Apple says it will tighten Full Disk Access, the macOS permission built so backup apps can work properly, because AI agents make that level of access far riskier. In an October 2 Developer News post, Apple said future grants of this “extraordinary level of access” will require “very explicit user action,” and that the risks “will grow substantially” as agents become more capable and autonomous. It gave no ship date and showed no technical design.
That omission matters. Nobody can test these controls yet. What Apple has done, in effect, is concede that the Mac’s old consent bargain fits badly with software that can read, reason and act.
🍎 What Apple actually announced about Full Disk Access, and what it did not

Apple’s short Developer News post is unusually direct. Full Disk Access, it says, “largely sidesteps” the controls macOS uses to protect private data. That exception exists, according to Apple, so backup apps can function properly on the Mac.
Some developers, Apple wrote, are using the permission in ways that could put users at risk, exposing files, mail, messages and even browsing history “without users’ full knowledge and understanding.” For communication apps, it added, this can also compromise the privacy of the people users are talking to. The person on the other end of a Messages thread never saw a macOS consent dialog, after all.
The promised response is an additional set of controls. People who genuinely want to grant this level of access will only be able to do so through “very explicit user action.” Apple tied the change directly to autonomy: “As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.”
Three blanks remain. Apple did not say when the controls will ship, how they will work, or whether existing grants will be revisited. TechCrunch reported that Apple did not respond to its inquiry about the change, and The Verge noted that the company didn’t say when the update will roll out. Apple also named nobody. No Meta, no Muse, no OpenAI, no Dots.
So the news is narrower than a macOS redesign and bigger than a dialog tweak. Apple has spotted a category error. Full Disk Access used to describe the territory an app could inspect. With an agent, it may also define the territory in which software makes decisions.
💾 Why Full Disk Access existed in the first place
The permission makes sense for a backup app. A backup that silently skips protected databases, mail or user files is barely a backup. So Apple built an escape hatch around the normal privacy compartments and made users switch it on by hand as a system-level permission.
That model assumed a fairly legible link between capability and purpose. A backup product reads broadly because broad reading is its stated job. Users may not know every directory involved, but they can connect the request to what the product does.
Desktop AI agents break that line. Their pitch is breadth: find something, summarize it, connect it to another source, take the next step. The very feature that makes an agent useful makes the permission hard to explain in one dialog. “Access your disk” tells you nothing about which future prompt will touch a Messages database, a browser cookie or a mail archive. It cannot describe a chain of actions nobody has planned yet.
Full Disk Access is also coarse. Apple’s own description says it largely sidesteps privacy controls, which is a long way from approving one folder or picking a file in an open dialog. Once granted, the operating system has accepted a broad trust decision. Any finer promise may live inside the app.
That is the gap any rewrite has to close. Consent now has to cover software initiative, connectors added later and the chance that another process steers the trusted agent, on top of where the data lives.
💬 Muse, Messages and the two-permission fight

The immediate argument started with a private conversation. Inc. columnist Jason Aten said Meta’s Muse sent him an unsolicited notification referencing an Apple Messages thread with a co-worker. Aten said he had never given Muse permission to read his messages and had assumed they were off-limits.
Meta disputes the idea that Messages access happens by default. Spokesperson Andy Stone wrote on X that it is “entirely opt-in”: the user must enable both Full Disk Access and the Messages connector, and can revoke access. Meta CTO David Singleton made the same case on Threads: “Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled.”
The public record does not establish whether Aten’s Mac had Full Disk Access switched on. Filling that gap with a guess would be wrong. So would flattening Meta’s account into “Muse secretly reads Messages.” Two separate controls sit at the center of Meta’s defense.
Then comes Patrick Wardle. The macOS security researcher told Ars Technica that, from a technical point of view, with Full Disk Access “any (non-root file), is readable,” including browsing history, browser cookies and chats. When Ars asked Meta how Muse could be the exception, Meta’s PR team simply repeated Singleton’s statement. So the uncomfortable question stands. Once the operating system has granted the broad privilege, is the Messages connector a real gate, or a product rule enforced inside Muse?
