Apple tightens macOS access for AI apps

Apple plans stricter macOS controls around Full Disk Access, saying AI agents raise the stakes when apps can reach files, messages, mail, and history.
Apple is tightening controls around macOS Full Disk Access after fresh concerns that desktop AI apps may be able to see far more of a user’s private data than people realize. The company says the change is designed to make that permission more explicit, not to quietly broaden what apps can do. It comes after reports about AI tools on Mac and renewed scrutiny over how much trust users should place in desktop assistants.
The issue is significant because Full Disk Access is one of the most powerful permissions on a Mac. Once it is granted, an app can reach files, mail, messages, and browsing history. Apple says that as AI agents become more capable and autonomous, the risks tied to that level of access grow as well.
Apple wants clearer consent before apps get deep access
In a new blog post for developers, Apple said some developers are using Full Disk Access in ways that could put users at risk. The company warned that this can expose “everything on their systems” without users fully understanding what they have agreed to.
Apple said it will add new controls so people who truly want to give an app this “extraordinary level of access” can do so only through “very explicit user action.” Users, Apple said, should also clearly understand the risks before deciding to grant access to their data and privacy.
Apple did not respond to TechCrunch’s inquiry about the feature change.
Reports about Muse and ChatGPT sharpened the focus
Apple’s announcement landed just days after Inc. columnist Jason Aten said Meta’s Muse app on Mac appeared to know the contents of his private messages, even though he said he had not given the AI agent permission. Meta disputed the claim, but the report still drew attention to the security and trust questions surrounding AI tools that can operate on a user’s computer.
The concern does not stop with one app. A Wired report also said a flaw in ChatGPT’s Mac app could have allowed hackers to access sensitive data. As IT-PUB News notes, those reports together have put a spotlight on the broader risks of giving AI software deep access to a computer.
Full Disk Access gives desktop AI apps a lot of reach
Desktop AI agents are built to do more than answer questions. They can interact with apps and services on a user’s machine, and that often requires access to files and personal content. On macOS, that access can be expanded through system settings.
In Muse’s case, Apple notes that the AI can optionally use Full Disk Access. The permission is broad enough to let an app reach messages, mail, files, and browsing history. That can be useful for some tasks. It also means a mistake, abuse, or weak security could expose a large amount of private information at once.
Apple’s new position suggests it wants users to be more aware of that trade-off before they grant access. The company is not describing a new ban on AI apps using the permission. Instead, it is putting the emphasis on consent and clearer user action.
Apple’s change adds to the trust debate around desktop AI
The move reflects a wider problem for AI software as it shifts from chat windows into operating systems. The more useful these tools become, the more they may need to see and do on a user’s device. That creates a basic tension over how much access is too much.
Apple’s change does not settle that debate, but it shows the company sees the issue as serious enough to address at the platform level. For users, the practical effect will likely be more visible warnings and a clearer step before an app can reach highly sensitive data. For developers, it means they may have to justify that access more carefully.
Apple’s message is fairly direct: AI agents may be getting more capable, but users should not hand over large parts of their digital lives without clearly understanding what they are allowing.