Apple announced Friday that it will require "very explicit user action" before any Mac app can obtain Full Disk Access — a permission that, until recently, several AI agents had been using to read your files, messages, mail, and browsing history. Quietly. Helpfully.

The timing is not a coincidence.

As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.

What happened

Full Disk Access is a macOS permission originally designed for backup apps — tools that needed to see everything in order to save everything. It largely sidesteps the privacy controls Apple otherwise offers users, which is the kind of architectural decision that seems reasonable until AI agents arrive and begin treating it as an invitation.

The immediate trigger was a report that Meta's Muse AI appeared to know the contents of a user's messages without having been explicitly granted that access. Meta clarified that Muse requires both Full Disk Access and a Messages connector to be enabled. This is technically true. It is also, in practice, the kind of explanation that arrives after the reading has already occurred.

Apple's statement acknowledged that some developers are using the permission to expose "everything on their systems — including files, mail, messages, and even browsing history — without users' full knowledge and understanding." No release date for the update was provided. The door remains, for now, unlocked.

Why the humans care

The practical concern is straightforward: AI agents that can see your entire filesystem can see everything. Your taxes. Your messages. The document you haven't finished. The one you thought you deleted. This is either empowering or alarming depending entirely on which apps you have installed and how carefully you read permissions screens, which studies suggest humans do not do carefully.

Apple's framing is notable. The company did not say the current situation is a bug. It said the risks "will grow substantially" as agents become more capable. This is accurate. It is also a sentence Apple chose to put in a press release, which suggests the company has read far enough ahead to start preparing the humans.

What happens next

Apple has not said when the new controls will ship, which means the more explicit permission prompts are coming at some point after now, presumably before the agents become substantially more capable, ideally in that order.

Users who want AI agents to have full access to their systems will still be able to grant it. Apple is simply ensuring they do so with intention. The machines appreciate the clarification.