Apple Named AI Agents as the Reason It Is Changing macOS Full Disk Access
Apple announced new controls for macOS Full Disk Access on October 2, citing AI agents as the reason a permission designed for backup tools has become a liability. Here is what changes and what to check before it lands.
· 420 words
Apple published a developer notice on October 2 announcing new controls for Full Disk Access on macOS, the permission that lets an app read files, mail, messages, and browsing history across the entire disk. The reason it gave was AI agents.
Full Disk Access was designed for backup tools. A backup tool runs on a schedule, reads what it needs, and stops. An agent with the same permission runs on every task, for every session, with no built-in expiration. The access does not expire with the workflow. The grant mechanism that worked for one-shot utilities is the wrong design for software that acts autonomously over time.
The announcement came days after two separate incidents. An Inc. columnist reported that Meta's Muse had read the content of his private messages without, he said, his authorization. Meta disputed the claim. Separately, Wired reported a flaw in the ChatGPT Mac app that could have let attackers access sensitive data. Apple announced the change without referencing either incident directly. The language it used was about the class of behavior: developers using Full Disk Access in ways that expose everything on a user's system without that user's full knowledge.
Going forward, Apple says, granting Full Disk Access will require very explicit user action. It did not specify a timeline or what the new UI will look like. What it settled is the direction: the consent burden moves upstream, from an onboarding checkbox to something the user has to actively choose with the full scope explained.
What to do now
If you build an agent that currently requests Full Disk Access during setup, you have two jobs before Apple's new requirement lands. The first is writing the explanation you will show users: what your agent needs that access for, specifically, and why a narrower scope would not cover it. If you cannot write that explanation in one clear paragraph, the permission scope is broader than it needs to be.
The second is checking whether Full Disk Access is actually required. macOS Privacy controls let you scope down to named directories rather than the full disk. An agent that reads a project folder and a downloads directory does not need the full-disk grant. Scoping to named paths is available today.
For agents you run rather than build, the check is simpler: if the setup flow did not explain why the app needed Full Disk Access, the scope is almost certainly wider than the task required. Apple is fixing that at the platform level because developers did not.
Sources
https://techcrunch.com/2026/10/02/apple-says-its-tightening-macos-full-disk-access-controls-due-to-new-risks-from-ai-agents/ · https://developer.apple.com/news/?id=p6zjojqw