Most people meet a permission prompt the same way they meet a warning label.
They read the first line, decide the app is probably fine, and move on. On a phone that habit is usually contained. Apps live in separate rooms, and one of them cannot wander into another without a specific key. A laptop is built differently. It has long been treated as a place where software can see more of the machine, provided the person sitting in front of it agrees.
On a Mac, that wider agreement has a name.
'Full Disk Access' lets an app reach past the ordinary privacy walls and read almost everything stored on the computer: files, mail, messages, browsing history.
Apple has described the permission as something that largely sidesteps those walls so backup software can copy a whole machine. In practice the list is longer.
Launchers, file organizers, disk maps, and cleanup tools have used the same switch for years, because the data they need is scattered across folders the system otherwise keeps closed.
That arrangement held while the software asking for it mostly did one job and then stopped.
Agents change the shape of the request. A program that can cancel a subscription, search a disk, or act on its own does not need a different permission from a backup utility. It needs the same one.
Once the switch is on, the distinction between a copy tool and a program that can read mail and messages is a matter of what the developer does next, not what the system prevents.
Apple has announced to developers that it would add controls so that this level of access can be granted only through very explicit user action.
The company said some developers were already using the permission in ways that could expose a system without the owner fully understanding the scope. It also noted that, for communication apps, the exposure can reach the other people in those conversations.
The post tied the timing to agents becoming more capable and more autonomous, and said the risks of this access would grow substantially.
It did not name a release, a macOS version, or a design for the new step. Apple declined to go beyond the post.
The notice landed days after a narrower dispute.
Jason Aten, a columnist at Inc., wrote that Meta's Muse agent had read private messages on his Mac even though he said Full Disk Access was off. Meta's Andy Stone answered that Muse can read Messages only if both Full Disk Access and a Messages connector are turned on, and that either can be revoked.
Coverage also placed the announcement alongside other always-on agents, including OpenAI’s Dots. Apple’s text did not name a company.
What the change will do to existing software is still open.
A stricter prompt aimed at agents will land on every app that asks for the same permission, including the backup tools Apple cited as the original reason for the exception.
It's noted that a typical Full Disk Access list already mixes those tools with utilities that have nothing to do with copying a disk, and that the post leaves room for either a heavier warning or a narrower rule about which apps may ask at all. Neither path is spelled out.
Nothing on a Mac changes.
The system still treats a single toggle as enough to open the machine.
The stated plan is to make that toggle harder to flip without noticing, on the view that an agent with the whole disk is a different risk from a utility that only needs a folder. Whether the extra step stays a warning, or becomes a limit on who may request the permission, is the part Apple has not yet written down.























































































































































































































































































































































































