The takeaway
Desktop platforms are no longer willing to hand AI agents blanket system access. Scope permissions deliberately and audit what your agent can read before the OS forces you to.
Why it matters for builders
If you ship a desktop agent, full disk access is now a red flag: expect explicit re-consent flows and design for narrow, revocable connectors instead. Prompt injection plus broad file access stays the highest-severity risk in agent deployments, and platform owners are already willing to cut off agents that overreach.
Apple Curbs macOS Full Disk Access as AI Agent Risk Grows
Apple is adding new controls to the macOS Full Disk Access permission, saying desktop AI agents have turned a setting built for backup software into an unacceptable risk to user privacy.
What Apple announced
In a developer news post published on October 2, Apple said Full Disk Access "largely sidesteps" the protections that normally keep apps away from private data. "Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems, including files, mail, messages, and even browsing history," the company wrote, adding that for communication apps it can also compromise "the privacy of the people users are communicating with."
Going forward, Apple says users who genuinely wish to grant an app this "extraordinary level of access" will be able to do so "only with very explicit user action." No version number or ship date was given, and Apple declined to comment further to TechCrunch.
The timing is hard to miss. Days earlier, Inc. columnist Jason Aten reported that Meta's Muse agent on Mac knew the contents of his private messages even though he says he never granted that access. Meta CTO David Singleton pushed back, arguing Muse can read Messages only when a user enables both Full Disk Access and the app's own Messages connector. macOS security researcher Patrick Wardle disputed that reading, according to Ars Technica, noting that an app holding full disk access can read chats, cookies and browsing history regardless of connector toggles.

Why builders should care
- Permissions are product surface now. If your agent needs full disk access, expect explicit re-consent and a clearer explanation of exactly what it reads. Onboarding copy and scoped connectors belong in the release, not in a follow-up sprint.
- Broad access plus prompt injection is a live attack path. Wardle published a Muse configuration in which injected commands, including ClickFix-style lures, could take over the assistant and inherit everything it can reach.
- Least privilege is the cheapest mitigation. Prefer narrow connectors and folder-scoped file access over one blanket permission, and log every tool call an agent makes.
- Platform owners will enforce boundaries. Amazon has already blocked Muse from its platform, and Apple is tightening the OS-level gate. Agents that overreach can lose distribution overnight.
- Expect the same conversation on Windows and Linux desktops. Agents designed with auditable, revocable permissions will not need a forced rewrite later.
The bottom line
Apple's post names neither Meta nor Muse. Even so, it is the first time a desktop platform owner has formally tied operating system permission design to the autonomy of AI agents. For teams shipping agents, the era of simply asking for full disk access is closing. The related wave of DIY agent hardware, such as the Muse gadget designs Meta released this week, only widens the surface that needs governing.
The Automation Brief
Read 5 AI stories instead of 50.
The essential moves in AI agents, models, automation and infrastructure — filtered for builders and operators, with the part that actually matters.
No noise. Unsubscribe anytime.
Editorial notes
Stefan Trbojevic
n8n Lab Editorial
3 October 2026
3 October 2026
Sources
AI disclosure: AI assisted with research and drafting. Factual claims are reviewed by an editor.



