Apple finally said the quiet part.
Full Disk Access on macOS is getting tighter, and the stated reason is AI agents. Apple posted an update on its developer site explaining that the permission exists so backup apps can do their job, and that some developers have been using it for things well outside that purpose. Going forward, Apple says it will add controls to make sure users who grant that access actually understand what they’re agreeing to. TechCrunch, AppleInsider, and Daring Fireball all read it the same way: this is a response to agentic apps asking for the keys to everything.
I review these tools for a living. I have granted Full Disk Access more times than I’d like to admit, usually because an agent framework threw a permissions dialog at me mid-setup and I wanted to get to the part where I test whether the thing works. That’s the pattern Apple is targeting, and honestly, it’s about time.
What the permission actually hands over
Full Disk Access is not a scoped grant. It’s not “let this app read the folder I pointed it at.” It covers the stuff macOS normally walls off from everything, including mail databases, message histories, browser data, and Time Machine backups. Apple built it for backup utilities because a backup utility genuinely needs to read your whole drive. That’s a narrow use case with an obvious justification.
An AI agent asking for the same grant is a different proposition. The agent reads files, but it also sends things somewhere. A model provider, a vector database, a logging endpoint, a telemetry pipeline nobody documented. Apple’s framing in the developer post is that users should understand the risk before granting access, and that’s the right framing, because the risk with an agent isn’t just local reading. It’s reading plus outbound.
Why I think this lands on the right target
The honest problem with agent tooling right now is that broad permissions are the path of least resistance for developers. Building scoped file access means thinking about which directories matter, writing a picker flow, handling the case where the user says no. Asking for Full Disk Access means none of that. One dialog, done, ship it.
I’ve tested agent tools where the setup docs literally say to enable Full Disk Access as step one, before explaining anything about what the agent does with files. No scoping. No explanation. Just a screenshot of System Settings with an arrow pointing at the toggle. When the easy path is also the overreaching path, you get overreach by default, and that’s not malice, it’s just friction doing what friction does.
Apple adding more consent friction flips the incentive. If the dialog gets scarier and more explicit, developers who were grabbing the permission out of convenience will have a reason to build the scoped version instead. That’s a win for users even if it’s annoying for the people shipping the tools.
What this means if you’re running agents today
Don’t wait for Apple. Go look at System Settings right now and see what’s in your Full Disk Access list. I did this recently and found three things I’d forgotten about entirely, including a CLI tool I tested once and never uninstalled.
- Revoke anything you don’t actively use. Nothing breaks that you can’t re-enable.
- For agent tools you keep, check whether they offer a scoped alternative. Some do and just don’t advertise it.
- Treat the permission request as a review signal. A tool that demands whole-disk access without explaining why is telling you something about how it was built.
- If a tool genuinely needs broad read access, ask where the data goes. The answer should be in the docs. If it isn’t, that’s your answer.
The part Apple hasn’t said
No rollout date. Apple hasn’t disclosed when these controls arrive, and the developer post doesn’t spell out what the new consent flow looks like in practice. “Additional controls” could mean a more detailed dialog, a periodic re-confirmation, a scoped middle tier, or something else. The gap between “we will introduce additional controls” and shipping behavior is where this either becomes meaningful or becomes another dialog people click through on autopilot.
That’s my one reservation. Consent screens have a terrible track record of actually informing anyone. We’ve all accepted cookie banners we didn’t read. If the new flow is just more words in the same box, the behavior won’t change much. If it’s structurally different, scoped grants, clearer disclosure of what the app can reach, it could reshape how agent tools get built on the Mac.
Either way, the signal matters. Apple naming AI agents as the reason means the overreach was visible enough from the outside to prompt a platform-level response. For anyone evaluating these tools, that’s useful information. The permissions an agent asks for tell you a lot about how carefully it was designed, and now the platform is going to make those asks harder to hide.
🕒 Published: