Apple is rewriting the rules for one of the most powerful settings on a Mac. It is called Full Disk Access, and until now, turning it on for an app meant that app could see almost everything on the computer: files, mail, messages, browsing history, the works. Apple says it is adding stricter consent steps because AI agents have made that level of access far riskier than it used to be.
The timing is not a coincidence. Days earlier, a technology columnist testing Meta's new AI assistant, Muse, said the app had synced more than 187,000 lines from his private Messages conversations, even though he never gave it permission to access them. Meta disputed the account, but the damage was already spreading.
Amazon had separately blocked Muse from its shopping site around the same time, saying the agent was moving through customer accounts and purchase history without properly identifying itself. A few weeks before that, a security researcher found that OpenAI's ChatGPT app for Mac had been storing every conversation on the hard drive in plain, unprotected text. Any other program running on the same computer could potentially read it.
OpenAI fixed the flaw after the researcher went public, but the app had been shipping that way for months without anyone noticing. Put these incidents together and a pattern shows up fast. Every major AI company is racing to build assistants that live on your desktop and act on your behalf, reading inboxes, calendars, and messages, sometimes even bank accounts.
To do any of that, these apps need deep permissions that macOS was never really designed to hand out casually. Apple's old approach was a single checkbox: click once, and an app had the keys to everything, forever, until someone remembered to revoke it. That model made sense when Full Disk Access was mostly used by backup software.
It makes much less sense when the app asking for it is an AI system that can read your messages, decide what matters, and act on its own. Apple's fix is to make that approval harder to give by accident, requiring a more deliberate, explicit action before a user hands over that level of trust.
There is also a competitive angle Apple is not saying out loud. Meta and OpenAI are both shipping agents far more capable than anything Apple's own Siri can currently do, and both have now had public privacy stumbles. Tightening the gate on Full Disk Access lets Apple position itself as the cautious, privacy-first platform owner, even while its rivals' agents run on top of its operating system.
For any company already using or piloting desktop AI assistants, this should prompt an actual check, not just a read. Look at which apps on company laptops currently have Full Disk Access turned on, and ask whether anyone remembers approving it on purpose. Surveys already show that a large share of employees feed confidential work information into AI tools without telling anyone, often because the app made it easy and nobody set a rule against it.
Treat any request for this level of access the same way you would treat handing someone a master key to the office: fine for a trusted few, dangerous as a default setting.