Should you give AI agents Full Disk Access on a Mac?
Quick answer: Usually not. Full Disk Access lets a Mac app read almost everything, including Mail, Messages, Safari history and Time Machine backups. On October 2, 2026, Apple said it will tighten the permission because more capable AI agents make that access much riskier. Refuse it for AI agents unless a specific task truly needs it, keep Accessibility and Screen Recording on a short leash, and prefer assistants that only see what you choose to send them.

Your AI assistant is already in WhatsApp. Get Sonic today.
Reminders that actually fire. Follow-ups Sonic sends for you and reports back. PDFs, contracts and invoices summarized in seconds. Your Google Calendar handled by text, and group chats that run themselves. Voice notes welcome. Nothing to install, nothing to learn: message Sonic like any contact. Try “Remind me to call the accountant every Monday at 9.” Leave your details and you’ll get Sonic’s number right away.
What did Apple change about Full Disk Access, and why now?
On October 2, 2026, Apple told developers it will add new controls around Full Disk Access on macOS, so apps can only get that permission after "very explicit user action." Its reason was blunt: as AI agents get more capable and more autonomous, the risks that come with that level of access will grow a lot. Apple also said some developers already use Full Disk Access in ways that expose everything on a user's system, without the user fully understanding what they agreed to. It singled out communication apps, because there the exposure reaches past you to the people you talk to. No timeline or technical details came with the announcement, so for now it's a warning shot, not a new switch in Settings.
The timing matters. The announcement came days after a tech journalist said Meta's Muse app on their Mac sent them a notification mentioning a private conversation from Apple's Messages app. They said they hadn't given it permission to read their messages, and Meta disputed the claim. Like several desktop agents, Muse offers Full Disk Access as an optional setting. Whatever happened in that case, the story hit a nerve because it's so easy to picture. You install a helpful assistant and click through a few prompts on a busy afternoon. A week later, it knows things you never meant to share. That isn't a movie-style hacking scene. It's an ordinary Tuesday, and it could happen to anyone who clicks "Allow" too fast.
For anyone choosing an AI assistant, this changes the buying question. Features used to come first: can it book meetings, summarize documents, draft replies? Now the first question is what it can see, and whether it really needs to see it. That goes for every assistant, including the one this site is about. Agent Sonic lives inside WhatsApp and works only with what you choose to send it: a forwarded PDF, a voice note, or a message like "Remind me to call the accountant every Monday at 9." It doesn't sit on your Mac and never asks for your disk. The rest of this guide is a practical permissions check, so you can judge any agent, desktop or chat-based, by the same standard.
What can an AI agent see once you grant Full Disk Access?
Almost everything. Full Disk Access gets around most of the privacy controls macOS normally uses to protect your data. Apple meant it for tools like backup software, which genuinely need to read the whole drive. Once an app has it, the app can read files across the whole system, including data stored by other apps. That means your Mail database, your Messages history, Safari data such as browsing history, Time Machine backups and some admin settings that cover every user on the Mac. Give it to an AI agent and you've given access to something that can also interpret, summarize and act on what it finds. A backup tool copies your messages. An agent can understand them, connect them and use them.
Think about what that means for a small business. Your Mail archive holds client contracts, bank notices, password reset links and that HR email you sent last spring. Messages holds family chats, supplier haggling and two-factor login codes. Your Downloads folder is a graveyard of invoices, ID scans and signed NDAs. Your browsing history shows which competitors you've been quietly checking out. None of this is dramatic on its own. Put together, it's a remarkably complete picture of you, your clients and everyone who has ever messaged you, and those people never agreed to anything. Apple raised that last point specifically, and most of us skip it when we click "Allow."
Then there's what the agent does with that view. A capable desktop agent doesn't just read. It can pass context between tools, send data to a cloud model for processing, and take actions for you. Even if the developer means well, more access means more room for bugs, sloppy logging or prompt injection, where a malicious web page or email slips hidden instructions to the agent. Our view: Full Disk Access should be a firm no for almost every AI agent. That's not because the companies behind them are villains. It's because one mistake could reach your entire digital life, and very few assistant tasks need anything close to that much access.
| Data | What's in it | Why it matters with an AI agent |
|---|---|---|
| Your full email archive and attachments | Contracts, bank notices and client details become readable context | |
| Messages | Your iMessage and SMS history | Exposes the people you talk to, not just you |
| Safari | Browsing history and other browser data | Shows who you research, buy from and deal with |
| Time Machine backups | Older copies of your files | Files you deleted may still be readable |
| Admin settings | Some system settings that cover every user | The reach extends past your own account |
Which Mac permissions should you refuse an AI agent?
