Apple to Tighten Full Disk Access in macOS Over AI Agent Risks

Apple plans additional checks in macOS when granting Full Disk Access. The company says the growing autonomy of AI agents significantly increases the risks associated with this broad access to data.

Apple Full Disk Access will be subject to additional checks in macOS. Apple announced this on October 2, 2026, saying that the broad permission can largely bypass standard privacy protections. The company wants granting it to require a very explicit user action going forward.

This is not an announcement of a confirmed vulnerability exploit or the release of a security patch. Apple is describing a planned change to how the system handles granting one of the broadest permissions available to applications in macOS.

Apple Full Disk Access and the Scope of Access

Full Disk Access can give an application access to files, emails, messages, and browsing history. According to Apple, it largely bypasses standard privacy protections that would otherwise limit an application’s access to protected data across the system.

Various types of desktop software may request this access, including backup tools and security products. In the context of its announcement, however, Apple specifically points to AI agents—applications with growing capabilities and autonomy. According to the company, these characteristics substantially increase the risk associated with Full Disk Access.

A More Explicit User Action

Apple says that after the planned change, granting such broad access will require a very explicit user action. The company has not yet disclosed the exact mechanism for the new checks or the form of the dialog or process through which users will confirm the permission.

Therefore, the announcement does not make it possible to determine whether this will involve a new system step, an additional warning, or another approval model. Apple also did not specify the supported macOS versions or the deployment date.

What Is Not Yet Known

  • It has not been confirmed how the change will affect applications that have already been granted Full Disk Access.
  • Apple did not specify the impact on legitimate backup and endpoint-security tools.
  • The company did not name a specific AI application or incident as the direct reason for the planned measure.
  • It is not known whether Apple will issue separate security guidance or documentation for AI agent developers.

These details should be tracked in further Apple documentation.

Sources

Verified and updated: 10/03/2026 06:24

Sharing