Apple told developers on 2 October 2026 that macOS Full Disk Access will get additional controls. The permission already lets an app sidestep normal privacy prompts so backup tools can read protected data. Apple now says some developers are using it in ways users do not fully understand, and that autonomous AI agents make that risk much larger.
What happened
In a developer news post, Apple said Full Disk Access can expose files, mail, messages, and browsing history. For communication apps, that also exposes the other party in the conversation. Going forward, a user who genuinely wants an app to have this access will have to take a very explicit action. Apple did not publish a ship date.
The note landed after reports that an always-on assistant had read message contents without a clear grant. Apple's point is narrower than a ban on agents. The extraordinary permission was built for backup software. Agents that run with less human oversight should not inherit it quietly.
Who is affected
Any Mac fleet where staff or a managed package has already ticked Full Disk Access for an AI assistant, a browser agent, or a "productivity" tool that did not need the whole disk. Backup and endpoint agents that legitimately need it will face a stricter consent step. The change is announced, not yet a dated OS update.
What to do now
- On managed Macs, list Full Disk Access grants and remove every AI assistant or agent that does not have a written need.
- Prefer narrower TCC prompts over Full Disk Access for mail, files, and screen tools.
- Block unsigned or user-installed agents from receiving the permission through device management.
- Tell users that an agent asking for the whole disk is a stop-and-ask event, not a click-through.
Source: Apple Developer News, 2 October 2026. Apple's note.
Also on the blog
- Denmark CPR breach: 8.8 million identity records
- CVE-2026-88779 crashes SAML NetScaler, patch by 7 October
- Zammad CVE-2026-102489: KEV due date is today
- CVE-2026-61500: Rejetto HFS admin session forgery
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.