# Apple Promises to Neuter Full Disk Access to Combat Rogue AI Agents

> Source: <https://eshumarneedi.com/2026/10/02/apple-promises-to-neuter-full.html>
> Published: 2026-10-03 03:42:09+00:00

We give developers powerful APIs to build incredible capabilities into their apps for Apple products, backed by a set of controls designed to protect users’ private data. Full Disk Access largely sidesteps these controls in order to allow backup apps to function properly on the Mac. Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.

Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action. Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.

Full Disk Access gives an app permission to open any file on a user’s computer; without it, apps are limited to folders they have explicitly been given permission to access. The vast majority of apps — power-user oriented or not — do not require Full Disk Access. On my MacBook Pro, I have given Full Disk Access to eight apps: Alfred, AppCleaner, CleanMyMac, Hyperspace, iTerm, Raycast, and Terminal. Three of these apps are “cleaning” apps, two are Terminals just so I can browse the file system in peace, and two are app launchers. None of these apps are mainstream — I don’t think the average Mac user installs disk cleaners or third-party app launchers.

Regardless, I think this news should force developers to think about whether their apps truly deserve Full Disk Access. Cleaning apps, backup apps like Backblaze, and terminal emulators all require Full Disk Access because they usually look in the Library and home folders. App launchers don’t search `~/Library` or hidden directories by default, and when I want to look there, I’m usually using a terminal or Finder anyway. Maybe others use their Macs differently, but the point I’m trying to make here is that it is probably for the better to heavily restrict unfettered read access to the file system in the age of artificial intelligence agents. There are few uses for such access.

For instance, AI agents, like Muse, should not have access to the SQL database of iMessages on a person’s computer. It’s against Apple’s iMessage terms of use for agents to send iMessages, and it’s bad manners to hand over encrypted chats to an unencrypted cloud agent. Jason Aten at Inc. [reported in September](https://www.inc.com/jason-aten/metas-new-muse-ai-agent-read-my-private-messages-i-never-asked-it-to/91408202) that Muse not only found his local Messages database, but also used it to do background research on him without his permission. Over 180,000 rows of Aten’s messages — from people who never consented to have their data sent to Meta’s servers — were scraped by Muse, whose privacy policy, in typical Meta fashion, is unacceptably lenient. Full Disk Access permits any app — signed or unsigned, sandboxed or not — to read a person’s entire Messages history, among many other sensitive files that even individual users don’t know are on their Macs. It’s just too much access.

This kind of access ought to be heavily restricted and almost onerous to enable. Yes, I think it should be possible to permit it, but it should be as difficult as disabling System Integrity Protection on a non-Apple silicon Mac. (Disabling SIP lets third-party apps and end-users *modify* hidden files. In the age of AI agents, I think read-only access should be just as well protected.) Perhaps this should be locked behind a developer mode or even an entitlement granted by Apple to trustworthy apps. All other apps that would benefit from viewing most, but not *all*, user-facing files should have a lower yet still permissible level of access to common directories, like `~/Desktop`, `~/Applications`, and `~/Documents`. Most apps ask for Full Disk Access just so users don’t have to hit Allow on every one of these permission prompts; Apple should conceive a way where one can grant access to these common folders while forgoing sensitive items in, say, `~/Library`. This is an imperfect solution, but one I think is desperately needed nowadays.
