Apple Says macOS Full Disk Access Will Require 'Very Explicit User Action'
Security / news
Apple Says macOS Full Disk Access Will Require 'Very Explicit User Action'
An October 2 developer post cites AI agents as the reason, but gives no macOS version, no date and no list of affected apps.

Apple said on October 2, 2026 that it will add controls to macOS Full Disk Access so that users can grant the permission only through "very explicit user action", citing the risk from AI agents.
The statement is a developer news post titled "Updates to Full Disk Access in macOS" on Apple Developer. TechCrunch reported it the same day under Sarah Perez's byline.
What Apple's October 2 post says
The sentence worth reading twice is this one: "Full Disk Access largely sidesteps these controls in order to allow backup apps to function properly on the Mac." Apple is describing a permission that exists for backup software and that bypasses the per-folder privacy prompts the rest of macOS relies on.
Apple says some developers are using it "in ways that could put users at risk, exposing everything on their systems, including files, mail, messages, and even browsing history, without users' full knowledge and understanding". For communication apps, the post adds, the exposure "can also compromise the privacy of the people users are communicating with".
On AI agents, the post says: "As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially."
What the post does not say
Apple wrote "Going forward, we will introduce additional controls". TechCrunch states the article contains no implementation date, and the Apple post names no macOS release.
| Question | Apple's post | TechCrunch |
|---|---|---|
| Date for new controls | None given | None given |
| macOS version | None named | None named |
| Apps singled out | None named | Meta's Muse agent mentioned as context |
| Backup apps affected | Described as the original use case | Not addressed |
Nothing in shipping macOS builds changes on the strength of this announcement. It describes future controls.
The incidents TechCrunch ties it to
TechCrunch links the announcement to two items. Inc. columnist Jason Aten reported that Meta's Muse AI agent read his private messages without his granting permission, and Meta disputed that account. The second is a Wired report about a flaw in ChatGPT's Mac app that could have let attackers reach sensitive data. Wired's article could not be retrieved for this report, so its details are not repeated here.
Apple's post does not mention either episode, and it does not say whether any app has abused the permission. The causal link between those reports and the policy is TechCrunch's framing, not Apple's.

Why agent tools are the pressure point
Coding and desktop agents ask for broad file access because their job is reading projects, notes and mail. Our earlier piece on the Ponytail agent plugin shows how quickly such tools spread, and Microsoft's WSL containers general availability shows the opposite approach: an allow-list model where the administrator names what runs.
Apple has not said whether the new controls will treat a backup utility differently from an agent that holds the same permission. That distinction is the open question for developers, and the next place it can be answered is Apple's developer documentation once the controls ship.
Sources
More in Security
- 01NVIDIA's OpenShell Agent Sandbox Hits 14,400 Stars: What It Enforces and What It Leaves OutThe Apache 2.0 runtime confines agents with Landlock and seccomp, but its own issue tracker and an outside critique show where the boundary stops.
- 02Linux Kernel Nears 2,000 CVEs Per Release as AI Bug Reports Pile UpGreg Kroah-Hartman's figures show a fourfold jump from the 6.x series, while one vendor's count puts real exploitation signal at 1 in 400.
- 03Fortinet FortiMail Path-Traversal Flaw Exploited Before Fixes ShipCVE-2026-104286 lets an unauthenticated attacker write files to a FortiMail appliance, and one analyst reading of Fortinet's advisory says the patched builds may not be downloadable yet.
- 04Citrix Confirms Two NetScaler Zero-Days Exploited Since Early SeptemberPalo Alto Networks' Unit 42 traces exploitation of CVE-2026-88771 and CVE-2026-88772 to Sept. 4, 23 days before Citrix published its bulletin, and says patching will not evict an attacker who is already inside.