# Apple plans additional controls for macOS Full Disk Access because of AI agents > Apple said on 2 October 2026 that it will require very explicit user action to grant Full Disk Access on macOS, citing the growing autonomy of AI agents. FireAI Security & Research Team (HisnLabs) · Published 2026-10-03 Canonical: https://hisnlabs.com/en/news/apple-macos-full-disk-access-ai-agents-explicit-user-action Apple announced on 2 October 2026, in a post for developers, that it will introduce additional controls around the macOS Full Disk Access permission so that an app can receive it only through very explicit user action [[1]](https://developer.apple.com/news/?id=p6zjojqw). The post cites the growing capability and autonomy of AI agents as a reason [[1]](https://developer.apple.com/news/?id=p6zjojqw). The announcement is relevant to Mac users because Full Disk Access is the broadest file permission a user can give an app. ## Background Apple states that macOS gives developers application programming interfaces backed by controls designed to protect users' private data, and that Full Disk Access largely sidesteps these controls so that backup apps can function properly [[1]](https://developer.apple.com/news/?id=p6zjojqw). AI agents are programs that act for a user, and some run commands and read files on the Mac they are installed on. The Apple post gives no technical specification of the planned controls and no release date [[1]](https://developer.apple.com/news/?id=p6zjojqw), and MacRumors likewise reports that Apple did not specify when the controls will be implemented [[3]](https://www.macrumors.com/2026/10/02/apple-announces-macos-full-disk-access-changes/). ## What the announcement states Apple writes that some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems, including files, mail, messages and even browsing history, without the users' full knowledge and understanding [[1]](https://developer.apple.com/news/?id=p6zjojqw). For communication apps, Apple adds, this can also compromise the privacy of the people the user is communicating with [[1]](https://developer.apple.com/news/?id=p6zjojqw). Apple states that, going forward, it will introduce additional controls so that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action [[1]](https://developer.apple.com/news/?id=p6zjojqw). It continues that, as AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially, and that it is committed to ensuring users understand these risks before granting such access [[1]](https://developer.apple.com/news/?id=p6zjojqw). TechCrunch reported the announcement on the same day and linked it to two recent reports. The first is an account by Inc. columnist Jason Aten that Meta's Muse AI agent accessed his private messages without explicit permission, which Meta disputed. The second is a Wired report on a flaw in the ChatGPT Mac app that could have let hackers reach sensitive data [[2]](https://techcrunch.com/2026/10/02/apple-says-its-tightening-macos-full-disk-access-controls-due-to-new-risks-from-ai-agents/). The Apple post itself names no app and no company [[1]](https://developer.apple.com/news/?id=p6zjojqw), and TechCrunch states that Apple did not respond to its request for comment [[2]](https://techcrunch.com/2026/10/02/apple-says-its-tightening-macos-full-disk-access-controls-due-to-new-risks-from-ai-agents/). MacRumors places the announcement in the context of privacy concerns about always-on AI agents such as Meta's Muse and OpenAI's Dots [[3]](https://www.macrumors.com/2026/10/02/apple-announces-macos-full-disk-access-changes/). > FireAI, the on-device firewall for macOS developed by HisnLabs, watches the network side of what an app does on a Mac and lists every app that went online, newest first. A 17-day trial is available. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## Implications for Mac users The change concerns the moment of granting access. Apple's wording indicates that the permission will remain available to users who want it, for example for backup apps, but that granting it will take more deliberate action than it does today [[1]](https://developer.apple.com/news/?id=p6zjojqw). The post does not say whether apps that already hold Full Disk Access will be asked again, so that point is open. The permission determines what an app can read on the disk, not where the app can send it. An app with broad file access and an open network connection can in principle pass what it reads to a remote server, and the sources do not describe a case of that happening. ## Recommendations 1. Open System Settings, then Privacy and Security, then Full Disk Access, and review which apps are listed there. 2. Switch off Full Disk Access for any app that is not a backup tool or another app that needs to read the whole disk, and for any AI assistant or agent whose need for it is unclear. 3. Read the access prompt of a new app before approving it; Apple states that users should understand the risks before granting this access [[1]](https://developer.apple.com/news/?id=p6zjojqw). 4. Install macOS updates as they arrive, since the new controls will come through Apple. 5. Check which apps connect to the internet, so that an app with broad file access is also known by its destinations. ## Relevance to FireAI FireAI is a firewall for one Mac. It identifies an app by its code signature, applies [per-app rules](https://hisnlabs.com/en/docs/per-app-rules) to each connection that app opens, and the [Activity](https://hisnlabs.com/en/docs/activity-and-connection-history) page lists every app that went online, newest first. For AI agents, the [Agent profile](https://hisnlabs.com/en/docs/agent-profile) recognises apps such as Claude Code and Cursor, learns where each normally connects, and flags a first-ever destination or an upload spike, using only host names and byte counts. FireAI does not grant, remove or manage the Full Disk Access permission, which belongs to macOS. It does not read files, messages or mail, and it cannot tell what an app has read from the disk. It does not read the inside of an encrypted connection, and it cannot show whether a particular transfer contains private data. > A file permission and a network connection are separate controls on a Mac. FireAI asks before an app contacts a destination it has no rule for, and keeps the list of what each app reached. Try it free for 17 days. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## Limitations The Apple post is a statement of intent: it gives no design, no macOS version and no date for the new controls [[1]](https://developer.apple.com/news/?id=p6zjojqw). TechCrunch's account of the Muse and ChatGPT reports is secondhand, and the Meta claim is disputed [[2]](https://techcrunch.com/2026/10/02/apple-says-its-tightening-macos-full-disk-access-controls-due-to-new-risks-from-ai-agents/); this item did not fetch the Inc. or Wired reports. The sources do not establish that any AI agent used Full Disk Access to read data in the cases mentioned. Try [FireAI, by HisnLabs](https://hisnlabs.com/en/download) free for 17 days. ## Sources - [Apple Developer News, 2 October 2026: Updates to Full Disk Access in macOS](https://developer.apple.com/news/?id=p6zjojqw) - [TechCrunch, 2 October 2026: Apple says it’s tightening macOS “Full Disk Access” controls due to new risks from AI agents](https://techcrunch.com/2026/10/02/apple-says-its-tightening-macos-full-disk-access-controls-due-to-new-risks-from-ai-agents/) - [MacRumors, 2 October 2026: Apple announces macOS Full Disk Access changes](https://www.macrumors.com/2026/10/02/apple-announces-macos-full-disk-access-changes/)