Apple plans tighter Mac disk access controls as AI agent risks grow
By Automate Basics, written with AI from The Verge's original

Apple plans to make full disk access on Macs harder to grant as AI agents gain the ability to act more independently, The Verge reports. The change matters to anyone who uses apps that can work with files, messages or other information on a work Mac.
What is changing with Mac full disk access?
Apple says it is preparing new controls that will require a particularly clear action from a user before a Mac app receives full disk access. The Verge reports that Apple is responding in part to the growing risks posed by AI agents. Apple has not said when the controls will arrive.
Full disk access lets an app reach broadly across a Mac, including information such as files, mail, messages and browsing history. Apple says the permission has allowed backup apps to do their jobs, but it can also bypass privacy protections that would otherwise limit what an app can see. The concern for people using AI at work is not just what an agent is asked to do. It is also what information the agent's app has permission to access while doing it.
Who can use the new Mac controls?
Mac users who grant apps full disk access are the people affected by Apple's planned change. That includes people considering whether an AI agent needs broad access to a work computer. The Verge does not identify a macOS version, a qualifying plan or a release date for the new controls. Its report also gives no price information.
The proposed limit concerns an existing Mac permission, not a newly announced AI service. Apple says some developers use full disk access in ways that may expose more of a person's information than they understand. For a workplace user, the practical distinction is between allowing an app to handle a particular task and allowing it to reach much of the computer. The new controls are intended to make that wider choice more deliberate.
How do I assess an AI agent on a work Mac?
A sensible first task for a Mac AI agent is one that does not require access to everything on the computer. Before giving an app full disk access, check whether the task truly calls for it and what kinds of work information the app could then reach. Apple identifies files, mail, messages and browsing history as information that broad access can expose.
If an app produces a useful result, check the result for information it should not have drawn from elsewhere on the Mac. That check cannot, by itself, show everything the app accessed, so the permission decision still matters. The Verge reports that Apple has not provided a rollout date or details of what the new approval process will look like. For now, do not assume the planned controls are already in place.
Frequently asked questions
What does full disk access let a Mac app see?
Full disk access gives a Mac app broad reach across the computer. According to Apple's account reported by The Verge, that can include files, mail, messages and browsing history. Apple says the permission helps backup apps work, but its breadth can also expose information users did not intend to share.
When will Apple's new full disk access controls arrive?
Apple has not given a rollout date, according to The Verge. The company says the planned controls will require especially clear user action before an app can receive full disk access. The report does not describe the approval process in enough detail to say what Mac users will see.
Related reading
Meta opens Muse code for building custom AI devicesMeta has released code for connecting its Muse AI agent to hardware people build themselves. The Verge reports that possible projects include a reminder display, while a separate Muse Home Link device can use community-built skills to control connected equipment.
Apple plans tighter Mac file access controls as AI agents spreadApple plans new controls for macOS Full Disk Access, a permission that can expose files, mail, messages and browsing history to an app. The change matters to people using AI agents on work Macs.
Circuit Breaker Labs builds AI users to test chatbot safetyCircuit Breaker Labs has built simulated AI users to test whether chatbots handle psychologically risky conversations. TechCrunch reports that the company is using the product with makers of AI coaching, journaling and mental health support apps.
Written with AI from The Verge's original and published after automatic checks: every figure here appears in the original, and no sentence is copied from it. The picture is AI-generated. The original is the authority.
Source: Apple will limit Mac disk access as AI agents ‘substantially’ increase risk, The Verge, 2 Oct 2026.