Apple plans to introduce additional controls for macOS Full Disk Access. The company says the change responds to growing privacy risks from increasingly capable AI agents.
The announcement came on October 2, 2026, through Apple’s developer news platform. Apple said some developers are using Full Disk Access in ways that could expose sensitive information without users fully understanding the consequences.
Meanwhile, the change arrives as desktop AI agents gain broader access to files, applications and personal data. These systems can perform tasks on users’ behalf, making extensive system permissions more consequential.
Apple Targets Broad System Access
Full Disk Access gives an application unusually broad access to a Mac. According to Apple, the permission can expose files, mail, messages and browsing history. It can also provide access to data belonging to other applications.
Apple originally designed the permission to support applications that need extensive system access. In particular, backup software may require access that macOS privacy controls would otherwise block. However, Apple now says some developers are using the permission in ways that could put users at risk.
Consequently, Apple plans to require more explicit user action before an application receives this level of access. The company has not yet provided a detailed technical description of the new controls or a rollout date.
The change also reflects a broader shift in desktop software. Traditionally, users granted permissions to applications that performed defined tasks. Now, AI agents can interpret instructions, access multiple sources of information and carry out several actions.
Therefore, a permission that grants access to an entire Mac can create a wider security exposure when combined with an autonomous agent.
AI Agents Raise New Privacy Risks
Apple directly linked the upcoming controls to the growth of AI agents. The company said increasingly capable and autonomous agents could substantially increase the risks associated with broad system access.
Apple has also been examining security risks around agentic software more broadly. At WWDC 2026, the company warned developers about indirect prompt injection and other threats affecting AI-powered applications.
For example, Apple explained that an attacker could potentially influence an AI system through untrusted content. Such manipulation could cause an agent to expose data, take unintended actions or communicate with an external service.
The company also highlighted a particularly important combination of risks. An agent becomes more exposed when it can access private information, process untrusted content and communicate externally.
That concern is becoming more relevant as AI applications move beyond chat interfaces. Desktop agents can now interact with documents, messages, websites and other applications. As a result, the consequences of excessive permissions can extend beyond the user who installed the software.
Muse Controversy Adds Pressure
Apple’s announcement follows concerns surrounding Meta’s Muse AI agent. Technology columnist Jason Aten said Muse appeared to know the contents of private messages on his Mac despite his claim that he had not granted the agent permission to access them.
Meta disputed that characterisation. The company said Muse’s Messages integration is opt-in and requires users to enable both Full Disk Access and the Messages connector before the agent can read Messages content.
Nevertheless, the episode highlighted a broader question about how clearly users understand system-level permissions. Full Disk Access can access data across multiple applications, so users may not always associate a single permission with the full scope of information it can expose.
Apple’s response focuses on that permission model. The company said that users who genuinely want to grant an application such extensive access should take very explicit action before doing so.
The company has not yet explained exactly how the revised controls will work. However, the move signals a tighter approach to system-wide permissions as AI agents become more autonomous.
For Mac users, the change could make broad data access more visible before an application receives it. Meanwhile, developers building AI agents will need to account for stricter permission requirements as Apple continues to adapt macOS security controls to agentic software.








