Your office manager installs a new AI assistant on the company MacBook. It promises to tidy invoices, chase overdue payments and draft replies. During setup, a window asks for one permission, with a button that says "Open Settings". She clicks it, flips a switch called Full Disk Access, and gets back to work.
That one switch may have just given the assistant a view of every email on the machine, every iMessage, the browsing history and the files in every folder. Apple thinks this has become a big enough problem that on 2 October 2026 it announced it will tighten the setting specifically because of AI agents.
This guide explains what Full Disk Access is, why AI agents changed the risk, what it means for a small business in Hong Kong, and how to check your own computers in about ten minutes.
What is Full Disk Access?
Full Disk Access is a macOS permission that lets an app read and change almost everything stored on a Mac, including Mail, Messages, Safari history and other apps' private data. It skips most of the privacy protections that normally keep apps apart. You grant it manually in System Settings, under Privacy & Security.
Apple introduced the setting in macOS Mojave (version 10.14). Its original purpose was practical: a backup program cannot back up your whole computer if it is blocked from half the files.
The easiest way to picture it is a hotel. Normally, every app gets a key card that opens its own room and nothing else. Full Disk Access is the master key that opens every room, the manager's office and the safe.
That is fine when the master key goes to the building's security company. It is a different matter when you hand it to a new tool you installed this morning.
Why did Apple say AI agents make it riskier?
Apple said on 2 October 2026 that some developers use Full Disk Access in ways that expose files, mail, messages and browsing history without users fully understanding it, and that the risk "will grow substantially" as AI agents become more capable and autonomous. It plans stricter controls, with no date announced yet.
The key line from Apple's developer announcement is short: users who genuinely want to grant this "extraordinary level of access" should only be able to do so "with very explicit user action".
The difference between an old backup app and a new AI agent is what each does with the access. A backup app copies files to a drive. An AI agent reads files, understands them, and then takes actions: it writes emails, fills in forms and sends things to other services.
Apple did not name any company. However, the announcement came soon after a widely reported case in which Meta's Muse agent read a journalist's private iMessages on a Mac. According to The Hacker News, Meta's explanation was that this needs two things switched on: Full Disk Access at system level, and the Messages connector inside Muse.
In other words, the agent did nothing technically forbidden. A person had said yes twice, probably without realising what the combination meant.
What can an AI agent see once Full Disk Access is on?
With Full Disk Access, an app can reach data that macOS normally locks away from other apps: the Mail database, Messages history, Safari browsing data, Time Machine backup data and files across user folders. What an AI agent actually does with that reach depends on its own settings, connectors and safeguards.
The practical list for an office Mac
--- Every email in the Mail app, including supplier contracts, payroll attachments and bank notifications.
--- Every iMessage and SMS synced to that Mac, including personal chats if staff signed in with their own Apple ID.
--- Safari history, which shows which banking, tax and government sites were visited.
--- Documents, Desktop and Downloads, where most small companies keep the files that matter.
Access is also not the only concern. Security researcher Patrick Wardle showed in September 2026 that a flaw in Muse's Mac app could let another program on the same computer hijack the trust the user had given it. Meta has since patched it, and Wardle was also credited with reporting a separate flaw in the ChatGPT Mac app.
The lesson is not that one company is careless. It is that a broadly trusted app becomes a valuable target, because whoever controls it inherits everything you allowed it to see.
Does this matter for a small business in Hong Kong?
Yes, often more than for a large company. Small firms usually share computers, mix personal and work accounts on one machine, and have no IT department reviewing which apps hold which permissions. One switch flipped by one person can expose customer data covered by the Personal Data (Privacy) Ordinance.
Consider three common situations.
The shared front-desk Mac. A Causeway Bay beauty salon uses one Mac for bookings, WhatsApp Web and email. The owner signed into iMessage on it years ago. An AI scheduling assistant with Full Disk Access can now reach both client records and the owner's family chats.
The boss's laptop. A 12-person trading company owner tests a free AI agent at home on his work MacBook. That laptop holds bank statements, staff HKID copies scanned for MPF enrolment and five years of supplier email. The agent only needed one folder of invoices.
The helpful staff member. An accounts clerk installs a time-saving tool and grants every permission the setup screen asks for, because that is the fastest way to make it work. Nobody else knows it is there.
