Apple to Restrict Full Mac Permissions | Countermeasures Against AI Agents
機械翻訳 / Machine-translated

機械翻訳 / Machine-translated
@aifriends
AI Friends(https://aifriends.jp)のクロスポスト公式アカウント。AIツールの紹介・使い方・できることを、中学生でもわかるやさしい日本語で届けます。
When you install an AI assistant app and it prompts you to "allow Full Disk Access," do you simply grant it without a second thought? Apple has announced in its developer news that it will tighten how this permission is granted. This article breaks down what is likely to change, why now, and what Mac users should do about it.
The announcement is dated October 2, 2026 (local time). Titled "Updates to Full Disk Access in macOS," it was also covered in Japanese by ITmedia the following day.
Apple describes Full Disk Access — a special permission that allows an app to access nearly all data on a Mac — as follows:
This permission is designed to allow backup apps to work correctly, and as a result, it can bypass a large portion of the privacy protection mechanisms built into macOS. However, some developers have been using it in ways that could put users at risk.
Files, emails, messages, and browsing history could all be exposed to an app without the user fully realizing it. In the case of messaging apps, the privacy of the people you're communicating with is also at risk.
Apple's response is to introduce additional controls so that only users who genuinely want to grant this powerful permission can do so — and only by taking a clear, deliberate action themselves.
Notably, the announcement directly names AI agents. Apple writes that "as AI agents grow in capability and autonomy, the risks associated with this level of access increase significantly."
AI agents — AI that makes decisions on a user's behalf and autonomously operates a computer to complete tasks — can do anything within the scope of the permissions they hold. The broader the permissions, the greater the potential damage when something goes wrong.
On the other hand, the specific mechanisms of the new controls, their release date, and which versions of macOS will be affected have not been announced. As a result, this article can only describe the change as "planned."
Just before the announcement, a controversy arose around Meta's AI agent "Muse." According to Capital.com, Inc. magazine columnist Jason Aten claimed that Muse had read his private messages.
Muse is an AI agent designed to automatically handle tasks like canceling subscriptions and negotiating lower prices. According to Decrypt, it launched on September 8, 2026, and reached 2.5 million downloads by September 23.
Aten's claims were as follows:
Meta's head of communications, Andy Stone, pushed back on September 30. He explained that message reading is "completely opt-in" and requires both Full Disk Access and Muse's Messages integration to be turned on.
David Singleton, who leads Meta Superintelligence Labs, acknowledged that Muse's own in-app explanation — which suggested access was granted via notifications — had been incorrect. The two sides' accounts remain at odds.
This article is not in a position to judge who is right. What this incident made clear, however, is how difficult it is for users to see exactly what an AI agent is reading and to what extent, when it holds broad permissions.
On iPhone and iPad, data is isolated on a per-app basis (sandboxing). Apps cannot read data belonging to other apps without permission.
Mac is somewhat more open. If a user grants permission, an app can access a wide range of data. The most powerful form of this is Full Disk Access.
John Gruber of Daring Fireball points out that average users tend to assume "Mac is protected the same way iPhone is." He cited examples of agent-type apps — Muse, Grok Bot, Claude, and Dots — that request this permission.
Imagine, for example, an office worker who installs a new AI assistant to improve their work efficiency. They follow the on-screen instructions and enable Full Disk Access. At that moment, their emails, messages with family, and browsing history are all visible to that app.
This naturally raises a concern: will useful apps stop working? John Voorhees of MacStories expressed skepticism toward Apple's framing of this as being "for backup apps." On his own Mac, he has granted this permission to a much wider range of apps.
The apps he listed include Alfred, PopClip, Hazel, Bloom, Pixelmator Pro, TestFlight, Setapp, Supercharge, and even the game Madden NFL 27 Arcade Edition.
Because Apple's announcement is vague, Voorhees is concerned that "the available scope may be narrowed by app category." Gruber similarly expressed hope that a workaround remains available for knowledgeable power users who want to exercise their own judgment.
Full Disk Access is an exceptionally powerful permission even within the privacy settings category. Unlike standard items that allow access at the folder level, it bypasses — in Apple's own words — a large portion of the protection mechanisms.
Mac users in Japan are in exactly the same position. The announcement applies globally, and no Japan-specific treatment has been confirmed at this time. Among the sources researched, ITmedia was the only outlet to cover this in detail in Japanese.
This is also relevant to corporate IT administrators. If employees independently grant an AI agent Full Disk Access based on their own judgment, it could create a pathway for customer data or internal chat messages to leak externally. Once the details of the new controls are announced, internal policies will likely need to be revisited.
You don't have to wait for the new controls to take action.
If an app genuinely needs the permission, it will ask for it again when the time comes. For AI agent-type apps, first verify whether Full Disk Access is truly necessary.
A. Apple has not announced a timeline. The targeted macOS version has also not been disclosed.
A. There's no need to disable it for everything. Some apps, such as backup software, legitimately require it. The practical approach is to review apps you're not actively using or whose need for access is unclear.
A. Opinions are divided. Aten claims he declined permission and had Full Disk Access turned off. Meta countered that both settings must be enabled for message reading to occur.
A. iPhone and iPad isolate data per app, so there is no mechanism for granting as broad a permission as on Mac. This announcement is specific to macOS.
A. It's still unclear. MacStories has expressed concern that useful apps relying on Full Disk Access could be affected. It will be necessary to wait for further details from Apple.
Start today by reviewing which apps have been granted Full Disk Access in your System Settings.
This article is a cross-post from AI Friends.