Apple Tightens macOS Full Disk Access After AI Agents Raised Privacy Concerns
Two incidents involving desktop AI agents pushed Apple to change how one of macOS's most powerful permissions gets granted. On October 2, 2026, Apple said any app, including an AI agent, will need "very explicit user action" before it can obtain Full Disk Access, the setting that lets software read Messages, Mail, browsing history, and nearly everything else stored on a Mac, per Apple's developer blog.
What
Full Disk Access exists so backup software can work properly, and it largely bypasses macOS's normal per-app data controls, Apple wrote. The company said some developers now use that same permission to expose "everything on their systems, including files, mail, messages, and even browsing history, without users' full knowledge and understanding." Apple gave no ship date or interface mockup for the new controls, only the "very explicit user action" requirement, per the same post.
The change follows two reports from the prior week. Inc. columnist Jason Aten wrote that Meta's Muse app on Mac appeared to know the contents of his private Messages even though he says he never knowingly granted that access, a claim Meta disputed, per TechCrunch. Separately, Wired reported a flaw in the ChatGPT Mac app that could have let attackers pull sensitive data off a user's machine, per Wired. TechCrunch said Apple did not respond to a request for comment on the timing of its announcement.
Desktop AI agents lose their quiet path to broad file access
Any AI agent that wants Messages, Mail, or browsing-history access on a Mac, not only Muse or ChatGPT, will clear a harder permission gate once Apple ships the change. Apple tied the shift directly to agent autonomy, writing that "as AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially," per Apple. That shifts work onto vendors like Meta and OpenAI, whose Mac apps currently request Full Disk Access through a single system dialog, and gives Mac users a clearer moment to decline before an agent can read their full message history. Until the stricter flow ships, that single-dialog grant stays in effect, so anyone who already approved Full Disk Access for an agent is still exposed under the old system.
What to do while you wait
Apple has not published a beta build, timeline, or mockup of the new consent flow, so the current single-dialog grant remains the only gate for now. Mac users can check it today: open System Settings, then Privacy & Security, then Full Disk Access, and revoke the permission from Muse, ChatGPT for Mac, or any other agent not knowingly approved for that level of access. From there, the signal to watch is whether the stricter permission shows up in an upcoming macOS beta, and whether Meta or OpenAI change how their Mac apps request Full Disk Access in response.
Sources
- Updates to Full Disk Access in macOS: Apple Developer News, October 2, 2026
- Apple says it's tightening macOS 'Full Disk Access' controls due to new risks from AI agents: TechCrunch, October 2, 2026
- A Flaw in ChatGPT's Mac App Could Have Let Hackers Grab Sensitive Data: Wired
