AI Affairs, home

Saturday 3 October 2026

Technology

Apple plans tighter macOS Full Disk Access controls over AI agent risks

The permission can expose messages, mail and browsing history. Apple says granting it will require a more explicit action, after a disputed account involving Meta’s Muse app.

An Apple MacBook Air keyboard and screen with macOS settings and app icons
Photo: Guilherme Pedrosa via Pexels

Apple said on 2 October 2026 that it would add controls to macOS Full Disk Access, a permission that can expose personal data to apps, as more capable AI agents make that level of access riskier, TechCrunch reported. The company said granting the permission under the new controls would require a very explicit action by the user.

Key points

  • Full Disk Access can give an app access to files, mail, messages and browsing history.
  • Apple says increasingly autonomous AI agents increase the risks of granting that permission.
  • The announcement followed a disputed account involving Meta’s Muse app and private messages.

Full Disk Access reaches beyond files

Full Disk Access was designed in part to let backup apps work properly. A backup needs to copy material from across a computer rather than open only the document in front of it, which helps explain why this permission reaches so widely. Apple says an app given the setting can access files, mail, messages and browsing history. That same breadth becomes consequential when an app is able to act on its own.

The reach extends to data held by other apps, including Mail, Messages, Safari and Home, as well as Time Machine backups and certain administrative settings, according to Apple’s Mac User Guide as described by Unite.AI. Full Disk Access is therefore a different decision from allowing an app to open a particular folder. The permission concerns areas of the Mac where several kinds of personal information can be kept.

Apple’s Platform Security guide says apps needing full storage access have had to be explicitly added in system privacy settings since macOS 10.13, Unite.AI reported. For more limited access, macOS 10.15 or later helps obtain consent before an app reaches locations including Documents, Downloads and Desktop. Full Disk Access instead requires a change in the Mac’s privacy settings, rather than the prompt used for requests to reach particular files and folders.

Looking up an old message could involve far more data than that message if the app used for the task had Full Disk Access. The same permission would allow it to reach mail, other files and browsing history. Apple’s planned controls would put a more explicit decision in the way of granting that broad access.

Apple seeks a more explicit permission

Apple said some developers were using Full Disk Access in ways that could expose everything on a person’s system without that person fully understanding the access being granted. Its concern is not confined to the files belonging to the app receiving permission: the setting can also reach communications and data stored elsewhere on the Mac. The company said people who want to allow that reach should have to take “very explicit user action”.

In its announcement to developers, Apple linked the change directly to AI agents becoming more capable and autonomous. Its warning was about what those apps could do once given broad access: “the risks associated with this level of access will grow substantially,” the company wrote. An agent’s ability to work across files and messages makes the scope of a standing permission particularly important, even when the permission was granted for a useful task.

That puts the decision to grant access at the centre of Apple’s plan. Developers whose apps depend on Full Disk Access would still be asking people to permit unusually wide access under the controls Apple described, but the company wants the act of granting it to be unmistakable. Unite.AI reported that Apple’s Developer News announcement gave no date or macOS version for the change and named no developer or app.

Macs managed through a device management service have another route for administering privacy permissions. Apple’s Platform Deployment guide describes a setting called System Policy All Files that can specify whether an app is allowed or denied access to data including Mail, Messages and Time Machine backups. Where a managed Mac receives multiple privacy preference policies, the operating system applies the more restrictive settings.

Jason Aten’s account of Meta’s Muse

Apple’s announcement followed a report by Inc. columnist Jason Aten that Meta’s Muse app for Mac knew the contents of his private messages, despite his account that he had not given the AI agent permission. Meta disputed the claim, TechCrunch reported. Muse offers an option to enable Full Disk Access, a setting through which an app can be permitted to read messages as well as other material on the computer.

Aten’s account and Meta’s denial leave a dispute over what happened in that instance. Apple’s warning addresses the wider permission available to desktop apps: Full Disk Access can place messages alongside files, mail and browsing history within an app’s reach. The company says its additional controls are intended to make the choice to allow that reach more explicit as agents gain the capacity to carry out more actions.

The scrutiny of desktop AI apps also extends beyond Muse. TechCrunch reported that Wired had described a flaw in the ChatGPT Mac app that could have allowed hackers to access sensitive data.

Topics: Agents, Safety