Apple has announced plans to tighten controls around Full Disk Access (FDA), a macOS permission that grants applications unrestricted access to system-protected areas and sensitive user data. The company says the move is driven by growing risks tied to AI agents that are increasingly capable and autonomous.
Full Disk Access was introduced in macOS Mojave (10.14) and can be managed under Apple menu > System Settings > Privacy & Security. By default, macOS restricts apps from touching protected system areas and private user data. Once a user grants FDA to an application, that software can read or modify files including mail, messages, and browsing history.
Why Apple Is Acting Now
According to Apple, some developers are using FDA in ways that put users at risk, exposing files, mail, messages, and browsing history without users fully understanding what they are consenting to. The company noted that for communication apps specifically, this also risks exposing the privacy of the people a user is messaging with, not just the user themselves.
Apple said that as AI agents become more capable and autonomous, the risks tied to this level of system access will grow substantially. The company is committed to ensuring users clearly understand what they are granting before FDA is approved, so they can make informed decisions about their own data.
Apple has not disclosed a timeline for when the new controls will roll out, nor has it detailed the exact technical changes planned.
Context: The Meta Muse Dispute
The announcement follows a report from tech journalist Jason Aten, who said Meta’s personal assistant app Muse accessed his private iMessages even though he believed Full Disk Access was disabled on his system. Meta executives disputed the claim, stating that both Full Disk Access and a separate Messages connector must be explicitly enabled by the user for such access to occur.
What Security Teams Should Know
Full Disk Access remains one of the most powerful permissions on macOS, and its abuse by malicious or poorly vetted applications can expose an organization’s communications, credentials, and browsing activity. Security teams managing fleets of Mac endpoints should audit which applications currently hold FDA, particularly AI assistants and third-party productivity tools, and reassess those grants once Apple’s new consent controls become available.
