Apple will make Full Disk Access on the Mac harder to grant, and it says AI agents are the reason. In a notice on its developer site dated October 2, 2026, Apple writes: “As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.” Users who want to grant the permission will be able to do so only “with very explicit user action.”
MacRumors carried the notice at 19:59 UTC the same day; its post on X passed 460,000 views by our read.
On this page · 7 sectionsOpen
- On October 2, 2026, Apple said on its developer news site that it will add controls to macOS Full Disk Access so that granting it takes very explicit user action.
- Apple’s reason is AI agents: as they get more capable and autonomous, it says, the risk of that level of access will grow substantially.
- Apple says some developers already use Full Disk Access in ways that expose files, mail, messages and browsing history without users’ full understanding.
- The notice names no app or company, gives no date and does not describe the new controls.
- It lands days after the Hunterbrook investigation into Meta’s Muse and OpenAI’s launch of dots, both always-on agents that run on cloud computers rather than inside your Mac.
- For anyone running an agent on their own machine, the practical rule is unchanged: grant the narrowest access the job needs.
§ 01What Apple said
| Point | Apple’s words |
|---|---|
| What the permission does | “Full Disk Access largely sidesteps these controls in order to allow backup apps to function properly on the Mac.” |
| The problem today | Some developers use it in ways “exposing everything on their systems”, including files, mail, messages and browsing history |
| Who else is exposed | “For communication apps, this can also compromise the privacy of the people users are communicating with.” |
| The change | Additional controls so granting it takes “very explicit user action” |
| The reason | “As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.” |
§ 02What Apple did not say
- When. No date and no macOS version.
- How. No description of the new controls or the grant flow.
- Who. No app, developer or company is named. A widely shared post said the change followed accusations about Meta’s Muse reading private messages; Apple’s notice does not mention Muse or any agent by name.
- Existing grants. Nothing on whether apps that already hold the permission keep it.
§ 03Where today’s agents run
Apple’s change touches apps on your Mac. Most of the always-on agents launched in the last six weeks do their work somewhere else.
| Agent | Where it works | Your own computer |
|---|---|---|
| Meta Muse | A dedicated cloud VM with its own browser | Connected apps and accounts, per Meta |
| OpenAI dots | Its own cloud computer and browser | Separate unless you connect it, per OpenAI |
| Perplexity Portable Computer | Entirely on a local machine (DGX Spark at launch) | It is your computer |
| CellCog AI employee | Its own secure VM and file system, plus its own browser identity and logins | Optional, through Cowork, with every command classified and shown to you |
The Hunterbrook investigation on September 28 was about what Muse found in Meta’s own data, not about Mac disks. The agents most exposed by Apple’s change are the ones that run locally with broad permission, the setup least privilege argues against.
§ 04What it means if you run an agent on your Mac
Check which apps hold Full Disk Access today in System Settings, under Privacy and Security. Give an agent a project folder or a specific account instead of the whole disk where the job allows it, and expect a stricter prompt once Apple ships the controls.
§ 05What would move this story
- A macOS beta or release note describing the new controls.
- Developer documentation for the new grant flow.
- Agent makers saying how their Mac apps will adapt.
§ 06The record
As of October 4, 2026, 01:11 UTC: page opened. Apple’s notice was read on developer.apple.com; X post times were computed from post IDs and view counts read through the X API.
§ 07Sources
- Apple Developer, Updates to Full Disk Access in macOS, October 2, 2026.
- MacRumors, Apple Announces ‘Full Disk Access’ Changes on macOS Due to AI Agents, October 2, 2026.
- OpenAI, Introducing dots, September 29, 2026.
- Our records on Muse, OpenAI dots, Perplexity Portable Computer and the Hunterbrook investigation.
Q1What is Full Disk Access on macOS?
A privacy permission that lets an app read data the Mac’s normal privacy controls protect. Apple says it exists so backup apps can work, and that it largely sidesteps those controls.
Q2Did Apple name Meta's Muse or any other agent?
No. Apple’s notice names no company. Coverage and posts tied it to always-on agents like Muse and OpenAI’s dots, but that link is commentary, not Apple’s text.
Q3Will my existing apps lose Full Disk Access?
Apple has not said how the new controls treat apps that already hold the permission. Watch the next macOS release notes.
Q4Should I give an AI agent Full Disk Access?
Only if the task truly needs the whole disk. Most agent work needs a project folder or a few connected accounts, and narrower grants are easier to review and revoke.
Q5How does CellCog handle this?
Each CellCog AI employee works on its own secure virtual machine with its own file system, browser identity and logins. Reaching your own computer is a separate opt-in, and every command it runs there is classified and shown to you.
