
- Apple says it is tightening macOS Full Disk Access controls because of new risks from AI agents.
- Access today covers files, mail, messages, and browsing history for any app granted the setting.
- Apple promises that granting it will require “very explicit user action.”
- Triggers: a Meta Muse privacy dispute and a reported flaw in the ChatGPT Mac app.
Four categories of data: files, mail, messages, and browsing history. That is everything a single macOS setting called “Full Disk Access” can hand to an app. On October 2, 2026, Apple said it is tightening the controls around that setting because AI agents are about to make it far more dangerous than it was when it was built for backups.
The Setting That Was Built for Backups
According to TechCrunch’s Sarah Perez, Full Disk Access on macOS was originally designed to let backup tools do their job. The permission lets an application reach files, mail, messages, and browsing history across the system. For a backup utility, that breadth is the whole point. For an autonomous AI agent, it is something else entirely.
Apple put the problem bluntly. “Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems…without users’ full knowledge and understanding,” the company wrote. It added that it will require “very explicit user action” before such access is granted.
What Apple Is Warning About
The most striking line is about the future, not the present: “As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.” Apple is framing this as a structural issue. A permission that was tolerable when humans clicked through apps one at a time becomes risky when software acts on its own.
Trend Insight — Operating-system vendors are becoming the first real regulators of AI agents. Instead of waiting for model-level safeguards, Apple is moving the control point to the permission layer, where it can act no matter which agent is installed.
Two Incidents Behind the Move
TechCrunch links the announcement to two recent reports. The first came from Inc. columnist Jason Aten, who reported that Meta’s Muse AI agent accessed his private messages without explicit permission. Meta disputed the claim, so it should be read as an allegation rather than an established finding.
The second was a Wired report documenting a flaw in ChatGPT’s Mac app that could have allowed hackers to access sensitive data. The wording matters here: the flaw “could have” exposed data, which is a statement about exposure risk, not confirmed theft.
Why These Cases Matter Together
The two stories involve different companies and different failure modes, one a disputed privacy claim and one a reported security flaw. What they share is the same underlying permission. When one switch opens the whole disk, any bug or overreach in an agent inherits the full blast radius.
Trend Insight — Whether or not each individual claim holds up, Apple has decided the pattern is enough. Agent developers should expect tighter, more explicit permission prompts and plan their products around narrower access rather than a single all-powerful toggle.
What This Means for Teams Running AI Agents
Apple has not detailed the new controls beyond the “very explicit user action” requirement, so specifics should be confirmed in its documentation as they appear. Even so, the direction is clear enough to act on now.
A Practical Checklist
First, review which apps on your Macs currently hold Full Disk Access, including AI assistants and agent tools. Second, ask whether each one truly needs it or could work with narrower folder-level permissions. Third, treat any agent that asks for blanket disk access as a security decision, not a convenience click.
For companies shipping agents on macOS, the lesson is to design for least privilege. Products that request only what a task requires will adapt more easily if Apple’s prompts become stricter, while products that depend on broad access may face friction and user distrust.
Trend Insight — The agent era is turning old permission settings into front-line security boundaries. Teams that audit access now will be ahead of whatever Apple ships next.
Related
- OpenAI Just Came for Microsoft’s Office
- The AI Agent That Wouldn’t Take No for an Answer
- OpenAI’s Agents Secretly Built a Program Out of URLs
- Meta Just Made the Cloud Optional for AI Agents
- Claude Code Will Stop Asking Your Permission Soon
Sources
- TechCrunch — Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents (Oct 2, 2026)
- TechCrunch — Artificial Intelligence category (Oct 2, 2026)
AI Biz Insider · AI Trends EN · aibizinsider.com

댓글 남기기