Refuse Full Disk Access outright. Be very stingy with Accessibility, Screen Recording, Input Monitoring and Automation too. These are the macOS privacy permissions that turn a helpful app into one that can see or control nearly anything. Accessibility lets an app work other apps by clicking and typing for you. Screen Recording lets it see whatever's on your display, including chats and banking pages. Input Monitoring lets it read your keystrokes in other apps. Automation lets it control other apps such as Mail or Finder. Some agents really do need one of these. An agent built to "use your computer" needs Accessibility, for example. Just grant it on purpose, not because a setup wizard asked nicely.
The narrower permissions are easier calls. Access to folders such as Documents, Desktop or Downloads can be fine if the task needs it, but a dedicated working folder is better. Drop the files you want processed there and keep everything else out of reach. Contacts and Calendars access makes sense for a scheduling assistant and looks odd for one that only writes social posts. Microphone access is fine for dictation while you're actively using it. The test is simple: ask yourself, "What specific task needs this?" If you can't name one, say no. You can always grant it later. And if an agent won't work at all without Full Disk Access, take that as information about the product, not a hurdle to click past.
Watch the setup flow too. Many apps open System Settings and walk you straight to the right toggle. That's convenient, and it's also a gentle kind of pressure. Slow down on that screen. Read the app's own explanation of why it wants the access, and ask whether you'll actually use the feature that needs it. If a permission only powers an "optional" feature, leave it off until you miss it. Keep the people around you in mind, too. When you let an agent into your Messages or Mail, you're making that call for every client, colleague and relative in those threads. That decision deserves more than a two-second click.
| Permission | What it lets an app do | Default answer for an AI agent |
|---|---|---|
| Full Disk Access | Read nearly all data, including Mail, Messages and Safari | No |
| Accessibility | Control your Mac by clicking and typing in other apps | Only if operating your computer is its core job |
| Screen Recording | See everything on your screen | Only while you need it, then switch it off |
| Input Monitoring | Read keystrokes in other apps | No |
| Automation | Control apps such as Mail or Finder | Only for specific apps you're comfortable with |
| Files and Folders | Read specific folders like Documents or Downloads | Prefer one dedicated working folder |

Your AI assistant is already in WhatsApp. Get Sonic today.
Reminders that actually fire. Follow-ups Sonic sends for you and reports back. PDFs, contracts and invoices summarized in seconds. Your Google Calendar handled by text, and group chats that run themselves. Voice notes welcome. Nothing to install, nothing to learn: message Sonic like any contact. Try “Remind me to call the accountant every Monday at 9.” Leave your details and you’ll get Sonic’s number right away.
How do you check and revoke AI agent permissions on your Mac?
Open System Settings, choose Privacy & Security, then click Full Disk Access to see every app that holds it right now. Turn off anything that isn't a backup tool, security software or something you can clearly justify. While you're there, check Accessibility, Screen Recording (called Screen & System Audio Recording on recent versions), Input Monitoring, Automation and Files and Folders the same way. You may be surprised by what you find: a screen-sharing tool from a client call two years ago, an AI note-taker you tried for a week, a utility that came in a bundle. Each was a reasonable choice at the time, and few still need the access. Removing it rarely breaks anything you care about. If an app truly needs it, it'll ask again.
Make it a habit, not a one-off. A five-minute review every quarter is plenty for most people. Put it in your calendar or, if you already live in WhatsApp, text your assistant something like "Remind me on the first Monday of every quarter to check my Mac privacy settings." Also uninstall agents you've stopped using instead of leaving them sitting there. A forgotten app with broad access gives you the worst of both worlds: no benefit and full exposure. If you look after Macs for a small team, write down which tools are approved for which permissions. A one-page list beats a security policy nobody reads, and it gives new hires a clear answer before they click "Allow."
