macOS: Apple tightens Full Disk Access as AI agents come knocking
On 2 October 2026, Apple announced new controls on macOS Full Disk Access, the permission that hands an app the keys to your entire Mac. Its reason for the crackdown: AI agents are getting a lot more capable.

On Friday, 2 October 2026, Apple put out an update for Mac developers announcing a crackdown on Full Disk Access. TechCrunch broke the story, and The Verge picked it up that same evening. The argument fits on a sticky note: AI agents make the risk much bigger.
A permission built for backups
Full Disk Access is a macOS permission that gives an app access to everything on your system. Apple itself admits that it “largely sidesteps” the privacy controls you’re offered. It exists so that backup software works properly on a Mac. A backup tool has to read everything, because that’s its whole job. The trouble starts when other apps ask for the same master key for other reasons.
According to Apple, some developers use this permission in ways that put users at risk. It exposes everything on the system (files, emails, messages, even your browsing history) without the person involved knowing or fully understanding it. The company adds that as AI agents become more capable and more autonomous, the risks of this level of access will “grow substantially”.
What changes, and what we still don’t know
Apple is announcing new controls. They’re meant to ensure that anyone who genuinely wants to grant “this extraordinary level of access” can only do so through a “very explicit user action”. In plain English: this should no longer be something you hand over on autopilot while mashing “Continue” to make the dialog go away.
Beyond that, we know almost nothing. Apple hasn’t given a rollout date. The source doesn’t describe what that explicit action will actually look like either: no word on whether it’ll be a new confirmation window, a mandatory trip into System Settings, or something else. For developers, one thing is certain: any app that relies on this permission will face a more demanding authorisation flow, and the technical details haven’t been published yet. The Verge asked Apple for comment and didn’t get an immediate reply.
The Muse affair in the background
The announcement comes a few weeks after an article in Inc. magazine. One of its journalists found that Muse, Meta’s AI, knew what was in his messages. He says he never explicitly gave the chatbot that access, on either his iPhone or his Mac.
A Meta spokesperson disputed that account. According to the spokesperson, access to Messages is “entirely opt-in”: for Muse to read that content, you have to enable both Full Disk Access and the assistant’s Messages connector. One clarification matters here. According to the source, Meta is disputing Inc.’s account, not Apple’s decision, and no Meta reaction to the latter has been reported. It’s The Verge that links the two stories. The passage of Apple’s announcement it quotes doesn’t name a single app.
Consent: the checkbox you tick too fast
The sources don’t settle the Muse case, and that isn’t really the point. Meta’s own version shows exactly the mechanism Apple wants to rein in. Once Full Disk Access is granted, an assistant doesn’t need a vulnerability to read your conversations: an enabled connector is enough. All of your security then rests on a consent you gave once, probably in a hurry, and almost certainly never revisited.
That’s the weak link Apple is going after: the moment you say yes, not what the app does afterwards. So Apple is going to make the gesture that unlocks your whole Mac more of a hassle. For once, a speed bump is the feature.
Sources (1)
Written with AI assistance from the sources cited above, then reviewed and approved before publication by Sébastien Soulier.


