Agents

Apple to Strengthen Controls on macOS Full Disk Access Permissions

October 5, 2026 · 2 min read

Hands typing on a laptop computer screen
Bluestonex / Unsplash

Apple announced on October 2 that it plans to enhance controls regarding the "Full Disk Access" permissions in macOS, allowing users to manage this access when granting it to applications. The company has not disclosed specific implementation details or timelines for these changes.

According to Apple, while it provides developers with robust APIs, it is also establishing a series of controls to protect users' private data. Full Disk Access is a permission that allows backup applications to bypass most of these controls to function correctly on Mac devices.

Apple pointed out that some developers have been using this permission in ways that could endanger users, exposing files, emails, messages, and browsing history without sufficient user awareness. In the case of communication applications, the privacy of the individuals with whom users interact could also be compromised.

In the future, only users who genuinely wish to grant this "extraordinary level of access" will be able to do so through explicit actions, as additional controls will be introduced.

Apple stated, "As the capabilities and autonomy of AI agents increase, the risks associated with this level of access grow significantly," indicating that it plans to create a system that ensures users are fully informed of the risks before granting permissions regarding their data and privacy.

While Apple did not mention specific companies or applications in its announcement, there was a recent discussion surrounding the Mac version of Meta's AI agent "Muse" in September, focusing on its handling of Full Disk Access and message data.

On September 19, a columnist raised concerns on Threads, stating that Muse was monitoring Mac notifications, including messages, and using that very personal information in conversations without disclosure. Muse's response included an apology for proceeding without permission.

In response, David Singleton, an executive at Meta's "Meta Superintelligence Labs," refuted the claims on the same day, explaining that the message integration for the Mac version of Muse operates on an opt-in basis. He clarified that Muse can read message content only if Full Disk Access is permitted at the macOS system level, and the message connector is enabled on the Muse side, which requires three levels of permissions including app-level consent and built-in macOS protections, thus preventing possible bugs in the Muse application from being exploited.