Apple said it will add controls so macOS Full Disk Access can be granted only with very explicit user action. The company said some developers already use that permission in ways users do not fully understand, and that the risk grows substantially as AI agents become more capable and more autonomous. The Verge reported the statement on 2 October 2026. Apple has not given a ship date.
What happened
Full Disk Access lets an approved app read files, mail, messages, and browsing history. Apple says the permission largely sidesteps the privacy prompts users expect, because backup tools needed it. Desktop AI agents have started asking for the same grant.
The change follows a September report by Inc. journalist Jason Aten, who said Meta's Muse agent appeared to know the contents of his messages without permission he recognised. Meta denied that. Meta communications vice president Andy Stone said the journalist would have had to enable Full Disk Access and the Messages connector. The dispute is unresolved in public. The permission itself is the issue Apple is moving on.
Who is affected
- Mac users who have already granted Full Disk Access to an AI assistant, agent, or connector
- IT teams that deploy desktop AI tools on staff Macs without a permission review
- Anyone waiting for Apple's control to land: it has not shipped, so current grants still stand
What to do now
Open System Settings, Privacy and Security, Full Disk Access, and remove every AI agent, connector, and unknown helper that does not have a written business reason. Do the same for Automation grants. Do not wait for Apple's update. A staff Mac with mail and messages exposed to an agent is a data-loss path that no email gateway will see.
Source: The Verge, Apple will limit Mac disk access as AI agents substantially increase risk.
Also on the blog
- CVE-2026-88779 crashes SAML NetScaler, patch by 7 October
- CVE-2026-104286: FortiMail path traversal, no patch yet
- Denmark CPR breach: 8.8 million identity records
- CVE-2026-86360: Dell System Update flaw scores 9.6, root on PowerEdge
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.