Apple is changing how full-disk access permissions work to curb abuse by AI agents. What we know, what we don't, and why it matters on your Mac.
Apple is changing how full-disk access permissions work, with the stated aim of curbing abuse by AI agents, according to Ars Technica's report. The text of the article was not available to us when we wrote this, so we are working from the headline alone. We will not pretend to know the technical details, the rollout dates or which apps are affected.
Even so, the direction is worth discussing. Full-disk access is one of the most powerful grants a macOS user can hand to an application. It was designed for backup tools, antivirus software and sysadmin utilities: programs that genuinely need to read everything. It was not designed for software that decides on its own what to open, summarize or send somewhere.

That is the tension agentic tools create. An assistant that can browse your files, run commands and chain actions is only useful if it has broad access. But broad access, granted in one click, is exactly what makes a misbehaving or manipulated agent dangerous. A prompt hidden in a document or a web page could steer an agent that already holds the keys to the whole disk.
Our reading is that Apple is trying to move from "all or nothing" toward something more granular and more visible to the user. That fits a pattern we have seen in the industry, where AI assistants and workplace AI tooling are spreading faster than the permission models underneath them. Treat that as our inference, not as something the source confirms.
What to watch
- Whether legitimate tools such as backup and security software need to reauthorize after the change.
- Whether agent-style apps get a narrower permission path instead of full-disk access.
- How clearly macOS tells you what an app can actually reach once you approve it.
Until the details are public, the practical advice is boring and sound: review which apps already hold full-disk access in System Settings, and revoke anything you no longer use. Before you give any AI agent that permission, ask whether it really needs the whole disk or just one folder. The original coverage is where to look for specifics as they emerge.
Our take: it is a sensible move, and a late one. Operating systems spent years teaching users to trust a permission prompt; agents turn that prompt into a blank check. Tightening it is less a feature than a repair, and we would rather see Apple fix the model now than after the first headline-grabbing incident.
Original source: Ars Technica
Produced with AI support and reviewed by the newsroom



Comentarios
Publicar un comentario