Apple said on October 2, 2026 that it will tighten macOS Full Disk Access controls because AI agents raise the risk that apps can read files, mail, messages, and browsing history without users fully understanding the grant, according to an Apple Developer News post titled “Updates to Full Disk Access in macOS.”
Full Disk Access was built so backup apps can work around narrower privacy controls on the Mac. Apple said some developers now use that permission in ways that can expose everything on a system without users’ full knowledge and understanding, and that for communication apps the privacy of people users talk with can also be at stake.
“Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action,” Apple wrote. The company framed the change as critical as AI agents become more capable and autonomous, and said it wants users to clearly understand the risks before approving that level of access.
TechCrunch reported the same statement, noting the timing after Inc. columnist Jason Aten claimed Meta’s Muse Mac app read private messages – a claim Meta disputed – and after a prior Wired report on a ChatGPT Mac flaw that could have exposed sensitive data. TechCrunch said Apple did not respond to questions about when the new controls will ship. Apple’s post describes a forward-looking change, not a same-day flip of the existing setting.
The news is Apple’s policy signal that backup-era Full Disk Access will face a harder, clearer user gate as desktop AI agents ask for broad system reach. The Muse dispute and the Wired ChatGPT report are context for why the company is talking about agent-era risk; they are not adjudicated findings in Apple’s announcement.