Apple to Tighten macOS Permissions as AI Agents Request Full System Access
The company warns that desktop AI tools risk user privacy by seeking broad disk privileges without clear user understanding.

Apple is preparing to add new safeguards to macOS security permissions to counter privacy risks created by autonomous AI agents, according to a report by Engadget .
In an update regarding developer practices, Apple warned that third-party desktop tools requesting "Full Disk Access" can expose sensitive user information without individuals fully understanding the scope of access granted. The company stated that upcoming operating system enhancements will introduce additional controls to make granting such extraordinary access a more deliberate, explicit action.
Apple did not provide a release timeline or detail the specific user interface and permission changes it plans to implement. However, the company indicated that certain developers are not being transparent about privacy trade-offs when prompting users for system-wide access.
"Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users' full knowledge and understanding," Apple said. "For communication apps, this can also compromise the privacy of the people users are communicating with."
Desktop clients for AI agents, including OpenClaw, Dots, and Meta's Muse, often encourage users to grant Full Disk Access to parse local files, communications, and system applications. The broad exposure required by these autonomous tools has prompted some security-conscious users to run agents on dedicated secondary machines, a behavior that contributed to Mac Mini hardware shortages earlier this year.
Scrutiny around desktop agent permissions expanded recently following user reports involving Meta's Muse agent. Inc. columnist Jason Aten reported that the Muse application accessed his messages despite his belief that he had declined that permission. Meta responded by stating that if messages were synced, the user must have opted in.
Apple did not name Meta or specific applications in its warning, but emphasized that the rapid evolution of autonomous agents requires stricter platform-level boundaries.
"Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action," Apple said. "Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy."
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.

