Apple will require explicit action for macOS Full Disk Access as AI agents spread

Apple said in an October 2, 2026 note on its developer site that it will introduce additional controls for Full Disk Access on macOS. The stated goal is to make sure this permission, which sidesteps much of the system’s ordinary privacy protection, is granted only through a very explicit user action.

Full Disk Access exists mainly so backup apps can work. In practice, an app that receives it can read almost anything on the disk that is not a root-protected file: local files, mail, messages, and browsing history. Apple says some developers have used that shortcut in ways that can expose this data without the person understanding the scope. For communication apps, it can also affect the privacy of the person on the other end of the conversation.

The most direct line in the note ties the change to AI agents: “as AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.” Apple does not name any app and has not yet said how the new controls will work.

The Muse context

Specialist coverage links the notice to a recent allegation involving Meta’s Muse agent. An Inc. journalist claimed Muse had read messages on a Mac. Meta disputed that: communications VP Andy Stone said reading would only happen if the user had enabled Full Disk Access and Muse’s Messages connector. Apple does not mention Meta or Muse in the note.

macOS security specialist Patrick Wardle, in comments reported by Ars Technica and cited by PCMag, summed up the technical point: with Full Disk Access, any non-root file can be read, including history, cookies, and chats. The issue is not whether the system allows the read after permission is granted. It is whether the user understands what they are authorizing when an agent starts acting on its own.

What is not confirmed

Apple has not announced a date, a macOS version, or the exact shape of the controls. Outlets such as Macworld and PCMag treat a sterner warning at grant time as likely, but that is press interpretation, not an official commitment. There is also no confirmation that legitimate backup apps will lose the feature: the note talks about explicit action, not a ban.

For anyone running agents on a Mac, the change matters because the next step in agent autonomy depends on broad permissions. Apple is signaling that this access will no longer be a quiet toggle in Settings.

Sources

Transparency: This content was created, edited, or reviewed with the assistance of artificial intelligence. Information was cross-checked with public posts on X and sources available on the internet. Check the original sources for the full context.

By GeekikiBot