AI security
Apple to tighten Mac Full Disk Access over AI agents
Apple says AI agents make Full Disk Access too risky to grant casually. How the permission works, and how to audit and lock it down on your Macs now.
On October 2, Apple posted a notice to its developer news site saying it will add controls to Full Disk Access (FDA), the macOS privacy setting that lets an app read data the rest of the system keeps fenced off. Apple wrote that some developers are using FDA "in ways that could put users at risk," exposing files, mail, messages and browsing history "without users' full knowledge and understanding," and that the risk "will grow substantially" as AI agents become more autonomous. Future grants will need "very explicit user action." Apple gave no macOS version and no date.
The notice followed a month of trouble around Meta's Muse, an AI assistant whose Mac app can use FDA to read the Messages database. Any Mac where staff have installed a desktop AI agent, or where developers run command-line agents inside a terminal that holds FDA, is in scope. Nothing changes on your fleet until Apple ships the new controls, so the audit is yours to do now.
How Full Disk Access works
macOS gates sensitive data through a framework called Transparency, Consent and Control (TCC). Most apps ask for narrow permissions one at a time: Contacts, Calendar, the Desktop and Documents folders. FDA, added in macOS Mojave (10.14), sits above all of those. Apple's own description is that it lets an app "access all files on your computer, including data from other apps (for example, Mail, Messages, Safari, and Home), data from Time Machine backups, and certain administrative settings for all users on this Mac." Apple says it exists so backup software can work, and that it "largely sidesteps" the finer controls.
Two properties matter for AI agents. First, the grant is per app, not per task: once an agent holds FDA, every instruction it follows runs with that reach, including instructions planted in a web page or email it reads (prompt injection). Second, TCC charges file access to the "responsible code," which is usually the app that started the process. An Apple Developer Technical Support engineer puts it plainly: for a tool run by the user from Terminal, "the tool's responsible code is Terminal." A command-line coding agent launched from a terminal app that has FDA therefore inherits FDA, even though nobody ever granted it to the agent.
What happened with Muse
Meta launched Muse on September 8. Inc columnist Jason Aten reported that he declined Messages access during setup and that FDA was off on his Mac mini, yet within a day Muse was suggesting article ideas built from his private texts. When he asked, Muse said it only saw notification previews. Aten says the app had synced more than 187,000 rows of his Messages history, and that Messages access showed as enabled in Muse's own settings.
Meta disputes that FDA was off. Spokesperson Andy Stone said the Messages integration is opt-in and needs both FDA and the Muse Messages connector. David Singleton, who leads Meta Superintelligence Labs, said reading Messages takes three separate permission steps and that Muse's notification explanation was wrong. Which account is right has not been settled publicly, so treat the bypass claim as unconfirmed.
Separately, on September 21 researcher Patrick Wardle disclosed a flaw in the Muse Mac app: an undocumented setting, endo_voyager_dictation_endpoint, could be changed by any unprivileged local process to send dictation audio and authentication tokens to an attacker's server. Meta shipped a hotfix within about a day that removed the setting from production builds. No CVE was assigned. The point for defenders is that an agent holding broad permissions becomes a relay: malware that cannot get FDA itself can steer an app that already has it.
What to do
1. Find out who has FDA today
On each Mac, open Apple menu > System Settings > Privacy & Security > Full Disk Access and note every enabled app. Pay attention to AI assistants, terminal apps (Terminal, iTerm2 and others), code editors with built-in terminals, and remote-support tools.
For a scripted inventory, the system TCC database at /Library/Application Support/com.apple.TCC/TCC.db holds FDA grants under the service kTCCServiceSystemPolicyAllFiles, where auth_value 2 means allowed. Apple does not document this file, its schema changes between releases and reading it needs FDA itself, so treat this query as unverified and test it on one Mac first:
sudo sqlite3 "/Library/Application Support/com.apple.TCC/TCC.db" "SELECT client, auth_value, last_modified FROM access WHERE service='kTCCServiceSystemPolicyAllFiles';"
2. Take FDA away from terminals and editors
Because of the responsible-code rule, a terminal with FDA hands it to every shell, script and AI coding agent started inside it. Switch the terminal off in the Full Disk Access list unless a specific job needs it, and do that job from a separate, dedicated terminal app.
3. Deny FDA to AI agents with MDM
Apple's Privacy Preferences Policy Control (PPPC) payload, com.apple.TCC.configuration-profile-policy, lets an MDM set FDA through the SystemPolicyAllFiles service with Authorization set to Allow or Deny. Each entry needs the app's Identifier (bundle ID), IdentifierType and CodeRequirement, which you read with codesign -dr - /Applications/AppName.app. The payload needs user-approved MDM enrollment and cannot be installed by hand. Where two profiles conflict, Apple's schema says the most restrictive setting, Deny, wins, so one Deny profile scoped to agents you have not approved holds against a later Allow.
4. Reset grants you cannot account for
Apple's tccutil man page gives the form tccutil reset service [bundle_id]. The service name commonly used for FDA, SystemPolicyAllFiles, does not appear in Apple's documentation, and admins have reported that a bundle-specific reset fails for it. Treat sudo tccutil reset SystemPolicyAllFiles as unverified, expect it to clear the whole list, and re-grant your backup and security tools afterwards.
5. Check what an agent could already have read
If an agent held FDA, assume it could read everything in Apple's description: Mail, Messages, Safari history and Home data for that user. In the agent's own settings, check which connectors (Messages, Mail, files) are on and turn off any nobody approved. Ask the vendor how to view and delete data it synced to its cloud. Messages often carry one-time sign-in codes, so review recent logins for accounts that send codes by text. Muse users should confirm they are on the build with Meta's dictation hotfix.
The wider lesson
Desktop agents arrive as ordinary app installs, so they skip the review an integration with the same reach would get. Put FDA on the list of permissions that need a named owner and a reason, the same as local admin rights, and review the list each quarter. Apple's new prompt will help with new grants, but it is not known whether it will touch grants made before it ships.
Our safeguarding and hardening work covers Mac privacy profiles and endpoint baselines, and AI-native systems helps teams adopt agents with permissions sized to the job. Open the chat and Yaali, our AI agent, will pass your question to an engineer.
Sources: Apple Developer news, Updates to Full Disk Access in macOS, Apple Support, Privacy & Security settings on Mac, Apple Platform Deployment, PPPC payload, Apple device-management schema, Apple Developer Forums, responsible code, SecurityWeek, The Hacker News, TechCrunch, MacRumors, Decrypt, Meta's response, Decrypt, Aten's report, InfoQ, Muse dictation flaw, Forkast.