Apple announced on October 2, 2026, that it will introduce stricter macOS controls for Full Disk Access. The Cupertino company cited privacy and security risks from autonomous artificial intelligence agents capable of reading private user files, mail, messages, and browsing history without full understanding.
Apple Alters Full Disk Access as AI Agents Expose Local Files
Apple plans to introduce new privacy controls for Mac users, warning that granting broad system access to third-party software creates vulnerabilities. The Full Disk Access setting on macOS was originally created to allow backup tools to function properly across local storage. However, the rise of desktop-based AI assistants has altered security conditions.
In a note addressed to developers, Apple stated that some developers are using Full Disk Access in ways that could put users at risk by exposing everything on their systems. This includes personal files, email archives, messages, and browsing histories without users fully understanding the trade-offs. For communication apps, this can also compromise the privacy of the people users are communicating with.
“Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding.”
Apple Inc., Developer News Statement
Recent Incidents Prompt Policy Changes For Desktop AI
Tech columnist Jason Aten reported that Meta’s general-purpose AI agent Muse displayed knowledge of a private message thread between him and a coworker, despite Aten stating he never granted permission for message reading. The policy announcement followed real incidents with prominent desktop AI applications. Meta Chief Technology Officer David Singleton disputed the account, stating that the Messages integration in the Muse Mac app is opt-in and requires both macOS Full Disk Access and an active Messages connector setting. Meta spokesperson Andy Stone likewise responded by noting that your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled. Meta PR reiterated that the integration is strictly opt-in.
Separately, a Wired investigation revealed a vulnerability in the ChatGPT Mac application that could have permitted unauthorized access to sensitive user data. macOS security expert Patrick Wardle noted that Full Disk Access makes any non-root file readable, including browser cookies, chats, and browsing history. Social media also saw widespread user debate following Aten’s report, with many participants comparing AI assistants with access to calendars, emails, messages, and shopping accounts to a skill saw or other power tool that can do real damage if not handled carefully. Furthermore, the rising popularity of running agents on dedicated machines has helped fuel Mac Mini shortages throughout the year.
Extraordinary Access Will Require Explicit User Action
Apple did not specify an implementation timeline or rollout date for the upcoming macOS changes. Nevertheless, the company confirmed that future updates will introduce additional controls to restrict how applications obtain system permissions.
“Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action.”
Apple Inc., Developer News Statement
Desktop clients for AI agents, such as OpenClaw, Dots, and Muse, routinely prompt users to adjust macOS settings so the software can execute automated tasks across local files and messaging platforms.

Apple emphasized that communication apps handling these permissions can inadvertently compromise the privacy of unconsulted third parties who are communicating with the user. The company stated that addressing this issue is critical because the risks associated with broad system access will grow substantially as artificial intelligence agents become increasingly capable and autonomous.
Developers Debate Rules While Mac Utilities Face Scrutiny
Some power users criticized stricter permissions as Mac cell-phonification
, while technical commentators argued that proper sandboxing of agent processes would perform better than user-awareness prompts. The developer community has voiced mixed reactions to the policy change. Other developers pointed out that Full Disk Access is relied upon by a wide variety of standard Mac utilities, launchers, and editors rather than backup software alone. Reviewers noted that standard user configurations often include alternative apps such as the Finder replacement Bloom, launchers like Alfred, the selection utility PopClip, Apple’s own Pixelmator Pro, Setapp, TestFlight, Unread, Supercharge, Madden NFL 27 Arcade Edition, and Hazel.