Apple, in a post to Developer News yesterday, announced it “will introduce additional controls” to Full Disk Access:
We give developers powerful APIs to build incredible capabilities into their apps for Apple products, backed by a set of controls designed to protect users’ private data. Full Disk Access largely sidesteps these controls in order to allow backup apps to function properly on the Mac. Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.
Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action. Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.
Apple doesn’t say it, but the timing strongly suggests this is in response to the recent revelations that Meta’s Muse was caught abusing its access to the macOS file system. No doubt similar concerns exist for other AI tools such as OpenClaw, Grok Bot, OpenAI Dots, Hermes, etc., all of which benefit from having unfettered access to your computer, and all of which can misuse that access, intentionally or not.
(But I’d wager a hotel-priced beverage it was Muse that drove Apple’s Friday morning announcement—the lack of details suggests it was written quickly, and there’s very little love lost between Apple and Meta. I’ll go further: I’ll bet Craig Federighi, Apple’s SVP of Software Engineering, was behind this post. He’s known to be bullish on AI and it wouldn’t surprise me at all to learn he toyed with Muse briefly until he saw that Meta was again being Meta, and made a late-night phone call to Susan Prescott (VP WWDR) and Greg Joswiak (VP Product Marketing) insisting Apple shut it down, shut it down now.)
Most people (and apps) don’t need Full Disk Access. My MacBook Air, on which I do most of my work, has 30 apps that have, at some point, requested Full Disk Access. I’ve only granted two of them that access (Terminal, Carbon Copy Cloner). The other 28 have never complained about the lack of access, and I’ve not noticed any loss of functionality when using them.
(In fact, I don’t recall any of those apps—save for Terminal—even asking me for Full Disk Access. For that matter, I’m not even sure why they would need such access. Why, for example, does 1Blocker, an ad-blocking tool, or SurfShark, a VPN, need access to my entire file system? Answer: They don’t. Either they’re asking for it just because or they’re being lazy. Or sneaky.)
I don’t expect Apple’s “additional controls” will “lock down” Full Disk Access, per se. For example, I doubt users would need to authorize it manually every time an app needs it, as John Gruber worries. Instead, for apps requesting Full Disk Access, I believe Apple will display a new dialog explaining the dangers of enabling it, along with a developer-supplied purpose string that describes why the app needs such access. You see this with permission requests for Location or Camera, for example. Apple would gate this access via a new Full Disk Access Capability and Entitlement, allowing Apple to review and approve (or not) apps that claim to need this level of access—and, equally importantly, rescind that access if the developer abuses it. One example is apps that want to access your contact notes, which Apple considers especially sensitive and for which it demands justification.
If Apple has time (or is especially motivated), it might also add more granular options to control what data apps can access. For example, instead of today’s single toggle that grants an app access to the broadly defined “data like Mail, Messages, Safari, Home, Time Machine backups, and certain administrative settings,” it might instead allow you to enable access to specific data on a per-app basis. This would allow, for example, Muse to access Mail and Safari, but not Messages or Time Machine.
This approach—a new permissions dialog, an Apple-gated entitlement, and more granular options—would give Apple and users more insight into why apps are asking for Full Disk Access and what data that access exposes. Power users would still have the control they demand, while less experienced users would have a better understanding of what they’re being asked to approve.
That’s a win-win.
