Wain AI/Tech Blog

AI news and trends worldwide, updated nearly every day

Apple Signals Added Controls for Full Disk Access on macOS - Says Risk Grows as AI Agents Act With Less Supervision

Apple Signals Added Controls for Full Disk Access on macOS - Says Risk Grows as AI Agents Act With Less Supervision

Apple told developers on October 2, 2026 that it will add controls around Full Disk Access on macOS. The permission was carved out for backup software and routes around existing privacy machinery, reaching files, mail, messages and browsing history. No timing and no macOS version were given.

On October 2, 2026, Apple told developers it will add controls around Full Disk Access on macOS1. The reason it gave is a forecast: as AI agents gain capability and operate with less supervision, what this one permission exposes turns into a bigger liability.

The notice runs to two paragraphs and says nothing about implementation. It is clear, though, about how Apple frames the permission. It exists so that backup software can do its job, and in exchange it steps around the privacy machinery that normally fences an app off from a person’s data.

What a single switch opens

By Apple’s own account, an app holding this permission can see everything stored on the machine, mail and messages and browsing history included1. Some developers, the company writes, have been using it in ways that hand over the entire system without the person grasping what they agreed to. Where the app handles conversations, it adds, the exposure reaches the people on the other end too.

Apple then says it will add controls so that this degree of access can only be handed over through an unmistakably deliberate act. The wording points at the path to the grant rather than at the permission itself: nothing in the notice suggests Full Disk Access is being withdrawn.

What the notice does not say

It stops short of anything an engineer could plan around. There is no date, no macOS version, and no description of what the new controls will look like — a reworked dialog, a grant that expires, separate rules by app category. No app and no developer is named1. TechCrunch reported that Apple did not answer its questions about the change2.

So the firm fact today is that Apple has publicly committed to changing how this permission gets handed out. When an existing app will feel that change cannot be worked backward from the notice.

Desktop agents are asking for the same switch

Apple naming AI agents as its reason has a backdrop. TechCrunch described desktop AI agents as apps that gain wide reach into a person’s files, messages and whatever else sits on the machine once macOS settings are changed2.

Agents that live on someone’s own Mac have been arriving in quick succession. On October 1 GitHub put desktop app control for Copilot into public preview on macOS and Windows. In September Meta began offering Muse, a personal AI agent, in the United States.

Each of those was a question of how much an app or an agent restrains itself. What Apple describes sits one layer below that, in how the operating system passes the permission across.

The incident that reporting ties to it

Apple names no app, but reporting has connected the notice to the past few days. According to TechCrunch, it followed a report by Inc. columnist Jason Aten, who said Meta’s Muse knew what was in his private messages although he had not granted it access2.

Meta rejects that account. TechCrunch reported that Andy Stone, the company’s VP of communications, wrote on X that the Messages tie-in in the Mac build of Muse is opt-in throughout, and that two separate toggles have to be switched on — Full Disk Access, plus the Messages connector — before Muse can read what is in a message3. David Singleton of Meta Superintelligence Labs replied to Aten on Threads, describing a chain of application-level permissions layered with protections built into macOS, which he said a bug in the app could not get around. Without Full Disk Access the Messages access levels cannot be picked at all; granting it drops the person into the macOS settings interface to confirm the intent a second time, and the Muse app restarts afterward. Aten’s account has Full Disk Access switched off when it happened, and Singleton answered that the model was confused and gave a wrong account of its own behavior. Which version is right remains contested between the two sides.

Meta’s own explanation, though, places Full Disk Access ahead of message access as the precondition3. That entry point is precisely what Apple says it is going to touch.

Where this lands for builders and for operators

For anyone shipping an agent that runs on a Mac, feature designs resting on Full Disk Access need another look. Rewriting code while the shape of the new controls is unknown is awkward, but it is no longer safe to assume one broad grant will stay as cheap to obtain as it is now. Where a narrower, per-purpose permission path can be built instead, that route looks more likely to survive the change.

For anyone running agents, the thing to check narrows to one place. Open the list of apps holding Full Disk Access in System Settings and the answer to what each of them can read is already there. Defenses do not always behave as configured, as the case of commands running outside the sandbox without a prompt in Claude Code showed. Pruning grants, and knowing which ones have been handed out, are both available today without waiting on Apple.

Sources

  1. Updates to Full Disk Access in macOS - Apple official developer notice (October 2, 2026)
  2. Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents - TechCrunch (October 2, 2026)
  3. Meta disputes claim that Muse read a user’s private messages without permission - TechCrunch (September 30, 2026)

We publish the latest AI news nearly every day.

Subscribe via RSS Get new posts the moment they go live.

Search other keywords →