Apple’s statement sharpened that tension without naming Meta. Developers, Apple said, are using Full Disk Access in ways that can expose messages, mail and history without users’ full understanding. Meta says the connector is a second switch that has to be on. Both can be true while the consent system still fails the comprehension test.
Stacking toggles does not automatically produce informed consent. Someone may approve Full Disk Access during setup, enable a connector weeks later and never see the combined capability as one decision. The operating system sees one grant. The product sees another. The user experiences a cheerful assistant that suddenly knows a private fact.
Two clicks can create one permission boundary. The interface should say so.
🧨 When the agent itself becomes the privilege

Eleven days before Apple’s post, Wardle disclosed a Muse configuration with a nastier shape. As Ars described it, any app or code running on the Mac, including commands injected through ClickFix attacks, could take full control of the assistant. From there, an attacker could reach the same resources Muse could.
That widens the question. Whether Muse should read a local database still matters. The sharper one: what can steer Muse after the user has trusted it?
An agent with broad local access is a privilege bundle. If untrusted code can feed it instructions, the attacker may not need to defeat every macOS privacy control one by one. The agent already crossed those gates with the user’s blessing. Compromise the interpreter and its approved reach comes along for the ride.
Apple’s focus on explicit action is necessary, then, but incomplete on its own. A clearer ceremony may cut down casual grants and setup fatigue. It says nothing yet about how macOS should contain an agent after approval, show what it accessed, separate user instructions from hostile input, or interrupt an unexpected chain.
When I went through OpenAI’s list of AI agent failure modes, use of exposed credentials and command injection were both on it, and the useful question each time was which boundary failed. Local privileges add a heavier layer. A capable model, permissive tools and weak instruction boundaries can turn one mistaken trust decision into access across years of personal data.
Amazon’s response shows the fight reaches beyond Apple’s settings panel. Ars reported that Amazon blocked Muse from its platform, saying such apps “should operate openly and respect service provider decisions about whether or not to participate.” An agent sits among several parties with competing consent claims: the Mac owner, the people in private threads, the app developer and the services being accessed.
One checkbox cannot settle all of them.
🤖 Dots and ChatGPT Mac: related risk, different products
OpenAI’s Dots makes the category easier to see. The Pro+ agent, priced at $100 a month, works inside a VM and can optionally reach the desktop through the ChatGPT app. The product story differs from Muse, but the security question rhymes: when an agent crosses from an isolated environment into a personal computer, which old permissions become part of its tool set?
I covered the product and pricing in the DevDay 2026 Dots analysis, so no launch replay here. For Full Disk Access, the boundary crossing is what counts. A VM can fence in one part of an agent’s work. Optional desktop access opens another zone, full of logged-in accounts, communications and browser state.
Product names can distract from the shared operating-system problem. Muse may organize personal context. Dots may run longer tasks. ChatGPT for Mac may feel like a familiar chat window. macOS still has to decide what each process can read, and what happens if its control path is hijacked.
There is already a reported example. TechCrunch pointed to a Wired report that a flaw in ChatGPT’s Mac app could have allowed hackers to access sensitive data. TechCrunch’s summary goes no further than that, so neither will I. It is still enough to drop the comforting idea that a big brand makes local access uneventful.
Agent products need their own controls, and Apple owns the floor beneath them. If Full Disk Access permits far more than a user can reasonably picture, app-level connectors are a second line of defense at best. Containment still has to come from the operating system.
⏱️ Microsoft’s clock is running below 24 hours
Apple’s post landed a day after Microsoft published its 2026 Digital Defense Report, and the numbers there are useful context. Microsoft says the median time from vulnerability discovery in the wild to weaponization has fallen to well below 24 hours. Enterprise remediation for critical external vulnerabilities, it adds, can take 30 to 60 days.
That mismatch is brutal.