Apple's coming controls will help, but don't wait for them, and don't treat them as a cure. A clearer, more explicit prompt still ends with someone clicking a button, usually while trying to get something else done. The deeper fix is to choose tools that don't need broad access in the first place. Here's the part few companies building agents like to say out loud: the most private assistant isn't the one with the best permission prompt. It's the one that never has to ask. For a lot of everyday admin, like reminders, follow-ups or reading a contract, you don't need an agent rummaging through your drive at all. You need one that handles exactly what you give it, and nothing else.
Is a chat-based assistant safer than a desktop AI agent?
For most everyday admin, yes, because a chat-based assistant only sees what you send it. There's no permission to grant on your Mac and nothing scanning your folders in the background. Want a contract reviewed? Forward the PDF. Want a reminder? Type it or say it. What the assistant knows about your life is exactly what you've chosen to share in the chat. That's far easier to keep track of than "everything on my disk." It isn't magic, though. Whatever you send still gets processed, so think twice before forwarding someone else's passport scan or medical letter. The difference is that it's opt-in, one item at a time, instead of all-or-nothing.
That's how Agent Sonic works. It lives in WhatsApp: you message it like any contact, with nothing to install and no dashboard to manage. Send "Remind me to chase the Levi invoice every Friday at 11" and it sets a recurring reminder. Forward a supplier contract and ask, "Any auto-renewal or penalty clauses?" and you'll get the key terms and deadlines back in plain English. Send a voice note while driving, like "add milk, call the landlord, book the van for Thursday," and it becomes a to-do list. It can also read spreadsheets and invoices, search the web, remember your preferences and help run your WhatsApp groups. Every one of those starts with you sending something.
There are trade-offs, and you should know them. A chat assistant can't reorganize your Downloads folder or click through a desktop app for you. If that's the job, a desktop agent with tightly limited permissions may be the right tool. And if you connect Google Calendar, Sheets or Docs to Sonic, you're giving it access to those accounts, so treat that like any other permission and only connect what you actually use. But for reminders, follow-ups, group coordination and reading documents, the chat approach gives you the help without the exposure. If that sounds right for you, see how an AI assistant in WhatsApp with no app to install works, or leave your details to get Sonic's number and onboarding.
Frequently asked questions
Is it safe to give an AI agent access to my files?
It can be, if the access is narrow and tied to a clear task. Giving an agent one working folder for the documents you want processed is reasonable. Giving it Full Disk Access is a different story, because it can then read Mail, Messages, browsing data and backups. Grant the smallest permission that gets the job done, review your settings regularly, and choose tools that work with files you send them whenever you can.
What does Full Disk Access actually allow on a Mac?
Full Disk Access gets around most of the privacy controls macOS normally uses to protect your data. An app that holds it can read files across the whole system, including data from Mail, Messages and Safari, Time Machine backups and some admin settings that apply to all users. Apple designed it for tools like backup software. That's why it's such a big ask from an AI agent that can also interpret and act on what it reads.
Will Apple's new controls stop AI agents from getting Full Disk Access?
Not entirely. Apple said apps will only get Full Disk Access after very explicit user action, which should make it harder to grant by accident. It didn't announce a ban, a timeline or exact technical details. You can still say yes, so the decision stays with you. Check System Settings, then Privacy & Security, now rather than waiting for the update to arrive.
Does Agent Sonic need any permissions on my Mac?
No. Sonic lives in WhatsApp, and you message it like any other contact, with nothing to install on your Mac and no system permissions to grant. It works with what you choose to send it: text, voice notes, PDFs, invoices or spreadsheets. If you choose to connect Google Calendar, Sheets or Docs, that gives it access to those accounts, so only connect the ones you actually plan to use.

Your AI assistant is already in WhatsApp. Get Sonic today.
Reminders that actually fire. Follow-ups Sonic sends for you and reports back. PDFs, contracts and invoices summarized in seconds. Your Google Calendar handled by text, and group chats that run themselves. Voice notes welcome. Nothing to install, nothing to learn: message Sonic like any contact. Try “Remind me to call the accountant every Monday at 9.” Leave your details and you’ll get Sonic’s number right away.