Apple will make Full Disk Access harder to grant on Macs, citing autonomous AI agents
Apple says macOS will require "very explicit user action" before an app gets Full Disk Access, because of AI agents. No date yet. Audit which apps hold it now.
On October 2, 2026, Apple said it will add new controls to macOS so that granting an app Full Disk Access, the setting that lets an app read nearly everything on a Mac, requires "very explicit user action", and it named autonomous AI agents as the reason. No release date or technical detail has been published yet. Nothing needs patching today, but anyone who manages Macs should find out which apps already hold this permission, starting with AI agent apps.
What happened, in plain English
macOS keeps different kinds of personal data behind separate permission prompts. These are the familiar "App X would like to access your Documents folder" pop-ups. Apple's name for the framework is TCC (Transparency, Consent, and Control). Full Disk Access (FDA) is the exception: one switch in System Settings that lets an app skip most of those individual checks. Apple's own help page says it gives access to "all files on your computer, including data from other apps (for example, Mail, Messages, Safari, and Home), data from Time Machine backups, and certain administrative settings for all users on this Mac."
Apple says the setting exists mainly so backup apps can work. In its developer notice it writes that "some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users' full knowledge and understanding." It adds: "As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially."
An analogy: FDA is a master key. Handing one to the backup company that comes in at night was always a calculated risk. Handing one to a new assistant who takes instructions from anyone who emails them is a different decision. Apple says the key will be harder to hand over by accident.
The announcement came days after a public dispute over Meta's Muse agent for Mac. On September 19, 2026, Inc. columnist Jason Aten reported that Muse had synced his iMessages even though, he said, he had declined that access and his Mac showed Full Disk Access as off. Meta denied it. Meta says reading Messages requires the user to turn on both Full Disk Access and Muse's own Messages connector. That dispute has not been settled publicly. Apple did not name any app.
Are you affected? What to do now
Who should care: anyone who manages Macs (IT admins, MDM owners, helpdesk staff), and Mac users who have installed AI assistants that can act on the computer. If you don't run Macs, you have nothing to do.
What changes today: nothing yet. Apple has not said which macOS version brings the change, how the new consent step will look, whether apps that already have access will be asked again, or how MDM-managed (Mobile Device Management) grants will be treated. TechCrunch corrected its story to make clear the change is about informed consent, not new limits on what FDA can reach.
Checklist:
- Find out who already holds FDA. On a single Mac, go to System Settings → Privacy & Security → Full Disk Access. Across a fleet, use your MDM's or endpoint agent's privacy-permission reporting if it has one. Write down every app that holds the permission and why.
- Separate the apps that need it from the ones that are just convenient. Backup tools and endpoint security agents usually need FDA. Don't switch it off for your EDR (Endpoint Detection and Response) or backup agent without checking with the vendor. AI assistants, chat clients and "computer-use" agents usually don't need it. They can be given specific folders or their own connectors instead.
- Remove FDA from AI agent apps that have no documented need for it. If a user needs an agent to read mail or messages, make that a deliberate, recorded exception, not something left over from setup.
- On supervised Macs, enforce it. Apple's Privacy Preferences Policy Control payload lets an MDM set the "System Policy All Files" service (FDA) to Allow or Deny per app. Apple notes this requires supervision, and that when several profiles conflict, the more restrictive setting wins. A Deny entry for unapproved agent apps covers you until Apple's change ships.
- Add AI agents to your software-approval process. Some agent apps are downloaded from the vendor's website rather than the Mac App Store, so App Store inventories can miss them.
- One awareness point for staff: if an app tells you to open System Settings and turn on Full Disk Access, stop and ask IT first.
- Watch the next macOS release notes and test with them. When the new consent step ships, check that your MDM-granted permissions for backup and security tools still work.
No official source has published indicators of compromise, and this is not a vulnerability. There is nothing to hunt for in logs.
The expert view
FDA was always the awkward part of the TCC model. TCC protects data in categories (Mail, Messages, Safari data, Desktop, Documents), and FDA is the switch that turns most of those categories off at once for one app. It has stayed tolerable because the apps that asked for it were a short, fairly predictable list: backup, disk utilities and security tools, which are usually vetted by IT or made by long-established vendors.
Desktop AI agents break that pattern. Three properties now sit in one process: broad read access to private data, the ability to take actions, and a constant stream of untrusted input (web pages, emails, documents) that can carry prompt injection, meaning text written to steer the model. Any one of these can be managed. Together they let an attacker who controls the input use the agent's access. Every permission prompt was written for one question: do you trust this vendor? An autonomous agent raises a second question: do you trust everything this agent will read?
What is new here is the platform owner, not a researcher, naming AI agents as the reason to change an operating-system permission model. The mechanism itself is not new: it is a stronger consent step, more friction in front of an existing setting. Consent steps are also only as good as the person clicking through them. A user who installed an agent to "handle my inbox" will grant whatever it asks for. Apple's own wording, ensuring users "clearly understand these risks", promises informed consent, not prevention. For managed fleets, MDM policy will do more than any prompt.
This fits the past few weeks. We covered the Muse Mac zero-day, where the risk was the local client and not the model. TechCrunch also links Apple's move to a Wired report on a flaw in ChatGPT's Mac app. The pattern is consistent: the desktop agent is becoming a privileged component, and endpoint teams should treat it the way they already treat a remote-access tool.
Still unknown:
- which macOS version brings the change and when
- whether existing FDA grants will be reset or prompted again
- how MDM grants will interact with the new "explicit user action"
- whether Apple will also review apps that ask for FDA at install time
- whether the change applies only to FDA or extends to other broad permissions, such as Accessibility, that agents also rely on
Official sources
- Apple Developer — "Updates to Full Disk Access in macOS" (October 2, 2026), the primary announcement
- Apple Support — Change Privacy & Security settings on Mac, what Full Disk Access covers
- Apple Platform Deployment — Privacy Preferences Policy Control payload settings, the MDM control for "System Policy All Files"
- Coverage: TechCrunch — Apple says it's tightening macOS 'Full Disk Access' controls due to new risks from AI agents (October 2, 2026, corrected)
- Coverage: MacRumors — Apple Announces 'Full Disk Access' Changes on macOS Due to AI Agents (October 2, 2026)
- Coverage: Help Net Security — Apple tightens macOS disk access as AI agents become more powerful (October 5, 2026)
- Coverage: The Next Web — Meta denies its Muse AI agent read a journalist's private messages (September 30, 2026), the Aten–Meta dispute and Meta's statements