Apple is tightening macOS Full Disk Access, citing AI agent risks
In a developer notice dated October 2, 2026, Apple said it will place additional controls around the Full Disk Access permission on macOS. People who want to hand an app that level of access will have to do it through a clearly deliberate step. One reason Apple gives: AI agents keep getting more capable and more autonomous.
A permission built for backups gets a second look in the agent era
Apple posted a news item on its developer site on October 2, 2026, titled "Updates to Full Disk Access in macOS". It starts by explaining the purpose of the setting. Backup apps on the Mac need broad reach to work properly, so Full Disk Access switches off most of the safeguards Apple has built to protect private user data. In practice, granting it to an app opens up the bulk of the system's other privacy layers for that app.
The problem, in Apple's telling, is that some developers lean on this permission in ways that expose users. Files, email, messages and even browsing history can end up exposed without the person fully knowing or understanding what is going on. With communication apps the damage can spread further, Apple adds, because the privacy of everyone a user talks to may also be compromised.
An explicit-action requirement is coming, with no date attached
What Apple describes is a threshold rather than a ban. TechCrunch later added a correction to its own report, withdrawing its description of the change as limiting permissions and saying the change reflects informed consent rather than a new limit. People who really want to hand an app such sweeping access will still be able to, but Apple says they "can only do so with very explicit user action". The company also warns that the risks tied to such access will rise sharply as AI agents grow more capable and autonomous. The notice names no macOS version and no date for the change, does not describe what the new confirmation step will look like, and does not say whether permissions granted earlier will be asked for again.
TechCrunch, covering the notice the same day, points to its timing. The outlet reports that Apple's move came days after Inc. columnist Jason Aten said Meta's Muse app for Mac was aware of what his private messages said, an account Meta disputed. TechCrunch notes that Muse gives users the option to turn on Full Disk Access, and it recalls Wired reporting that a bug in the ChatGPT app for Mac might have opened sensitive data to hackers. Apple's own notice does not name any app or developer, and TechCrunch says Apple did not answer its questions about the change. We covered the launch of Muse as a personal agent on September 9.
Desktop agents need wide reach, and Apple is putting a gate in front of it
An AI agent that reads files, checks messages and drives apps on a computer becomes more useful the more data it can see. Apple's notice highlights the other side of that trade: the same broad reach becomes a larger attack surface the more independently the agent operates. As the platform owner, Apple is choosing not to remove the access but to require that users grant it knowingly, through a consent gate.
For businesses that use or build agent tools on the Mac, that raises two practical questions. First, which apps hold Full Disk Access today, and does each one actually need it? Second, the permission flow will change once the new controls ship. With no timeline announced, preparing now is cheaper than discovering a broken workflow later.
The sources say nothing about Türkiye, so this section is UNALSOFT commentary
Neither Apple's notice nor the TechCrunch report contains any information about Türkiye. Nothing in the sources addresses whether the change will roll out differently by country, when it would reach Mac users in Türkiye, or how any local institution views it. What follows is therefore not drawn from the sources but is explicitly UNALSOFT commentary.
Our reading: for a business in Türkiye running desktop AI tools on a Mac, the risk Apple describes comes from the same permission setting as anywhere else, and as TechCrunch reports for Muse, an agent app may offer that permission to users as an optional switch. To list the unknowns one by one: the sources do not give the macOS version that will carry the new controls, when they take effect, what the explicit user action will look like in practice, whether permissions already granted will be revoked or re-prompted, or whether anything will differ for Türkiye. Given that uncertainty, the sensible move is to take an inventory of permissions now.
The UNALSOFT view
We read this less as a product update and more as a question of permission discipline in agent design. An agent that can do its job with narrow, clearly defined permissions is less exposed when platform rules tighten, and it is easier to explain to users what it can see. That is why in agentic AI projects we treat writing down which data an agent needs, and why, as its own step, and we avoid making broader access than necessary the default. Since Apple has not published a timeline, this article makes no recommendation tied to a specific date or version.
Do you know which data your agents can reach, and why?
A short conversation is enough to review the permissions of the AI agents you use today or plan to deploy.