Apple on October 2, 2026 said it will add controls around Full Disk Access, the macOS permission that lets an app sidestep the system's usual privacy safeguards, so that a person can grant it only through "very explicit user action". The notice, published on Apple's developer news site, names no release date, no macOS version and no developer.

In Short

Apple said on October 2, 2026 that it will add new controls so a Mac app can get Full Disk Access, the permission that lets it read nearly everything stored on a computer, only when the owner takes a very deliberate step. The change matters to anyone who installs backup tools, messaging apps or AI agents, because those apps can see files, mail, messages and browsing history once the permission is switched on. Apple gave no date and no macOS version, so the way the permission is granted today has not changed yet.

What Apple wrote

The notice is short: two paragraphs, fewer than 200 words, filed under the title "Updates to Full Disk Access in macOS" and dated October 2, 2026. Apple begins with its standard arrangement. Developers receive powerful programming interfaces, and those interfaces are backed by controls designed to protect users' private data. Full Disk Access, it says, "largely sidesteps these controls" so that backup apps can work properly on the Mac.

Trouble starts with how some developers use the exception. According to Apple, certain apps employ the permission in ways that could put people at risk, exposing files, mail, messages and browsing history "without users' full knowledge and understanding". For communication apps, the company adds, the damage can reach beyond the account holder to the people on the other end of a conversation.

The fix is described in a single sentence. Apple will add controls so that people who "genuinely wish to grant an app this extraordinary level of access" can do so only with "very explicit user action". A second thread then runs through the closing lines: "Addressing this is critical." The reason Apple gives is that, as AI agents become more capable and autonomous, the risks of this level of access "will grow substantially". The company says it is committed to making sure people understand those risks before granting access, so that they can make informed decisions about their own data and privacy.

What the notice leaves open

Absences stand out. According to MacRumors, Apple did not say when the controls will be implemented, and the text names no macOS release either. It describes no mechanism, so whether the step will take the form of a confirmation dialog, a changed settings flow or something else is not stated. No developer or app is named. Nor does the notice say whether the extra step will apply to grants made centrally by IT administrators, or how Apple's own assistant features fit in.

MacStories, in its post on the notice, read the wording in two ways. One reading is that people will have to clear additional hurdles to give agents and other apps the permission. The other starts from the notice's framing of the permission around backup apps, which, according to MacStories, could signal an intent to limit the kinds of apps that may use it. The text itself does not settle the matter.

How the permission works at present

According to Unite.AI's summary of Apple's Mac User Guide, Full Disk Access lets an app reach all files on a computer, including data from Mail, Messages, Safari and Home, Time Machine backups and certain administrative settings for every user on the Mac. In practice the grant is a single switch. A June 2024 guide from Northwestern University IT for the CrashPlan backup client walks through it: open System Settings, choose Privacy & Security, select Full Disk Access, turn on the switch beside the app, enter the Mac's password if asked, then quit and reopen the app.

Organisations that run mobile device management software can skip the switch. According to threads on the Jamf community forum, administrators have granted the permission to security products from vendors including Sophos and CrowdStrike through configuration profiles. In the November 2019 Sophos thread, the profile entry for the permission is SystemPolicyAllFiles, set to allow. A thread from October 2022 notes that the System Settings pane does not show grants made that way. Whether Apple's new step will reach such deployments is not addressed in the notice.

The agent episode behind the timing

Apple's notice names no company. The timing nonetheless drew comparison with recent agent releases. According to MacRumors, the notice arrives amid the rise of always-on AI agents such as Meta's Muse and OpenAI's Dots, which have prompted privacy concerns. Muse reached users in the United States on September 8, 2026, on iOS, Android and muse.ai.

The Muse dispute

On September 28, AppleInsider reported an account from Jason Aten, a columnist at Inc., who installed Muse on an iPhone and a Mac mini. Aten says he declined to give the app access to his messages and left Full Disk Access switched off, yet found that Muse had synced about 187,000 lines of his local Messages database. When he asked how it knew about a conversation, Muse said the Mac app only relayed incoming notifications, according to Tom's Hardware.

