Apple is about to make it much harder to hand an AI agent the keys to your entire Mac. The company announced it will add stricter controls around Full Disk Access, the master-key macOS permission that lets a single app read your files, mail, messages, and browsing history in one sweep. The stated reason is new: AI agent snooping, which Apple says has turned an old developer tool into a growing privacy risk.

In a developer note published this week, according to TechCrunch, Apple said the permission largely sidesteps the privacy controls macOS normally enforces, and that it exists so backup software can copy an entire drive. Some developers, the company wrote, now use it in ways that expose everything on a user's system without their full knowledge and understanding. The warning went further: for apps that handle communication, the overreach can also compromise the privacy of the people on the other end of your conversations. Apple attached no timeline and no macOS version to the change, and its statement names no app or developer.

What Prompted the Crackdown

The announcement landed days after a public dispute over Meta's desktop AI assistant. Inc. columnist Jason Aten reported that the Muse agent on his Mac surfaced details from his private Messages history, including a note from his editor, even though he says the permission was switched off. Meta pushed back hard: executive David Singleton said three separate layers of app and system permissions stand between the assistant and a user's messages, and that the macOS protections cannot be bypassed even by a bug in the app. Apple named no app in its announcement.

Security researchers say the technical picture is murkier than either side admits. Patrick Wardle, a well-known macOS security expert, told Ars Technica that any app holding that level of access can technically read non-root files, including chat databases and browser cookies. Separately, Wired documented a flaw in the ChatGPT desktop app that could have let attackers reach sensitive data. The pattern is the same one worrying Apple: assistants that are most useful when they can see everything are also the ones asking for the most dangerous permission.

AI Agent Snooping: What Changes for Your Mac

For now, the practical change is friction on purpose. Users who genuinely want to grant an app this level of access will still be able to do so, as reported by MacRumors, but only through an unusually deliberate opt-in that Apple has not yet described in detail. The company framed the move as a direct response to AI agent snooping, warning that the risks attached to this kind of access will grow substantially as agents become more capable and autonomous. Developer reaction has been split: some welcome the tighter scoping, while others warn that legitimate backup and utility tools will get harder to use.

If you already run a desktop assistant on your Mac, the takeaway is worth two minutes. Open System Settings, head to Privacy and Security, and look at which apps hold the master permission. Ask whether an inbox-clearing bot or study helper really needs to read your mail, messages, and browsing history, or whether it can do its job with narrower folder-by-folder access. The tools that are most useful when they can see everything are the ones most worth auditing against AI agent snooping.

Not everyone is cheering. Power users argue the tightening trades one privacy risk for another kind of lock-in, where Apple's own assistants keep deep access while third-party agents get stopped at the gate. Apple has not addressed that critique, and with no ship date attached, the industry gets time to argue about it first. Either way, the era of casually handing an agent a skeleton key to your digital life is ending. You will have to mean it now.

For more on how AI is creeping into daily life, read our explainer Gen Z Says AI Is Already Conscious, and keep up with the week's biggest stories on The Feed.