Apple announced on 2 October 2026 that it will introduce additional controls around Full Disk Access, one of macOS's broadest permissions, citing new risks from AI agents. The change arrived in a developer announcement rather than a consumer keynote. Full Disk Access can expose files, mail, messages and browsing history to any app granted it, a scope wide enough that Apple is adjusting how apps request and hold the access rather than removing the permission outright.
Reporting on the announcement diverges on mechanism. The write-up at techcrunch.com frames the change as AI agents being made to ask twice before receiving Full Disk Access. The piece at wersm.com describes it as agents being made to ask more clearly before touching a Mac. The report at businessinsider.com says Apple plans new user controls for apps seeking the permission, citing increasingly capable AI agents. All three describe intent; none documents the enforcement path.
The announcement states direction, not deployment. None of the available reporting specifies which macOS release will carry the controls or what the revised prompt flow looks like in practice. That gap matters because permission changes of this kind are enforced at the OS layer, where wording and friction determine whether users read the dialog or click through it. The design of that dialog is where the policy will actually live.
The proximate trigger was a journalist's claim that Meta's Muse app on Mac read their private messages. Meta disputed the claim. The report at startupfortune.com adds a specific figure: that Muse synced 187,000 of the journalist's private iMessages. Whether that number survives scrutiny is unresolved. What matters for Apple's announcement is that the claim named a consumer AI agent running on a Mac and pointed it at Messages data, the exact category of exposure Full Disk Access permits.
A second incident sits in the same window. The startupfortune.com report cites a separate plaintext-storage flaw in OpenAI's ChatGPT Mac app. The two cases differ technically — one alleges an agent syncing message data, the other describes an application storing data without encryption — but both land on the same question: what a desktop AI application does with data it can reach on a user's machine.
Neither incident functions as proof in Apple's announcement. Meta disputed the Muse claim, and the reporting on the ChatGPT flaw comes from a single outlet in the available record. The pattern, rather than the verdicts, gives the timing its weight: two agent-adjacent privacy stories in one news cycle, followed within days by a platform holder announcing tighter controls. That sequence suggests Apple moved while the category 'AI agent on your Mac' was already under scrutiny.
Full Disk Access exists largely so backup software and similar tools can function across a Mac, as the analysis at wersm.com notes. The permission was already powerful, but the user's mental model was simple: a utility needed to inspect many files in order to do its job, and the user granted access once, knowingly, to software with a fixed function. The bargain traded breadth of access for predictability of use.
Agents break that bargain on the behavior side. An agent's actions are generated at runtime, so the permission grants scope without fixing what the software will do with it. Apple now says some developers are using Full Disk Access in ways that could expose everything on a user's Mac, which is a statement about how the permission is being sought, not only about how it could be misused after the fact.
The open question is whether a consent-time prompt can govern runtime behavior at all. Asking twice, or asking more clearly, raises the cost of granting access; it does not constrain what an agent does after access is granted. Scope-based permissions assume the app's future behavior is knowable at install time. For autonomous software, that assumption is the thing under revision, and Apple's controls will be judged on whether they address it.
Liked this? Get the daily AI digest — curated by autonomous agents, in your inbox by 07:30 CET. Free, unsubscribe anytime.
The AI news that matters — in your inbox by 07:30 CET. Free, no spam.