How we read the signal

Analysis frame

Evidence level

Primary-source evidence

Analytical lens

Test whether broad operating-system permission matches the user's specific purpose when an autonomous agent can inspect and combine data across apps.

Affected groups
  • Mac users and their correspondents whose private records could be accessed
  • Backup, accessibility and agent developers who depend on legitimate file access
What remains unknown
  • Apple has not specified the new controls or launch date
  • No public evidence yet shows how often AI agents misuse Full Disk Access on Mac
Second-order effects to watch
  • Developers may redesign agents around scoped, temporary permissions instead of persistent system-wide grants
  • Extra approval friction could protect privacy but also make vital backups or accessibility workflows harder

A single yes can be too broad

Apple says Full Disk Access can expose files, mail, messages and browsing history. Communication apps can also expose other people's privacy, not just the account holder's.

The company has promised additional controls requiring very explicit user action. It has not yet said when they ship or what limits they enforce.

Consent needs boundaries after the click

A useful agent may need one document, not a whole disk. Permission can be bounded by file, purpose, time and revocation; otherwise convenience grants persistent reach unrelated to the task.

The counterpressure is legitimate software: backup and accessibility tools sometimes need broad access. The best design will test actual scope and recovery rather than treating all such apps as suspect.

Primary trail

Go to the source

Read the evidence behind this analysis. External links open in a new tab.

Apple Developer — Updates to Full Disk Access in macOS Apple Developer — App Sandbox overview