Apple just announced it's restricting Full Disk Access permissions in macOS, and the reason is telling: AI agents now pose a "substantial" new security risk. This isn't about hypothetical threats. Apple is responding to real behavior from AI coding assistants, productivity agents, and autonomous software that needs unrestricted file system access to function.
The move marks the first time a major OS vendor has implemented security controls specifically designed to limit AI agent capabilities. For developers building AI tools on Mac, and users running them, the rules just changed.
Why Apple Is Changing Disk Access Now
According to Apple's security documentation, the company determined that AI agents create fundamentally different risks than traditional software. The key difference: autonomy. Traditional apps request specific files. AI agents scan entire directories, read arbitrary documents, and make decisions about what data to process without explicit user direction for each action.
Apple hasn't disclosed specific incidents that triggered this change, but the timing aligns with the proliferation of AI coding assistants like Cursor, Windsurf, and GitHub Copilot that require deep file system access to index codebases. These tools have become standard for many developers over the past 18 months.
This is Apple's acknowledgment that AI agents require a different permission model than traditional software because they act autonomously after being granted access once.
The security concern is straightforward: an AI agent with Full Disk Access can read your entire file system, including sensitive documents, API keys, private keys, browser data, and application files. Unlike a human-controlled app where each action is deliberate, an agent might scan thousands of files based on a vague natural language instruction.
What Full Disk Access Actually Means
Full Disk Access is a macOS permission level that bypasses standard file system protections. Apps with this permission can read any file on the system, including files in protected locations like ~/Library, system logs, and other applications' data.
Before this change, apps could request Full Disk Access and retain it permanently once granted. Users saw a one-time permission dialog, clicked "Allow," and the app had unrestricted access until manually revoked in System Settings.
Before
One-time approval grants permanent unrestricted file system access. AI agents can scan entire drives autonomously based on natural language instructions.
After
Time-limited or scope-limited access. Apps must justify why they need full access, and permissions may require periodic reauthorization.
For most traditional apps, this worked fine. A backup utility needs to read everything once per day. A search tool indexes files on demand. But AI agents operate differently—they make autonomous decisions about what to read based on evolving context from conversations or task instructions.
The AI Agent Threat Model
The threat isn't necessarily malicious AI. It's scope creep and data exposure from well-intentioned agents operating with too much access. Here's what Apple's security team is concerned about:
Unintended data exfiltration: An AI coding assistant instructed to "find all API integrations" might scan your entire codebase and send file contents to remote servers for analysis, inadvertently uploading proprietary code or credentials embedded in config files.
Instruction injection: If an AI agent processes untrusted input (like code comments or README files), an attacker could embed instructions that cause the agent to access and transmit sensitive files. This attack vector is already documented in academic research on prompt injection.
- Prompt Injection
- A security vulnerability where malicious instructions embedded in data processed by an AI system cause it to perform unintended actions, similar to SQL injection but for natural language models.
Persistent monitoring: Unlike traditional apps that access files when explicitly launched, some AI agents run as background services, continuously monitoring file system changes. With Full Disk Access, this creates a surveillance risk if the agent is compromised or begins behaving unexpectedly.
How the New Restrictions Work
Apple hasn't published complete technical documentation yet, but based on developer reports and the security bulletin, the new system works like this:
Apps requesting Full Disk Access must now provide a detailed justification in their Info.plist file explaining why they need unrestricted access. Generic justifications like "to improve user experience" will be rejected during App Store review.
Full Disk Access may be granted on a time-limited basis, requiring periodic reauthorization. Apps that haven't been used in 30-90 days may have their permissions automatically revoked, similar to how iOS handles location permissions.
Justification Required
Apps must explain in technical detail why Full Disk Access is necessary for core functionality.
Time Limits
Permissions may expire after extended periods of non-use, requiring users to reauthorize.
Scope Auditing
macOS may log or restrict which specific files an app accesses even with full permission.
User Notifications
Users may receive periodic reminders about which apps have Full Disk Access.
The system may also introduce telemetry that logs which files apps with Full Disk Access actually read, allowing macOS to alert users if an app is accessing files outside its stated purpose.
Impact on AI Coding Tools and Productivity Agents
AI coding assistants are the most immediately affected category. Tools like Cursor need to index entire codebases to provide context-aware suggestions. That requires reading thousands of files across a project directory.
Under the new rules, these tools will need to either:
Request scoped access: Instead of Full Disk Access, request access only to specific directories the user designates as project folders. This is more secure but creates friction—users must manually grant access for each new project.
Justify full access with specific use cases: Provide detailed technical documentation explaining why scoped access isn't sufficient. For AI coding tools, this might mean explaining the need to access configuration files, dependency directories, and build outputs across the entire system.
Developers building AI agents will need to architect for minimal viable permissions rather than requesting broad access by default.
Productivity agents that manage files, organize documents, or automate workflows face similar constraints. An AI agent that "organizes your Downloads folder" doesn't need Full Disk Access—it needs access to ~/Downloads. The new system will likely enforce that distinction.
What Developers Need to Know
If you're building AI agents or tools for macOS, here's how to prepare:
Audit your actual access needs: Map out exactly which directories and file types your AI agent needs to access for its core functionality. Don't request Full Disk Access if scoped access to specific folders would work.
Implement least-privilege architecture: Design your agent to request the minimum permissions needed at any given time. If a user asks the agent to analyze a specific document, request access to that file or folder, not the entire file system.
Prepare detailed justifications: For tools that genuinely need Full Disk Access (like backup utilities or security scanners), write detailed technical documentation explaining the requirement. Apple's review teams will scrutinize these more carefully.
Build permission management UI: Help users understand what your agent can access and provide easy controls to revoke or scope down permissions. Transparency builds trust and reduces the likelihood users will deny access entirely.
| Tool Category | Likely Access Level | Strategy |
|---|---|---|
| AI Coding Assistant | Scoped (project directories) | Request access per project, index only active workspaces |
| File Organizer Agent | Scoped (user-selected folders) | Let users designate which folders the agent can manage |
| Security Scanner | Full Disk Access | Provide detailed justification, implement access logging |
| AI Writing Assistant | Scoped (Documents folder) | Request access only to user writing directories |
The larger trend here is clear: OS vendors are starting to treat AI agents as a distinct security category requiring new controls. Apple is first to implement restrictions at the OS level, but expect similar moves from Microsoft and Linux distributions as agent-based software becomes ubiquitous.
For users, this change means more friction when setting up AI tools, but significantly better protection against unintended data exposure. For developers, it means rethinking permission models and building transparency into agent architectures from the start. The era of AI agents operating with unrestricted system access is ending.