Analysis
Apple said it's adding new controls around macOS's "Full Disk Access" permission, warning that the risks of granting that level of system access "will grow substantially" as AI agents become more capable and autonomous, TechCrunch reported. Full Disk Access -- originally built so backup software could function properly -- lets an app read files, mail, messages and browsing history; Apple said "some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems... without users' full knowledge and understanding," per Bloomberg.
A Specific Incident Behind a General Warning
Apple's announcement comes shortly after a Wired report that a flaw in ChatGPT's Mac app could have let hackers access sensitive user data, and amid the broader rise of always-on AI agents -- Meta's Muse and OpenAI's Dots among them -- designed to act autonomously across a user's files and apps rather than respond to a single prompt. Pulse tracks OpenAI's agent products on its company hub. Both products are the kind of software Apple's new controls are aimed squarely at: agents that need standing, broad access to do their job rather than one-off permission grants.
“Pulse tracks OpenAI's agent products on its company hub.”
Why This Is a Platform Story, Not Just a Privacy Patch
Apple controlling how much system access any app -- AI agent or otherwise -- can get is the same gatekeeping role it has long played with App Store review and iOS permissions, now extended explicitly to agentic AI on the Mac. Going forward, Apple says only users who "genuinely wish to grant an app this extraordinary level of access" will be able to, through "very explicit user action," rather than a single click-through dialog. That's a meaningful friction point for any AI agent startup whose product depends on broad file access to be useful.
What the Headline Misses
Apple's framing puts the responsibility on "some developers" misusing Full Disk Access, not on any single named company, and the company hasn't announced specifics on what the new consent flow will look like or when it ships. The risk for AI-agent developers isn't just Apple's rule change itself -- it's the precedent: if Microsoft and Google follow with their own agent-specific permission gates on Windows and Android, every agent product leaning on deep system access faces a wave of new consent friction roughly at the same time, independent of its own user growth strategy.