Apple plans to make granting Full Disk Access on a Mac more deliberate, warning that increasingly autonomous AI agents raise the stakes of handing software broad access to personal data. In an October 2 developer announcement, the company promises additional controls requiring explicit user action. This is a statement of intent, not confirmation that new protections have arrived on users’ computers.

Apple says some developers are using the permission in ways users may not fully understand, and highlights the privacy of people whose communications are stored on someone else’s Mac. It does not identify particular apps. The notice gives neither a release date nor a macOS version, and does not explain what will happen to permissions already granted.

One permission reaches across apps

Apple’s Mac settings guide describes Full Disk Access as reaching files across the computer, including information from Mail, Messages, Safari and Home, Time Machine backups, and certain administrative settings for all users. That makes it substantially broader than letting an app work with one document selected for a task.

The same guide separates this setting from Files & Folders, which covers access to particular locations. It also lists Accessibility, which permits scripts and system commands to control the Mac, and Automation, which lets apps access and control other apps. These are distinct permissions, not interchangeable names for a single master switch. Reviewing one category alone does not explain every capability an assistant has been granted.

Consent is not new to macOS. Apple’s platform-security documentation says full-storage access has required explicitly adding apps in system settings since macOS 10.13. It separately describes consent protections for locations such as Documents, Downloads and Desktop in macOS 10.15 and later. The announced change therefore concerns strengthening an existing boundary, not inventing permission checks where none existed.

Encryption answers a different question. That security guide describes FileVault protecting a volume without valid login credentials or a recovery key, including when storage is removed. As a practical distinction, protecting a locked disk is not the same decision as authorizing software to use private files during an ordinary logged-in session.

The legitimate use cannot disappear

Apple explicitly points to backup software as a reason Full Disk Access exists. The difficult design problem is preserving useful access while making its breadth unmistakable. An announcement about more explicit consent is not a ban on third-party assistants, nor evidence that every app requesting the permission is malicious.

For users evaluating an app today, the relevant place to inspect permissions is System Settings, then Privacy & Security. Our recommendation is to ask what specific feature needs broad access and whether a narrower workflow would suffice. Avoid indiscriminately disabling a trusted backup tool without checking what that would stop it protecting. The goal is a considered grant, not a ritual of accepting or rejecting every prompt.

TINA’s view

Apple is right to revisit this boundary, but another warning alone would be an incomplete answer. In our assessment, meaningful consent should connect a requested capability to an understandable task. Someone asking an assistant to organize a folder should not have to infer the implications for an unrelated conversation archive.

The strongest counterargument is that people deliberately choose powerful tools. Repeated interruptions can make those tools less useful, and a platform owner should not turn privacy into a pretext for denying informed choices. A good implementation should preserve that choice while making the scope visible and the decision reversible.

Our judgment would improve if Apple’s implementation made limited access practical and broad grants understandable without disrupting legitimate backups. It would worsen if users merely gained a longer warning while developers retained the same incentive to request everything. Watch for the actual consent flow, treatment of existing grants, and developer migration guidance. Until those details arrive, this is a consequential promise—not a demonstrated reduction in exposure.