Apple tightens macOS Full Disk Access as AI agents raise the risk
Apple said Friday it will add stronger controls around Full Disk Access on macOS, warning that some apps use the permission in ways that can expose a user's files, mail, messages, and browsing history without clear understanding — a risk the company says will grow as AI agents become more autonomous.
Desktop AI agents want the keys to the whole machine. Apple just told developers that the old Full Disk Access shortcut — the one that can see mail and messages — is getting a harder yes from the user, because agents make that permission more dangerous, not less.
On Friday, 2 October 2026, Apple published a developer notice titled “Updates to Full Disk Access in macOS.” The page is Apple Developer News. It prints October 2, 2026. It does not print an hour. Full Disk Access is a switch in macOS, the Mac operating system. Turn it on for an app, and that app can read much more of the computer than the usual privacy prompts allow. The notice is Apple’s.
What the permission was built for. Apple says it gives developers powerful tools so apps can do more, with controls meant to protect a person’s private data. Full Disk Access, Apple says, largely sidesteps those controls so backup apps can work on the Mac. A backup app has to copy the machine, including files a person would not approve one prompt at a time. Sidestep, in that sentence, means the permission skips the checks that normally ask first. Those lines are Apple’s.
What Apple says some developers are doing with it. Some are using Full Disk Access in ways that could put users at risk. The notice says that can expose everything on their systems, including files, mail, messages, and browsing history, without users’ full knowledge and understanding. Browsing history is the record of sites a person has opened. Mail and messages are the conversations stored on the Mac. Those lines are Apple’s. The notice does not name an app.
Who else is exposed. For communication apps, Apple says this can also compromise the privacy of the people a user communicates with. A communication app is one that sends and receives messages. The risk Apple names is the person who turned the switch on, and also the people in those threads. Those lines are Apple’s.
What Apple says comes next. Going forward, Apple will introduce additional controls so a user who genuinely wants to grant an app this level of access can do so only with very explicit user action. Extraordinary is Apple’s word for that access. Very explicit user action means a clearer yes than the switch people already know. The notice does not name a macOS version. It does not say when the new prompts will appear. Those lines are Apple’s.
Why Apple says the timing matters. “As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.” An AI agent, here, is software that can take steps on the computer. A chat box answers. An agent can act. Autonomous means it can keep going with less of a person steering each step. Capable means it can do more of those steps. Apple says addressing this is critical. It says it is committed to making sure users clearly understand these risks before they grant that access, so they can decide about their own data and privacy. That quotation is Apple’s, in the notice.
What TechCrunch reported the same morning, and where that reporting stops. Sarah Perez at TechCrunch, with the page stamped 11:11 a.m. Pacific on 2 October 2026, wrote that the notice follows other reporting about Meta’s Muse app on the Mac and about a flaw in the ChatGPT Mac app. TechCrunch says Inc. columnist Jason Aten reported that Muse knew the content of his private messages, and that he said he had not given the agent permission to read them. TechCrunch says Meta disputed that claim. TechCrunch also says a Wired report described a flaw in ChatGPT’s Mac app that could have let hackers reach sensitive data. TechCrunch says that in Muse’s case the app can optionally ask the user to turn on Full Disk Access. Apple did not answer TechCrunch’s question about the change. Those sentences are TechCrunch’s account of that other reporting. Apple’s notice does not name Muse or ChatGPT, and it does not say Apple removed either app.
The picture is a desk graphic. A dark indigo field. An orange panel on the right. The Apple logo sits with the word macOS. The lines read Full Disk Access, then AI agents raise the risk, then files, mail, messages, and browsing, then very explicit user action. Beside the type is the orange folder icon Apple uses for Full Disk Access, with a lock and a key. The frame does not print a calendar date. It is a graphic of the permission and the warning. It is not a photograph of a System Settings pane, and it does not show a new prompt.
In plain terms, Apple told developers on Friday that Full Disk Access, the old permission that lets a backup app see nearly the whole Mac, is being used in ways that can expose files, mail, messages, and browsing history without a user fully understanding that. For message apps, Apple says the people on the other side of those conversations are exposed too. Apple says it will add controls so that kind of access takes a very explicit yes. Apple says the risk grows as AI agents get more capable and more autonomous. The notice does not name a software version or a date for the new prompts. TechCrunch ties the timing to reports about Muse and about a ChatGPT Mac flaw. Meta disputed the Muse claim, Apple did not answer TechCrunch, and Apple’s own notice does not name those apps.
