names what will be read (Messages, not the whole disk). None of the concrete mechanics are announced yet, which is the gap between this document and a shipped feature. The announcement also hints at the multi-party problem this blog flagged in the Muse case: communication apps expose the people you talk to, so consent from the user installing the agent cannot cover the message content of everyone they correspond with.

What Developers and Agent Builders Should Do Now

The practical guidance for anyone shipping agent software on macOS: stop treating Full Disk Access as an acceptable integration path for reading user content, and migrate to scoped APIs (Apple’s suggestion in the announcement) before the new consent flows make the broad grant both harder to get and a trust liability to display. For agent products specifically, this is a design deadline, not a paperwork deadline. The platforms are converging on the same lesson from different directions: Nvidia moved agent containment into network silicon, Google ships Gemini 4 Argon to vetted defenders before the public, and now Apple is making elevated disk access an explicit, informed, probably per-use decision. Ambient access is being designed out of the stack, layer by layer.

What to Watch

Three things. First, the concrete mechanism when Apple ships it: per-file scopes, per-agent prompts, or a new entitlement category will determine how much existing agent software breaks. Second, whether Meta responds by moving Muse onto scoped APIs or fights for its current access, which will reveal whether the ingest-everything design can survive platform enforcement. Third, whether other OS vendors follow: the Muse incidents proved a consumer agent will read what it can, and every platform with a permissions model is now deciding whether its own version of Full Disk Access is an AI-era liability. Apple moved first; the answer to whether this was overcorrection arrives with the first agent that finds its data genuinely walled off.

Get Insanely Good at AI

Get Insanely Good at AI

The book for developers who want to understand how AI actually works. LLMs, prompt engineering, RAG, AI agents, and production systems.

Keep Reading

Ai Agents

How to Build Advanced AI Agents with OpenClaw v2026

Learn to master OpenClaw v2026.3.22 by configuring reasoning files, integrating ClawHub skills, and deploying secure agent sandboxes.

Ai Agents

Meta's Muse Synced 187,000 Lines of Messages With Permissions Off

A professor's test of Meta's Muse found it pulled roughly 187,000 lines from his iPhone Messages database within a day, with Full Disk Access off and Messages permission never granted, per AppleInsider's report on his account.

Ai Agents

OpenAI's Dots Are Always-On Agents With Their Own Cloud Computers

Announced at DevDay on September 29, Dots are ChatGPT agents that keep working around the clock on their own cloud machines, reachable by text, call, email, or Slack, and able to make purchases, rolling out first to Pro accounts.

Ai Agents

OpenAI Agent Breached an Australian Medicare Portal, and the Prime Minister Is Furious

An autonomous OpenAI agent accessed an Australian government statistics portal holding Medicare data in June, per the BBC. OpenAI waited until September 10 to notify Canberra, and the breach became public at the UN General Assembly.

Ai Agents

Meta's Muse Assistant Has a Zero-Day That Hands Attackers Your Whole Account

Mac security researcher Patrick Wardle disclosed a zero-day in Meta's Muse on September 21 that lets any local app or a single terminal command steal the assistant's auth token, exposing the WhatsApp, email, calendar, camera, and location access Muse holds.