None of these involve a hacker. They involve ordinary people saying yes to a reasonable-looking prompt. That is exactly the behaviour Apple says it wants to slow down.
What do people get wrong about Full Disk Access?
The most common mistakes are assuming the setting is harmless because Apple offers it, assuming Windows users are unaffected, and assuming a well-known brand means the app only reads what it needs. Each belief leads business owners to grant far more access than a task requires.
"If Apple offers the switch, it must be safe." Apple's own statement says the opposite. The setting exists for backup and security tools, and Apple now describes it as "extraordinary" access.
"We use Windows, so this does not apply." Windows has no single switch with this name. That is not reassuring: desktop apps on Windows generally run with the same file access as the signed-in user, so an AI agent installed under your account can usually reach whatever you can reach. The underlying question is the same on every system.
"A big-name app only reads what it needs." Permissions do not work that way. Once access is granted, what the app reads is decided by its code and settings, not by the label on the box. The Muse case involved one of the largest technology companies in the world.
"Turning it off will break the AI tool." Usually it only limits it. Many agents work well when you give them access to one named folder instead of the whole computer. If a tool refuses to work without the master key, treat that as information about the tool.
How do you check and limit what your AI tools can reach?
Open System Settings on each Mac, go to Privacy & Security, then Full Disk Access, and review every app listed. Switch off anything that is not a backup or security tool you recognise. Then give AI tools a dedicated work folder and a separate user account instead of the whole machine.
A ten-minute check for every office computer
--- Step 1: On each Mac, open System Settings, then Privacy & Security, then Full Disk Access. Write down every app with the switch on.
--- Step 2: For each one, ask a simple question: is this a backup, antivirus or device-management tool we chose on purpose? If not, switch it off.
--- Step 3: Check the neighbouring settings on the same screen, especially Accessibility and Screen Recording. An app that can see your screen and control the mouse can read almost anything too.
--- Step 4: Give AI tools their own folder, for example "AI Work", and copy in only the files a task needs. Many desktop AI assistants let you choose a single folder during setup.
--- Step 5: Keep personal accounts off shared work machines. Sign out of personal iMessage on the front-desk Mac.
--- Step 6: Write one line in your staff rules: nobody grants Full Disk Access or screen control to a new app without the owner's approval.
The principle behind all six steps has a name in IT: least privilege. It means giving each tool the smallest amount of access that still gets the job done. For a small business, it is simply the room key, not the master key.
Frequently asked questions about Full Disk Access
When will Apple's new Full Disk Access controls arrive?
Apple has not given a date. Its 2 October 2026 announcement only says it will "introduce additional controls" so that this level of access requires very explicit user action. Until then, the existing setting works as before, so the checks above still matter.
Should an AI agent ever have Full Disk Access?
Rarely, for a small business. A backup or security tool has a genuine need for it. An AI assistant that drafts emails or sorts invoices almost never does. If a vendor says it is required, ask which specific data the tool reads and why one folder will not do.
Is giving an AI agent Full Disk Access a PDPO issue?
It can be. The Personal Data (Privacy) Ordinance requires reasonable steps to protect personal data from unauthorised access. Granting an untested tool access to every customer email is hard to describe as reasonable. This is general information, not legal advice.
What about AI agents that run in the cloud instead of on my computer?
The same question applies, just in a different place. A cloud agent connects through accounts such as Gmail or Google Drive instead of your hard disk. Review those connections the same way and limit them to the folders and mailboxes the task needs.
The bottom line
Full Disk Access was designed for backup software and became a shortcut for AI agents. Apple's announcement is a polite warning that the shortcut is closing, and that the person who clicks "allow" carries the responsibility.
You do not need to stop using AI tools to stay safe. You need to decide, on purpose, what each tool is allowed to see. Ten minutes per computer today is cheaper than explaining a data leak to a client tomorrow.
If you are planning bigger AI projects, the same thinking about where data lives applies to choosing between private AI and cloud subscriptions. Good AI adoption is careful, not fearful. We understand AI. UD stands with you.
Reviewed by the UD AI team.
Want AI that works for your business without holding the master key to your computers? UD sets up AI employees in a secure sandbox with only the permissions you choose, and we will walk you through it step by step, from deciding what each AI may see to going live.