Skip to content
News

Apple is changing Full Disk Access on Mac: safer from AI agents, but backup apps may feel it

Apple has said it will add new controls to Full Disk Access on the Mac, so that people can grant it only with “very explicit user action”. Nothing changes on your Mac today. Apple gave no date and no design, and named no app. It says AI agents, apps that carry out tasks for you on their own, are the reason: the risks of this access will grow substantially as agents become more capable and autonomous.

Full Disk Access is a permission in macOS, the Mac’s operating system, that lets an app access all files on your computer, including data from other apps such as Mail, Messages and Safari, and your Time Machine backups, the Mac’s built-in backup. Today you give it yourself in System Settings, under Privacy & Security, by adding the app to the Full Disk Access list. Apple hasn’t said what the new step will look like, which version of macOS gets it, or whether apps that already hold the permission keep it.

Apple’s reasoning starts with how the permission was built. It says Full Disk Access largely sidesteps the privacy controls designed to protect your data, because backup apps need it to work properly. It also says some developers use it in ways that could expose files, mail, messages and browsing history without users fully knowing or understanding it, and that, for communication apps, this can also compromise the privacy of the people the user is talking to.

About two weeks earlier, Jason Aten, a tech columnist, wrote that Meta’s Muse agent read his private messages though he never asked it to, and says Full Disk Access was off. Meta disputes that. It says Muse can read Messages only if a user turns on both Full Disk Access and a Messages setting inside Muse. Apple hasn’t linked its announcement to that dispute. On 25th September we covered Muse and the Muse Charm, the pocket device Meta announced for it, and on 29th September the tools Nvidia launched to keep agents inside the limits their owners set.

What gets better

If the new step does what Apple describes, it should put the risk in front of the person before they approve. Apple’s own concern is that people don’t fully know or understand what the permission exposes. Apple commentator John Gruber writes that on an iPhone no permission lets an app read your email or end-to-end encrypted chats, while on a Mac an app that has been granted everything it asks for reaches almost everything on the startup drive. He thinks many people assume the Mac protects them the way their phone does.

The messages on your Mac also include what other people wrote to you, and the people who wrote them weren’t asked. So once this ships, an AI agent that wants your messages should have to clear a bigger hurdle than being added to a list.

What could be lost

Backup apps and AI agents ask for the same permission, so a step added to the permission reaches both. Apple’s post ties Full Disk Access to backup apps, and Mac users’ own lists show wider use. Writer John Voorhees’s Mac has granted it to Alfred, a launcher driven by hotkeys and keywords, the file manager Bloom, the text-selection tool PopClip and Hazel, a tool that organises files automatically. A user on a Mac forum lists the backup app Carbon Copy Cloner, the antivirus app ClamXAV, the file-search app Find Any File and Terminal, Apple’s built-in app for typing commands.

Scheduled backups and file automation can run when nobody is at the keyboard. If the new step comes up each time an app runs, they would stall until someone clicked. A one-time approval when you add the app wouldn’t have that problem. Apple hasn’t said which it will be, and Gruber says he fears something like it, a manual approval every time an app does something.

Apple’s post also leaves open which apps get the permission at all. Its wording implies that people who genuinely want to grant it still can, and it mentions no ban and no list of approved apps. People who deliberately run an agent on their own files will probably face a harder setup too, which looks like the aim.

You can see which apps hold the permission now in System Settings, under Privacy & Security, then Full Disk Access. We think Apple is right to go after agents, because the people whose messages sit on your Mac weren’t asked about an agent reading them. The test is whether someone who knows what they’re doing can approve an app they trust once and have it keep working, or gets the step back every time.

The Analyst

The Analyst delivers in-depth, data-driven insights on technology, industry trends, and digital innovation, breaking down complex topics for a clearer understanding. Reach out: Mail@Tech-ish.com

Join the discussion

0 comments
posting as Ndovu Mkubwa

Anonymous by default — no sign-up or email needed. Prefer to be recognised? Add a name or email above, your call. We don't email you about replies, so do check back.

protected, no CAPTCHAs
Back to top button