Apple announced plans to tighten Full Disk Access in macOS: soon, this permission will only be grantable to an app after a very explicit user action. The company directly links the decision to the growth of autonomous AI agents on Mac.

image
image

What happened

On October 2, 2026, a publication titled "Updates to Full Disk Access in macOS" appeared on the official Apple Developer portal. In it, Apple announced that Full Disk Access in macOS will soon only be grantable to an app after a very explicit user action. According to the company's explanation, developers are applying this permission, originally created for backup utilities, to bypass standard privacy APIs: through it, an app receives files, mail, messages, and browser history without the computer owner's full knowledge, and in the case of messengers, this additionally compromises the privacy of the interlocutors, who themselves did not grant any access. The announcement does not say exactly how the new permission granting will look or when the restrictions will take effect.

Context

Full Disk Access opens the entire disk content to an app, without categorization. The standard macOS privacy mechanism works differently: through privacy APIs (TCC), each data category is requested separately, and the user sees exactly what the app is asking for. The full access permission was historically intended for tasks like backups, which really need the entire disk at once. Apple's statement came against the backdrop of a boom in autonomous agents on Mac: a few days before the announcement, on September 28, 2026, 9to5Mac analyzed complaints about the agent app Meta Muse, which requests excessive access, and by the time of the statement, according to the publication, Meta Muse had exceeded 5 million downloads, and OpenAI is preparing 20 announcements around its Dots agent for the DevDay event.

Why this matters for the industry

For the industry, the main point of the statement is the wording of the reason: Apple officially acknowledged AI agents as a privacy risk at the operating system level for the first time. Full Disk Access bypasses privacy APIs (TCC), and an agent product that scans the entire disk as a universal data source relies precisely on this bypass. The change may force agent developers, including Meta Muse and OpenAI, to rewrite their data access methods under new, narrower permissions, and least-privilege design becomes a condition for product survival on macOS, not just a recommendation. There is no direct break yet: the announcement is not accompanied by details, and existing permissions continue to work, so a realistic step today is to audit exactly what agent pipelines are taking through Full Disk Access and prepare a migration to granular access so as not to be in the first wave of breakages when the rules are announced. There is also a side effect for methodology: agent results obtained with full access to user data are not equivalent to capabilities in restricted environments, so reproducible agent benchmarks will probably start explicitly recording the permission context — this is an interpretation, not a plan stated by Apple.

Why this matters for users

A practical step is available on your machine today, without waiting for new versions of macOS: open "System Settings", the "Privacy & Security" section, the Full Disk Access item, and go through the list of apps. It is worth leaving the permission only for programs that really need the entire disk; for AI agents and backup utilities, the meaning of such access should be reconsidered, because it opens your mail, correspondence, and browser history, and in messengers it extends to correspondence with interlocutors — people who themselves did not grant anything. There is no direct threat at the moment: existing permissions continue to work, and new rules are not yet described. But the trend is clear: in future versions of macOS, granting "full disk access" will become noticeably more difficult, so apps that really need it will either have to explain the benefit of such access or move to narrow permissions.

What is still unknown / limitations

This is an announcement of intentions, not an implemented change: Apple has not disclosed the mechanisms of the new restrictions, deadlines, the exact form of the "very explicit user action", or how already granted permissions will be handled in future macOS updates. The number of Meta Muse downloads and OpenAI's plans around the Dots agent (20 announcements at DevDay) are cited with reference to 9to5Mac, not the companies themselves. Expectations that specific APIs and the first wave of rewrites will appear in the near future, and that the ecosystem will shift to a permission-aware architecture in the long term, are interpretations by analysts, not confirmed Apple plans, and they need to be checked against future publications on the Apple Developer portal.

Sources

Author

Look at AI, editorial team