Meta disputes the account. According to Decrypt, its communications chief, Andy Stone, said the Messages integration in the Muse Mac app is opt-in and works only if both Full Disk Access and a Messages connector inside the app are enabled. The sources reviewed do not reconcile the two versions, and Apple's notice does not mention the episode.

Breadth of access, and the regulators

Apple's own account of the permission explains the tension. A switch designed so that backup software can read an entire disk now sits in front of software that chooses its own steps. A backup tool copies everything by design; an agent may need a folder, a mailbox or a single file, yet the switch, as documented, offers no such gradation.

Regulators have been working on the same problem from the legal side. Spain's data protection authority published a 71-page guide on agentic AI under the GDPR that warns uncontrolled access to repositories such as email accounts and customer databases risks breaching data minimisation, and that recommends explicit access policies for every repository an agent can reach. The Council of Europe's draft guidelines for chatbots and agents call for permission to read data to be kept separate from permission to create, modify, transmit or delete it. The Dutch data protection authority warned on February 12, 2026 that open-source agents such as OpenClaw carry risks of data breaches and account takeovers.

Breadth also sets the reach of a hostile instruction. In prompt injection, text that an agent was meant to read as data is obeyed as a command, and UK regulators have warned that agents granted broad permissions widen the attack surface. A confirmation step changes how a permission is granted; by itself it does not change how much the permission covers. Whether Apple's controls will narrow scope or only add friction is the question the notice leaves unanswered.

Apple's own agents, and its earlier developer notices

Apple is not a bystander to agentic software. At WWDC on June 8, 2026, it presented a Passwords app capability that uses Apple Intelligence and Safari to navigate websites, sign in and change credentials on a person's behalf, and its Siri AI shipped alongside macOS 27, which reached users on September 14, 2026. The Full Disk Access notice is silent on how first-party features figure in the new controls.

Apple's developer notices have carried firmer detail on other privacy changes. A notice dated September 16, 2026 on App Tracking Transparency in the European Union named a software version, iOS 27.2, and five countries - Germany, France, Italy, Poland and Romania - where only an alternative version of the system prompt will be available. In 2024, Apple set May 1 as the date from which new or updated apps with listed third-party SDKs needed privacy manifests, with non-compliant apps refused by the App Store. The Full Disk Access notice carries no comparable anchor.

Why marketing teams are watching

Desktop agents are arriving in tools that marketers already use. Google's Gemini Spark reached macOS in beta on June 30, 2026, for US subscribers aged 18 and over to the $99.99 Ultra tier, with Mac file sorting among its functions. On July 30, Google gave Spark the ability to browse Chrome using a person's saved logins and passwords. Whether any of these products depends on Full Disk Access is not stated in the sources reviewed.

Mail and messages feature on Apple's list of exposed data. On agency and in-house marketing Macs, those folders typically hold correspondence with clients and partners, the third parties whose privacy the notice says communication apps can compromise.

The notice does not mention advertising, measurement or marketing software, and the sources reviewed identify no effect on ad tech tools. What it does show is a platform owner revising a long-standing permission because of agent software, with the mechanics yet to be published. Until Apple publishes the controls, the practical effect on products already shipping to Macs remains unknown. How much of a Mac does a single switch expose, and to which software? The notice poses the question without answering it.

Timeline

Summary

Who: Apple, through its Apple Developer News site. The change concerns Mac app developers, people who install apps on a Mac, and organisations that manage Macs centrally. Apple names no company.

What: A notice titled "Updates to Full Disk Access in macOS". It commits Apple to additional controls so that granting Full Disk Access requires very explicit user action. It names AI agents as a growing risk and gives no description of the mechanism.

When: Published October 2, 2026. No implementation date or macOS version is given.

Where: On macOS, via Apple's developer website. The notice states no geographic limit.

Why: According to Apple, Full Disk Access largely sidesteps the controls that protect private data so that backup apps can work, some developers use it in ways that expose files, mail, messages and browsing history without users' full knowledge, and the risks will grow as AI agents become more capable and autonomous.