macOS Full Disk Access: What AI Agents Should Not Keep
Apple says tighter controls are coming. Audit broad disk permissions before agents make the risk harder to reason about.
Short answerKeep Full Disk Access only for core disk utilities; revoke it from AI agents unless the need is specific.
By JasonPublished Oct 6, 2026Last verified Oct 6, 20265 min read

If you use AI agents on a Mac, the decision is not whether Apple is right to add more friction. The useful question is which apps should still have Full Disk Access today, and which ones should lose it before Apple changes the approval flow.
Apple says Full Disk Access can largely bypass macOS privacy controls and expose files, mail, messages and browsing history. The company also says some developers are using the permission in ways that may put users at risk, and that future controls will require very explicit user action. Apple links this directly to more capable and autonomous AI agents.
That creates a practical split for indie builders and remote workers. Some Mac tools may need broad disk visibility to do their core job, especially backup-style utilities. But an assistant, communication app or coding agent often has a narrower task: one project folder, one workflow, one chat context. Giving that class of app broad local visibility changes the risk profile.
Our answer: keep Full Disk Access only where the app’s main function depends on broad disk access. Revoke it from AI agents unless you can name the exact workflow that needs it.
What changed
Apple says it will add more controls around Full Disk Access on macOS. The company describes the permission as an extraordinary level of access that largely bypasses privacy controls so backup apps and similar tools can work.
Apple also says some developers are using Full Disk Access in ways that could put users at risk, including exposure of files, mail, messages and browsing history. For communication apps, Apple says the issue can also affect the privacy of people the user communicates with.
The AI-agent angle is explicit. Apple says that as agents become more capable and autonomous, the risks tied to this level of access will grow. The company has not described the exact future interface or policy details, only that granting the permission will require very explicit user action.

Why AI agents make this harder
A normal utility with broad access is already sensitive. An agent adds a second layer: it interprets instructions and may take actions across a workflow. If it has Full Disk Access, the user has to reason not only about what the app can see, but what future agent behaviour might do with that visibility.
Daring Fireball frames this as a Mac-versus-iOS expectation problem. On iPhone and iPad, according to Daring Fireball, a user can approve app prompts without giving an app the same kind of access to email or end-to-end encrypted messages. macOS is different: Full Disk Access can give an app a much wider view of the machine.
That difference matters for remote workers and small teams. A Mac may contain source code, client documents, message archives, browser history and personal files. Apple’s note does not say every agent is abusing access. It says the permission is broad enough that misuse or misunderstanding can expose data users may not expect to be in scope.
What should keep Full Disk Access
Keep it where the app’s basic job plausibly requires broad local visibility. Apple’s own example is backup software. If a tool exists to copy, inspect or protect the whole Mac, Full Disk Access may be part of the core function.
The same logic may apply to some system utilities, but the standard should stay concrete: can the tool do its stated job without seeing broad parts of the disk? If the answer is yes, it probably should not keep this permission by default.
What to revoke first
Start with apps where the permission is broad but the task is narrow:
- AI agents that mainly work inside one project folder.
- Communication apps that do not need to inspect the whole disk.
- Assistants where the reason for Full Disk Access is vague.
- Tools you installed once, granted access to, and no longer actively use.
This is not a claim that every app in those groups is unsafe. It is a scope argument. If you cannot explain why the app needs broad disk visibility, remove the permission and re-grant later only if a necessary feature breaks.
A practical audit checklist
- Open macOS privacy settings and review the Full Disk Access list.
- Keep access for backup-style tools or system utilities whose core function depends on broad disk visibility.
- Remove access for agents and assistants unless you can name the exact workflow that requires it.
- Prefer project-folder access over whole-disk access when the app supports narrower access.
- Re-check after Apple ships the new controls, because the approval flow may change.
The useful stance is not panic. It is least privilege. Give an app the smallest access that still lets it complete the task you actually hired it to do.
Our read: treat Full Disk Access as a broad Mac permission that deserves a regular audit, not as a convenience toggle for every AI helper. Apple’s own post is direct about the scope: the permission can bypass normal privacy controls and expose local data categories that many users would not mentally group together. That is enough to justify checking the list now, even though Apple has not described the exact future controls.
For builders, the operational risk is not just one mistaken prompt. If an agent can see broad local data, then an unclear instruction, an over-broad workflow, or a poorly explained connector can expand from a project task into access to mail, messages, files and browsing history. The right default is narrow access: project folders, explicit file selection, or task-specific integrations where possible. Full Disk Access should stay reserved for tools whose purpose plausibly fails without it. If an AI agent asks for it, the burden of explanation should sit with the agent vendor and the specific workflow, not with the user’s general willingness to trust automation.
Keep Full Disk Access only for core disk utilities; revoke it from AI agents unless the need is specific.
This is a permission-audit moment, not a reason to stop using macOS agents. Apple’s statement gives enough basis to tighten your own defaults before the platform does.
Skip the audit only for Macs where you already know every app with Full Disk Access and can justify each one.
Read next
Follow new articles
Email updates are not live yet, and we are not collecting addresses. To follow new articles, use the RSS feed.