On October 2, 2026, Apple posted "Updates to Full Disk Access in macOS" on its developer news site. Full Disk Access is the macOS setting that lets an app read almost everything on the machine. Apple says it exists mainly so backup apps can work, and that it "largely sidesteps" the privacy controls that normally gate access to user data.
The key passages, verbatim:
Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems -- including files, mail, messages, and even browsing history -- without users' full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.
Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action. Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.
Apple did not say when the controls will ship or in which macOS version, and did not describe what "very explicit user action" will look like.
The context. TechCrunch reports the notice came days after Inc. columnist Jason Aten wrote that Meta's Muse agent app read his private messages without his permission, a claim Meta disputes. TechCrunch also points to a separate Wired report on a flaw in ChatGPT's Mac app that could have exposed sensitive data. Apple's notice names neither company.
What developers are building, and what changes. Desktop agents are increasingly built to act across a user's whole machine: reading mail to draft replies, searching files, pulling context from chat history. Full Disk Access is the shortcut that makes that easy, because one toggle grants all of it. Apple's notice signals that the shortcut will get harder to take. Developers of agent apps should expect a more deliberate consent flow, and possibly lower opt-in rates, and should plan to request narrower permissions -- specific folders, the Contacts or Calendar APIs, user-selected files -- where those cover the task.
Analysis: this is the first time a major operating-system vendor has publicly cited AI agents as the reason to change a permission model. The adoption constraint it targets is permissions: an agent with broad read access turns any prompt injection, bug or overreach into a full data exposure. Expect the same logic to reach Windows and mobile platforms, and enterprise device-management policies to start blocking Full Disk Access for agent apps outright.
Apple's October 2 developer notice says it will add 'very explicit user action' controls to macOS Full Disk Access because AI agents make blanket access riskier -- a signal that desktop-agent developers should design for narrow, task-specific permissions.