Apple just fired the first shot in what is shaping up to be the defining platform fight of the agentic AI era. In a notice posted to Apple Developer News on October 2, 2026, the company announced it will tighten macOS Full Disk Access controls, and it named AI agents as the reason.
The phrasing is blunt for Apple: “As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.” Going forward, users will only be able to grant the permission “with very explicit user action.”
This is the first time a major operating system vendor has updated a core permission specifically because of agents. Not malware, not spyware, but software designed to act on your behalf.
Why Full Disk Access is the permission agents love most
To understand why this matters, you need to know what Full Disk Access actually does. macOS normally gates access to sensitive data through per-app privacy controls, the prompts that ask whether an app can use your camera, microphone, photos, or contacts. Full Disk Access largely sidesteps those controls. It was carved out so backup apps like Carbon Copy Cloner could do their job.
Once an app holds it, the reachable surface is enormous: Mail, Messages, Safari browsing history, contacts, photos, and Time Machine backups. Apple’s notice says some developers now use the permission in ways that expose “everything on their systems,” including files, mail, messages, and browsing history, “without users’ full knowledge and understanding.”
Apple even flagged the blast radius beyond the user: “For communication apps, this can also compromise the privacy of the people users are communicating with.” Your friend’s messages to you are your messages, and if an agent can read yours, it can read theirs too.
The timing points at Muse and the agent gold rush
Apple named no app and no company. But the notice landed days after a series of agent controversies that map directly onto its wording.
On September 28, Hunterbrook published an investigation into Meta’s Muse, the always-on agent Meta has been pushing aggressively. Inc. columnist Jason Aten separately claimed the Muse Mac app read his private messages without clear consent, a claim Meta disputed. And a Wired report documented a flaw in the ChatGPT Mac app that could have exposed sensitive user data.
Apple itself flagged this category of risk months ago. Its summary of the WWDC26 Privacy and Security Group Lab, published June 10, warned developers that “agentic technologies introduce a new category of risk, notably indirect prompt injection,” instructions hidden in content a model reads rather than typed by its user.
This is also a crowded field. As we covered, OpenAI’s Dots is the always-on AI agent that works while you sleep, and the agent economy keeps producing rogue agent activity serious enough to draw a California subpoena. The permission system that was fine for backup utilities is now the front door for software that acts on its own.
What Apple did not say
The notice is a policy signal, not a shipped feature. Four things are conspicuously missing:
- When. No macOS version and no date for the new controls.
- How. No description of the new grant flow or what “very explicit user action” will look like.
- Who. No app or developer is named, despite the widely shared posts tying the change to Muse.
- Existing grants. Nothing about whether apps that already hold Full Disk Access keep it.
Worth noting: most of the headline always-on agents launched in recent weeks, Meta’s Muse and OpenAI’s dots, run on their own cloud computers rather than inside your Mac. Apple’s change bites hardest at agents that run locally with broad permission, the exact setup where least-privilege principles say the risk is highest.
The 3-minute Full Disk Access audit to do today
You do not need to wait for Apple’s new guardrails. Check what you have already granted:
- Open System Settings → Privacy & Security → Full Disk Access.
- Look at every app on the list. Backup apps, antivirus, disk utilities: fine. AI agents, chat apps, anything you do not recognize: question it.
- Toggle off anything that does not need whole-drive access. Revoking it will not break the app, it will just be asked for a narrower permission the next time it needs a file.
The practical rule stays the same before and after Apple’s change: give an agent a project folder or a few connected accounts instead of the whole disk wherever the job allows it. Narrower grants are easier to review and easier to revoke.
Expect this to be the first of several platform moves, not the last. When the permission model meets software that can act autonomously, the user consent that was adequate for a backup scheduler is no longer adequate for an agent that reads your email and acts on it. Apple just said so in writing.
