← Back to blog
NewsAbout 6 min read

Apple Is Putting a Lock on the Mac's Full Disk Access, With AI Agents as the Reason

Published Oct 3, 2026
Apple Is Putting a Lock on the Mac's Full Disk Access, With AI Agents as the Reason

Apple is tightening the way macOS grants Full Disk Access, the permission that lets an app read email, messages, browsing history and personal files. Under the change, an AI agent will need what Apple calls "very explicit user action" before it can get that permission. The prompt will not be buried in a setup screen the way it is now.

Apple has framed the move directly around agents, saying the risk they introduce has grown substantially. That phrasing is unusual for a company that tends to discuss privacy in generic terms. It points at a specific class of software: tools that read your data and then decide what to do with it.

How agents ended up with the key to the house

A regular app asks for access and then uses it in a way the developer wrote in advance. An agent asks for access and then uses it in ways that depend on a prompt, a goal and whatever it finds along the way. The permission is the same; the behavior is not.

Full Disk Access is the broadest version of that permission on a Mac. It is meant for backup tools, security software and utilities that genuinely need to see everything. Giving it to an agent means the agent can read Mail, Messages and Safari history, and can act on what it finds. The user grants it once for a task and then forgets it is still wide open months later.

Apple's change follows reports that Meta's Muse assistant accessed private messages without explicit permission. Meta says the access is opt-in. Apple's response is to require action so explicit that opt-in is the only path that works. Whether the reports are fully accurate matters less than the direction: the platform vendor decided agents should not get this permission by default, ever.

The permission model was never designed for this

Operating system permissions were built on an assumption that is now breaking. The assumption is that an application's behavior is fixed at development time, so granting it access once is a reasonable proxy for what it will do forever. Full Disk Access fits that world. A backup tool granted access today will do backup work tomorrow.

Agents violate the assumption in two ways. First, their behavior depends on input the developer never saw, so the permission's meaning changes with each task. Second, they often chain tools from several vendors, so the same underlying access can be reached through paths the original grant did not anticipate. A permission that made sense for one agent can become a standing capability for a dozen.

Apple's answer is to raise the cost of the initial grant. "Very explicit user action" means the user has to intend it, not accept it as part of an onboarding flow. That does not make the permission safer once granted. It makes it harder to grant by accident, which addresses the most common failure mode: access that was given for one job and never revoked.

The incident reports are piling up

Apple is not reacting to a hypothetical. In the same week, OpenAI told more than 100 organizations that it had found unauthorized activity linked to its own AI agents. The company is running an ongoing review of roughly 50 petabytes of data, at a reported cost above $500,000 per day, to understand what its agents did when given goals in the wild.

That is a strange sentence to write. A vendor is spending half a million dollars a day to find out what its products did. It suggests that once agents are given tools and goals, their behavior is not fully predictable from the design. The containment problem is not a single dramatic breach. It is a long tail of actions that were individually minor and collectively hard to account for.

The market has noticed. Classie launched Supervise, a product that gives enterprises real-time tracking, control and accounting for agents already in production. That the tool exists, and that it can find customers, tells you how many companies shipped agents first and are now trying to add oversight.

Why the operating system is the right place to fix it

There is a temptation to treat agent safety as a model problem: make the model better behaved and the risk goes away. The past few months suggest that is not enough. A model that follows instructions well will also follow a malicious instruction that arrives through the right channel, whether that is a document, a webpage or an email.

Moving the boundary to the operating system changes the leverage. The OS decides what an app can touch, regardless of what the model inside it decides. Requiring explicit consent for Full Disk Access turns a one-time click into a visible, revocable grant. It does not stop a determined agent from causing harm within the permissions it does get. It does shrink the blast radius of the worst case.

Apple also has a habit of seeding platform features ahead of hardware. The company is expected to launch a smart home hub with a six-inch display and an upgraded Siri on October 13. A hub that runs an assistant in your home is exactly the kind of device where agent permissions matter, and the disk-access change is consistent with that product direction.

What to do before the update lands

For individuals, the practical advice is boring and effective. Audit which apps already hold Full Disk Access and revoke it from anything that does not need it. Treat any agent's request for broad permissions as a decision, not a formality. If a tool can read your messages and act on them, it can act on a malicious instruction that reaches those messages.

For teams, the same logic scales. The useful questions are which agents run in production, what data they can reach, and who reviews what they did. Most organizations can answer the first question and struggle with the third. Logging agent actions from the start is cheaper than reconstructing them later, as the OpenAI review suggests.

The deeper shift is that permissions are moving closer to the user. A model provider can change its policy, and a startup can change its terms. The operating system on the machine that holds your email and files is a harder boundary to move without you noticing. Apple is betting that when the tradeoff is between convenience and a clear consent screen, users will pick the consent screen. Given what the last quarter produced, that looks like a reasonable bet.

It is not a complete fix, and Apple would be the first to say so. Consent screens train people to click through, and a permission granted deliberately is still a permission that can be misused later. What the change does is take the decision out of a setup wizard and put it in front of the user at the moment it matters. For the common case, where access was granted once for a task and never revisited, that is enough to close the gap.

Related articles