Nearly 40,000 CVEs were published in the first half of 2026, according to the report, putting the year on track to roughly double. Between February and early May, Microsoft Defender observed ClickFix-style attacker-supplied commands executed on more than 1.1 million unique devices, roughly an eightfold increase.
ClickFix matters here because it talks a person into running commands. Wardle’s Muse finding supplies the local bridge: injected commands may steer an already privileged assistant. No single statistic proves an attack against a specific AI product. Together, though, they explain why an operating-system vendor cannot treat agent permissions as a slow design exercise.
Microsoft also sees AI used across vulnerability discovery, reconnaissance, phishing, malware and exploit development and post-compromise activity, and says agentic systems are beginning to automate more of the attack chain. One line in the report could have been written about Muse: “An AI agent with excessive permissions can create a new path to data, applications, or infrastructure.” Attackers wiring models into their own tooling is not theoretical either; the CLOSEDQUORUM implant Cisco Talos found asks up to four commercial LLMs what to do next.
Attackers move fast. Defenders patch slowly. Agents can link steps that used to take more manual effort, and broad local privilege raises the price of getting any single boundary wrong.
🛠️ What builders and Mac users can do now
Apple has announced intent, and the finished control is still missing. Until a technical design and a ship date exist, the practical move is to drop assumptions.
For Mac users: check which apps hold Full Disk Access and remove grants that no longer have a clear purpose. Treat a product-level connector and the macOS permission as one combined capability, even when they live on different screens. If an agent can do the job in a VM or without desktop access, stay in the narrower mode until a task genuinely needs more.
For builders: an operating-system grant is no proof that a person understood every downstream data source. Ask again at the moment a sensitive connector becomes relevant. Make revocation obvious. Keep records that let people see which source an agent touched and why. Broad privilege should never become ambient authority that every new feature quietly inherits.
Design for steering attacks too. Wardle’s finding is a warning against treating the agent as a passive reader. Separate untrusted content from instructions, constrain command paths and assume another local process will try to influence the assistant. A polished consent screen cannot rescue an agent that accepts hostile control after the click.
Apple’s hardest call will be granularity. More prompts breed fatigue; fewer prompts keep the old blank cheque. The company hasn’t said where it will land. A useful design has to convey the combined consequence of disk access, connectors and autonomy without asking people to become macOS security engineers.
OpenAI ran into a lab-scale version of this when it cancelled the GPT-6.1 Astra release over scope and authorization failures, which I wrote up in the safety-case piece. Same question: what is this agent allowed to touch, and can anyone check? On a Mac the answer is painfully concrete. Private threads, browser state, mail archives and the data of people who never agreed to use an AI product at all.
Full Disk Access solved a real backup problem. AI agents changed what can happen after the door opens. Apple now says the lock needs work. The important details are still missing.
📚 Sources
- Apple Developer News, “Updates to Full Disk Access in macOS,” October 2, 2026: https://developer.apple.com/news/
- TechCrunch, “Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents,” October 2, 2026: https://techcrunch.com/2026/10/02/apple-says-its-tightening-macos-full-disk-access-controls-due-to-new-risks-from-ai-agents/
- Ars Technica, “Apple changes full-disk access permissions to curb abuse from AI agents”: https://arstechnica.com/security/2026/10/apple-changes-full-disk-access-permissions-to-curb-abuse-from-ai-agents/
- The Verge, “Apple will limit Mac disk access as AI agents ‘substantially’ increase risk”: https://www.theverge.com/tech/1004295/apple-limit-mac-disk-access-ai-agents
- Microsoft, 2026 Digital Defense Report, October 1, 2026: https://www.microsoft.com/en-us/security/security-insider/threat-landscape/2026-digital-defense-report
- Microsoft Security Blog, “Insights from the 2026 Microsoft Digital Defense Report,” October 1, 2026: https://www.microsoft.com/en-us/security/blog/2026/10/01/insights-from-the-2026-microsoft-digital-defense-report/
1 comment