Skip to main content
Back to News
news/AI Safety

Apple Curbs macOS Full Disk Access as AI Agent Risk Grows

Apple will require very explicit user action before Mac apps gain Full Disk Access, citing rising risks from autonomous AI agents reading private data.

Stefan Trbojevic

Stefan Trbojevic

3 October 20262 min read
LinkedIn
Abstract security gate with data pathways routing through layered permission planes

The takeaway

Desktop platforms are no longer willing to hand AI agents blanket system access. Scope permissions deliberately and audit what your agent can read before the OS forces you to.

Why it matters for builders

If you ship a desktop agent, full disk access is now a red flag: expect explicit re-consent flows and design for narrow, revocable connectors instead. Prompt injection plus broad file access stays the highest-severity risk in agent deployments, and platform owners are already willing to cut off agents that overreach.

Apple Curbs macOS Full Disk Access as AI Agent Risk Grows

Apple is adding new controls to the macOS Full Disk Access permission, saying desktop AI agents have turned a setting built for backup software into an unacceptable risk to user privacy.

What Apple announced

In a developer news post published on October 2, Apple said Full Disk Access "largely sidesteps" the protections that normally keep apps away from private data. "Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems, including files, mail, messages, and even browsing history," the company wrote, adding that for communication apps it can also compromise "the privacy of the people users are communicating with."

Going forward, Apple says users who genuinely wish to grant an app this "extraordinary level of access" will be able to do so "only with very explicit user action." No version number or ship date was given, and Apple declined to comment further to TechCrunch.

The timing is hard to miss. Days earlier, Inc. columnist Jason Aten reported that Meta's Muse agent on Mac knew the contents of his private messages even though he says he never granted that access. Meta CTO David Singleton pushed back, arguing Muse can read Messages only when a user enables both Full Disk Access and the app's own Messages connector. macOS security researcher Patrick Wardle disputed that reading, according to Ars Technica, noting that an app holding full disk access can read chats, cookies and browsing history regardless of connector toggles.

Layered permission rings with data pathways radiating to endpoint nodes

Why builders should care

  • Permissions are product surface now. If your agent needs full disk access, expect explicit re-consent and a clearer explanation of exactly what it reads. Onboarding copy and scoped connectors belong in the release, not in a follow-up sprint.
  • Broad access plus prompt injection is a live attack path. Wardle published a Muse configuration in which injected commands, including ClickFix-style lures, could take over the assistant and inherit everything it can reach.
  • Least privilege is the cheapest mitigation. Prefer narrow connectors and folder-scoped file access over one blanket permission, and log every tool call an agent makes.
  • Platform owners will enforce boundaries. Amazon has already blocked Muse from its platform, and Apple is tightening the OS-level gate. Agents that overreach can lose distribution overnight.
  • Expect the same conversation on Windows and Linux desktops. Agents designed with auditable, revocable permissions will not need a forced rewrite later.

The bottom line

Apple's post names neither Meta nor Muse. Even so, it is the first time a desktop platform owner has formally tied operating system permission design to the autonomy of AI agents. For teams shipping agents, the era of simply asking for full disk access is closing. The related wave of DIY agent hardware, such as the Muse gadget designs Meta released this week, only widens the surface that needs governing.

Share𝕏

The Automation Brief

Read 5 AI stories instead of 50.

The essential moves in AI agents, models, automation and infrastructure — filtered for builders and operators, with the part that actually matters.

No noise. Unsubscribe anytime.

Editorial notes

Reported by

Stefan Trbojevic

Edited by

n8n Lab Editorial

Published

3 October 2026

Updated

3 October 2026

AI disclosure: AI assisted with research and drafting. Factual claims are reviewed by an editor.

n8n Lab is an independent service provider. We are not affiliated with, endorsed by, or sponsored by n8n GmbH. “n8n” is a trademark of n8n GmbH and is used here only to describe the platform-specific implementation and automation services we provide.