Apple announced plans to tighten macOS Full Disk Access controls on October 2, 2026, warning that increasingly autonomous AI agents increase the risk of exposing sensitive personal files, messages, and browsing history without explicit user understanding.
Apple is moving to restrict how third-party software reaches deep into macOS file systems due to new privacy risks introduced by desktop-based artificial intelligence. The platform developer announced that upcoming updates will introduce additional controls
designed to ensure that users only grant this high level of system access through deliberate actions.
The Scope of Full Disk Access on macOS
Full Disk Access is one of the broadest permissions available in Apple’s operating system. Originally engineered to allow backup applications to operate across protected directories, the setting bypasses standard system safeguards and sandboxing controls.
According to Apple’s platform documentation, holding this permission allows an application to read data belonging to multiple core apps, including Mail, Messages, Safari, and Home. It also encompasses Time Machine backups and administrative settings for all users on the Mac.

When granted, the setting lets an app read an entire drive, including private emails, message histories, photos, and web browsing history. Apple noted in its Developer News post, titled Updates to Full Disk Access in macOS,
that some developers are utilizing this permission in ways that could put users at risk by exposing everything on their systems without full knowledge and understanding.
AI Agents and Autonomous Data Harvesting Risks
The push for tighter security follows heightened scrutiny over autonomous desktop assistants and AI tools that operate continuously in the background. Tools like Meta’s Muse and OpenAI’s Dots have brought these privacy questions to the forefront of desktop computing amid rising user concerns.
Inc. columnist Jason Aten reported that Meta’s Muse app knew the content of his private messages even though he claimed not to have given the AI agent permission, a claim disputed by Meta. A Wired report cited a flaw in ChatGPT’s Mac app that could have allowed hackers to access sensitive data, while OpenAI recently fixed a bug in its Mac app that could have allowed its agent to become corrupted and run malicious commands on behalf of an attacker.
Apple explicitly tied its planned policy shifts to the changing nature of modern software, noting that constant background tools can access private communications and browsing logs without clear user comprehension.
The company also highlighted a secondary privacy consequence: when communication apps harvest message histories, the exposure extends beyond the device owner to compromise the privacy of third parties taking part in those conversations.
Developer Restrictions and What Users Can Check Today
Apple’s security architecture dictates that apps cannot automatically obtain Full Disk Access through an application entitlement or code alone; users must explicitly authorize the setting inside System Settings.

While Apple has not yet released a concrete timeline, version number, or exact deployment date for the upcoming macOS controls, current users can audit their device permissions immediately by going to System Settings under Privacy & Security, then inspecting the Full Disk Access list to verify which utilities and assistants currently hold clearance to read system storage.
Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.
Apple, Platform Security Announcement
The company's announcement shows that these updated controls are necessary to protect user data as AI integration expands across the macOS ecosystem.