Apple Rethinks a Blanket Permission on the Mac
Apple is preparing to overhaul one of the broadest permissions a Mac user can hand to a third-party application. According to the company, updates are coming to "Full Disk Access," the setting that lets apps reach deep into a machine's email, messages and file systems all at once. Under the revised approach, Macs will explicitly ask users whether they want to grant an outside app access to a specific part of their system rather than approving everything in a single stroke.
The motivation is not abstract. Apple says it is responding to the surge of AI agent applications that have been tapping into private data on Macs — a category exemplified by Meta's Muse, which the company cites as a driving example behind the change. The announcement amounts to an admission that the permission model Apple built for traditional software no longer fits software that acts on its own.
How Mac Permissions Were Supposed to Work
Apple's existing framework is built around discrete, contextual requests. When a user installs a third-party app that needs a particular capability, the app must ask for it, and the user must agree before that capability becomes available. A webcam app, for instance, is required to request permission to use the Mac's camera and audio devices. Nothing happens until the person at the keyboard says yes.
Full Disk Access functions as a shortcut around that piecemeal approach. Some tools genuinely need to see the whole picture rather than a single slice of it, and Apple created the setting so those apps could make one request instead of many. That is where the trouble begins, because the categories covered by Full Disk Access include:
- Email stored on the machine
- Messages and conversation history
- File systems and the documents held inside them
- The broad range of system functions a backup-style app needs to do its job
For a conventional backup utility, that scope is the entire point. For an AI agent, it is a doorway into a person's most sensitive daily records.
The Difference Between a Tool and an Agent
A traditional app does what it is told and stops. An AI agent runs autonomously, stringing together tasks and decisions with limited user oversight. That distinction is central to Apple's rethink. The company is positioning the change specifically around the rise of agents and the hazards that come with giving them unrestricted access to a user's private data — hazards that people downloading a helpful-looking assistant may not fully grasp when they click through a permission prompt.
The Muse Episode That Brought the Problem Into Focus
One widely circulated anecdote helps explain why Apple felt compelled to act. Jason Aten, a columnist at Inc., discovered that Meta's Muse assistant had somehow synced his entire local Messages database and was drawing on those conversations as context for the tasks it performed. Aten says he never granted Muse permission to reach his Messages. Meta's position is that such access would be impossible if a user genuinely declined the request.
Whatever the precise mechanics, the episode illustrates the friction at the heart of agentic software on the desktop: a user can believe they said no while data still flows to the assistant. Multiply that uncertainty across millions of installs — Muse alone recently passed 5 million downloads — and the scale of the exposure becomes easier to see. Apple points to that trajectory, along with the sheer risk of handing full access to a person's complete private data, as the reason the update is happening now.
Why Granular Prompts Matter
The shift Apple describes is essentially a move from an all-or-nothing switch to something closer to a series of smaller decisions. If a Mac asks whether an app should reach a particular part of the system, a user has a chance to think about the trade-off before it is made for them. That is a meaningful change for anyone who has ever approved a permission dialog without reading it — which is to say, almost everyone.
It also puts pressure back on the developers of AI agents. An assistant that wants to read mail, scan messages and index files will now need to justify each of those requests separately, and users can decline the ones that feel unnecessary. Agents that can complete a much wider range of tasks when they hold Full Disk Access will not lose that ability outright, but the path to obtaining it becomes narrower and more visible.
Autonomy Is the Wild Card
The deeper issue is that autonomy makes permission decisions hard to evaluate in advance. A conventional app's behavior is largely predictable from its purpose. An agent's is not, because the agent decides what to do next. Users may not understand the cybersecurity implications of granting that kind of authority, and Apple's framing suggests the company sees education, not just enforcement, as part of the fix.
A Wider Anxiety About Agentic AI
Apple's move lands alongside growing unease about what happens when autonomous software gains access to private accounts and records. That concern extends well beyond the desktop: Mashable has also reported that big banks are worried AI agents could increase the risk of scams and fraud. Financial institutions and platform owners appear to be arriving at the same conclusion from different directions — that agents acting on a user's behalf create openings that older security assumptions did not anticipate.
What Comes Next for Mac Users
For now, the practical takeaway is straightforward. Mac owners should expect more permission prompts, not fewer, and they should read them. The controls Apple is adding are designed to make the boundaries of an agent's reach explicit, so that granting access to a specific slice of the system is a deliberate choice rather than an incidental one.
The larger signal is that the era of treating an AI assistant like any other downloaded app may be closing. Apple built Full Disk Access for tools that needed everything at once. As agents that act on their own become mainstream, the company is signaling that the permission system has to grow more careful — and that users, once again, will be the last line of defense.
This article is based on reporting by Mashable. Read the original article.
Originally published on mashable.com








