On October 2, 2026, Apple told developers it is changing one of the most powerful switches in macOS — Full Disk Access — because of AI agents. In a post on its developer news site, Apple said it will introduce “additional controls” to make sure users grant that level of access only through “very explicit user action.” The reason, in Apple’s words: “As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.”
If you run local AI agents, desktop automation, or any workflow that reads your files and messages on a Mac, this affects you directly. Here is what Apple said, what triggered it, and what to check on your own machine.
What Apple actually announced
Full Disk Access is the macOS permission that lets an app read everything on your Mac — files, mail, messages, browsing history — bypassing the usual per-app privacy controls. It exists for legitimate reasons: backup apps need it to do their job.
Apple’s announcement is unusual because it names the culprit outright:
“Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems — including files, mail, messages, and even browsing history — without users’ full knowledge and understanding,” said Apple. “For communication apps, this can also compromise the privacy of the people users are communicating with.”
The key sentence: “Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action.”
Apple did not say when the new controls arrive. Expect them to land as extra confirmation friction — harder to grant by accident, harder for installers to quietly toggle — rather than a removal of the setting.
What triggered it: the Muse complaints
The immediate spark is Meta’s Muse, an always-on AI agent that can do complex tasks like canceling unused subscriptions or haggling for better prices. After Meta’s conference last week, users complained that Muse accessed what they believed were private messages on their Macs. Inc technology columnist Jason Aten accused Muse of reading his private messages, and said he had not enabled Full Disk Access.
Meta spokesperson Andy Stone pushed back, saying Muse’s access to the Messages app is strictly opt-in: “You have to enable both Full Disk Access and the Messages connector for Muse to be able to read your Messages content. It can’t read your Messages unless you do this. And it can be revoked at any time.”
The broader context is the always-on agent wave: OpenAI’s Dots (agents with their own cloud computer working around the clock), Microsoft’s Autopilot in Teams and Outlook, and Meta’s Muse. These agents need deep access to be useful — and deep access is exactly what worries Apple. Apple declined to comment beyond its developer post.
Why this matters if you build agents or automation
Most of the readers of this site run workflows on servers, but plenty develop on a Mac — local AI agents, desktop automation tools, and MCP servers that read your files, notes, and email. A few practical takeaways:
-
Audit what has Full Disk Access right now. Go to System Settings → Privacy & Security → Full Disk Access and look at the list. If a tool you installed months ago no longer needs that level of access, revoke it. Least privilege is the cheapest security you have.
-
Expect new friction in install flows. Once Apple’s controls land, apps that today guide users to flip Full Disk Access in one click may hit extra confirmation steps — or get blocked from guiding users at all. If you distribute a Mac tool or MCP server that needs file access, plan for this now.
-
Watch the sandboxing gap. iPhones and iPads sandbox apps by default — no single app can read another app’s data. Macs are more flexible, and that flexibility is exactly what Apple is now putting guardrails around. Design your local agents assuming access gets narrower, not wider.
-
This is a pattern, not a one-off. Apple’s move follows a week of agent-accountability pressure, including the bipartisan AI Agent Accountability Act introduced in the US Senate on October 1, which would make AI company executives criminally liable when their agents hack into systems. The era of “the agent can do whatever the user technically allowed” is ending.
Key Takeaways
- Apple announced (Oct 2, 2026) that macOS Full Disk Access will get “additional controls” requiring “very explicit user action,” citing risks from increasingly capable AI agents.
- The trigger: complaints that Meta’s always-on Muse agent accessed private Mac messages; Meta says access is strictly opt-in and revocable.
- If you develop agents or automation on a Mac: audit your Full Disk Access list today and design for narrower access in the future.
Next step: check which apps currently hold Full Disk Access on your machine — it takes thirty seconds, and it’s the one permission review that actually matters this week.
Audit your Mac’s privacy settings today.