Apple tightens macOS Full Disk Access after AI agent risk
Explicit user action required before apps can read mail, messages, and files

Apple tightens macOS Full Disk Access after AI agent risk

Apple said it will add controls so macOS Full Disk Access can be granted only with very explicit user action. The company said some developers already use that permission in ways users do not fully understand, and that the risk grows substantially as AI agents become more capable and more autonomous. The Verge reported the statement on 2 October 2026. Apple has not given a ship date.

What happened

Full Disk Access lets an approved app read files, mail, messages, and browsing history. Apple says the permission largely sidesteps the privacy prompts users expect, because backup tools needed it. Desktop AI agents have started asking for the same grant.

The change follows a September report by Inc. journalist Jason Aten, who said Meta's Muse agent appeared to know the contents of his messages without permission he recognised. Meta denied that. Meta communications vice president Andy Stone said the journalist would have had to enable Full Disk Access and the Messages connector. The dispute is unresolved in public. The permission itself is the issue Apple is moving on.

Who is affected

  • Mac users who have already granted Full Disk Access to an AI assistant, agent, or connector
  • IT teams that deploy desktop AI tools on staff Macs without a permission review
  • Anyone waiting for Apple's control to land: it has not shipped, so current grants still stand

What to do now

Open System Settings, Privacy and Security, Full Disk Access, and remove every AI agent, connector, and unknown helper that does not have a written business reason. Do the same for Automation grants. Do not wait for Apple's update. A staff Mac with mail and messages exposed to an agent is a data-loss path that no email gateway will see.

Source: The Verge, Apple will limit Mac disk access as AI agents substantially increase risk.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

CVE-2026-86360: Dell System Update flaw scores 9.6, root on PowerEdge
Unauthenticated path traversal in Dell System Update before 2.3.0.0