Technology

Apple Tightens macOS Full Disk Access for AI Agents

Martin HollowayPublished 4h ago3 min readBased on 4 sources
Reading level
Apple Tightens macOS Full Disk Access for AI Agents
source:apple.com

Apple is introducing additional controls around the macOS Full Disk Access setting, citing new risks from AI agents. The plan was detailed in reporting published on Oct. 2, 2026. TechCrunch

Full Disk Access gives an app permission to access files, mail, messages and browsing history. Apple said the feature was designed to allow backups to function properly. That scope makes it one of the broadest grants available on macOS.

Under the current model, an app cannot grant itself that scope. Apple's developer documentation states that an app cannot automatically gain Full Disk Access through an entitlement or code and that the user must grant access in System Settings. Apple Developer Documentation

Apple said AI agents have increased the risks associated with that grant. The concern centers on agents that operate across the file system and act on a user's behalf, where a single permission can expose mail, messages, browsing history and documents together. Apple said the risks will grow substantially as AI agents become increasingly capable and autonomous.

Apple also said some developers are using Full Disk Access in ways that could put users at risk by exposing everything on their systems without users' full knowledge and understanding. The company did not frame this as a flaw in the consent mechanism alone. It framed it as a mismatch between user expectation and the breadth of data an agent can then read.

One example of the pattern is already in the market. Meta's Muse AI on Mac optionally allows users to enable Full Disk Access. The option is presented as user choice, which is consistent with the existing System Settings flow.

What changes is the bar for that choice. Apple said users who genuinely wish to grant an app Full Disk Access will be able to do so only with very explicit user action under the new controls. The company has not described the precise interaction. The intent is to preserve access for legitimate uses such as backups while adding friction against casual or poorly understood grants.

The move arrives alongside broader OS hardening. iOS 27 fixes 122 vulnerabilities and macOS 27 fixes over 200 vulnerabilities, with some of those fixes credited to AI systems such as Claude and Codex Security. ITnews

The broader context here is familiar to anyone who manages endpoint privilege. Least privilege works well when app boundaries are stable. Agents blur those boundaries by design, because their value comes from reading across silos and chaining actions. A file indexer needs broad read. A backup tool needs broad read. An agent that can read mail to find an invoice, then read files to file it, then act in the browser, needs all three at once.

In my view, Apple is choosing friction in the right place. Blocking broad access outright would break legitimate administration and backup workflows. Allowing it through a single toggle invites overprovisioning, especially when the prompt appears during onboarding for an assistant that promises to handle everything. A more explicit grant pushes developers toward narrower file access where possible and forces a clearer value exchange where broad access is truly needed.

Worth flagging for enterprise and power-user workflows is the operational cost. Explicit grants complicate fleet deployment and remote support. They also create an incentive to design agents that request Full Disk Access by default rather than degrade gracefully. The long arc is still positive. Better scoping, clearer consent and agents that can explain which stores they need and why would leave users with both more capable automation and tighter control over mail, messages and files.