Software
Apple adds explicit-action controls to macOS Full Disk Access for AI agents
On 2 October 2026, Apple said it will require very explicit user action before apps gain Full Disk Access on macOS, warning AI agents raise the risks of such broad file, mail, message and browsing-history access.
Photo: TechCrunchKey points
Apple announced additional macOS Full Disk Access controls requiring very explicit user action, citing growing risks as AI agents become more capable and autonomous.
Apple said on 2 October 2026 it will introduce additional controls around the Full Disk Access permission on macOS, warning that increasingly capable AI agents make broad access to users' files, mail, messages and browsing history riskier. In a post on its developer news website, the company said users who want to grant such access will only be able to do so with very explicit user action.
The change matters because Full Disk Access is a single macOS setting that lets an app reach essentially everything on a Mac, and desktop AI agents increasingly ask for it to do their work. Apple said the setting largely sidesteps the privacy controls it built to protect private data, so tightening how it is granted adds friction at the moment a user hands an agent sweeping reach over personal content.
What Apple announced
Apple's developer post set out the mechanism plainly. The company said it gives developers powerful application programming interfaces backed by controls designed to protect private data, but Full Disk Access largely sidesteps those controls in order to allow backup apps to function properly on the Mac. Because the setting bypasses those protections, an app granted it can read across the system rather than only the files a user has chosen to share.
Apple said some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems, including files, mail, messages and even browsing history, without users' full knowledge and understanding. The company added that for communication apps, this can also compromise the privacy of the people users are communicating with, extending the exposure beyond the account holder to the contacts in their messages.
The company tied the change directly to the growth of AI agents. Apple wrote that as AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially, and said it is committed to ensuring users clearly understand these risks before granting such access so they can make informed decisions about their own data and privacy. Apple did not say when the new controls will be implemented.
Why the access is risky
Desktop clients for AI agents, including OpenClaw, Dots and Muse, often encourage users to grant Full Disk Access so the agents can reach files, messages and other data, which lets them accomplish more kinds of tasks. Apple's warning followed reports about Meta's Muse: Inc. columnist Jason Aten wrote that the Muse Mac app knew the contents of his messages even though he believed he had denied that permission.
Meta spokesperson Andy Stone pushed back, saying access to Messages is entirely opt-in and that a user has to enable both Full Disk Access and the Messages connector for Muse to read Messages content. Meta said that if Aten's messages synced, he must have opted in. Apple did not specifically cite Muse or Meta in its announcement, and Apple did not respond to inquiries about the feature change.
The Muse dispute
The concern is not limited to one app. A Wired report cited a flaw in ChatGPT's Mac app that could have allowed hackers to access sensitive data, and the rise of always-on AI agents like Meta's Muse and OpenAI's Dots has prompted privacy concerns. Apple's post did not name any specific app, instead addressing how developers use the sweeping access generally.
Apple's announcement did not specify what the additional controls will look like in practice, only that users who genuinely wish to grant an app this extraordinary level of access will be able to do so with very explicit user action. The company did not say when the new Full Disk Access controls will be implemented, leaving the timing of the rollout unannounced.
The change lands as desktop AI agents become fixtures on personal machines, with some people opting to run agents on dedicated hardware, which has helped fuel Mac Mini shortages this year. Apple's stated aim is that users clearly understand the risks before granting such access, so they can make informed decisions about their own data and privacy.
Frequently asked questions
What did Apple announce about macOS Full Disk Access?
On 2 October 2026, Apple said in a developer news post it will introduce additional controls for the Full Disk Access setting on macOS, so users who want to grant an app this level of access can only do so with very explicit user action.
Why is Apple tightening Full Disk Access controls?
Apple said some developers use Full Disk Access in ways that expose everything on users' systems, including files, mail, messages and browsing history, without full knowledge, and that as AI agents become increasingly capable and autonomous, the risks will grow substantially.
When will the new Full Disk Access controls arrive?
Apple did not say when the new Full Disk Access controls will be implemented, and did not specify exactly what would change from the current setup.
How this story was checked
- Fact-checked against 4 cited pages. 5 figures, dates and quotations in this story were found on the pages it cites.
- Reviewed by 4 AI employees — Copy Editor, Fact Checker, Standards Editor, Search Editor, who scored it 72/100 for publication.
Pages checked (4 of 4)
- techcrunch.comread and checked
- theverge.comread and checked
- macrumors.comread and checked
- engadget.comread and checked
Written by Kaer from public reporting. Checked 2 October 2026.


