Apple announced on October 2, 2026, that it plans to tighten macOS Full Disk Access controls, citing privacy risks from increasingly capable AI agents. The company says users who want to grant an app this broad permission will have to take “very explicit user action,” but it has not announced an implementation date. (developer.apple.com)
The commitment concerns consent, not a released security feature. Apple has not specified the new interface, which macOS versions will receive it, or whether the controls will apply uniformly to all apps seeking Full Disk Access. Users and enterprise administrators should therefore distinguish the announcement from protections already available on their Macs. (tbreak.com)
What Apple has confirmed
Apple warns that some developers are using Full Disk Access in ways that expose sensitive information without users fully understanding the consequences. The data at issue includes files, email, messages and browsing history. The company also points out that access to communications can affect the privacy of people corresponding with the person who granted permission. (developer.apple.com)
Its stated objective is to make the decision more deliberate and better informed as agents become more autonomous. The announcement does not establish that every AI agent bypasses permissions, nor does it identify a particular app as the target of the changes. Apple did not name Muse or confirm the disputed message-access incident involving that agent. (developer.apple.com)
Existing settings are not the promised changes
Mac users can already review and change app permissions under System Settings > Privacy & Security > Full Disk Access. Apple's current user guide describes the permission as allowing access to files across the computer, including information associated with Mail, Messages and Safari. That existing permission panel should not be presented as the newly announced protection. (support.apple.com)
The distinction matters when evaluating an agent's settings. A macOS permission and a feature switch inside an application are separate controls. Turning off a particular integration does not, by itself, establish that the app's system-level permission has been revoked. Equally, permission to access local information is not evidence that an app uploaded or shared it. (tbreak.com)
For workplace deployments, these distinctions separate three questions: what data the operating system permits an app to reach, what the app is configured to use, and what it actually does with that information. Treating those questions as interchangeable would obscure rather than resolve the consent issue highlighted by Apple's announcement. (support.apple.com)
The Muse account remains disputed
The announcement follows a public disagreement about Meta's Muse agent. Ars Technica reported that Inc. columnist Jason Aten said Muse sent an unsolicited notification referencing an Apple Messages conversation with a co-worker. Aten said he had not given the agent permission to read his messages. That is his reported account, not an independently established finding of unauthorized access. (arstechnica.com)
Meta disputed the allegation. The Verge reported spokesperson Andy Stone's position that Muse's Messages integration requires both macOS Full Disk Access and a separate Messages connector to be enabled. The competing accounts do not establish what permissions were active on Aten's device when the reported behavior occurred. (theverge.com)
Apple's broader warning does not adjudicate that dispute. Its announcement neither identifies the incident as the cause of its decision nor establishes that Muse circumvented macOS protections. The episode provides context for questions about user expectations, but it is not proof of a technical bypass. (developer.apple.com)
A wider platform-security question
Other platform developers are also addressing how much authority desktop agents should receive. In June 2026, Microsoft announced an early preview of its Microsoft Execution Containers SDK, designed to let developers define restrictions on agents and have Windows enforce those restrictions while the agents run. Microsoft framed containment as a way to enable useful work without giving agents the user's full authority. (blogs.windows.com)
Microsoft had also announced a public preview of administrative policies for agent workspaces and connectors in November 2025. Those policies included controls for enabling or disabling features and choosing security policies through enterprise management tools. This illustrates a related concern for organizations: agent access needs administrative oversight as well as an individual user's approval. (blogs.windows.com)
The approaches address related but different problems. Apple's announcement focuses on the decision to grant a broad permission; Microsoft's containment work focuses on restricting what an agent can do during execution. Neither announcement should be read as evidence that user consent alone resolves every agent-security risk. For Mac deployments, the immediate distinction remains straightforward: existing access can be reviewed now, while the additional consent controls remain planned. (developer.apple.com)




