On October 2, 2026, Apple posted "Updates to Full Disk Access in macOS" to its developer news page.
- This guide provides comprehensive, actionable information
- Consider your specific workflow needs when evaluating options
- Explore our curated AI Assistants tools for specific recommendations
What Apple actually said
On October 2, 2026, Apple posted "Updates to Full Disk Access in macOS" to its developer news page. The core of it is two sentences. First, the problem: "Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems, including files, mail, messages, and even browsing history, without users' full knowledge and understanding." Second, the fix: "Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action."
The post names the reason directly: "As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially." It also makes a point that is easy to miss. For messaging apps, the exposure is not only yours: granting access "can also compromise the privacy of the people users are communicating with."
What Full Disk Access is, and why agents want it
Most of macOS privacy works one door at a time. An app asks for your photos, your contacts or a folder, and you answer each request separately. Full Disk Access is the exception. In Apple's words it "largely sidesteps these controls in order to allow backup apps to function properly on the Mac." A backup tool genuinely needs to read everything. Once granted, so does any other app holding the permission: the Mail store, the Messages database, Safari history, and every document in your home folder.
That is exactly what a personal agent wants. An assistant that triages your texts or answers questions about last week's email has to read them somewhere, and on a Mac the shortest route to the Messages database is Full Disk Access. Daring Fireball lists Meta's Muse, xAI's Grok Bot, Claude and OpenAI's Dots among the agent apps that ask for it, and draws the contrast with the iPhone, where no third-party app can read your email or end-to-end encrypted messages whatever you grant. On the Mac, saying yes to everything gives an app "effectively, almost everything on your startup drive."
Why now: the Muse dispute
Apple's post does not name any app, but it landed two days after a public argument about one. Inc. columnist Jason Aten reported that Meta's Muse, running on his Mac, had read his private messages although he says Full Disk Access was off and he had declined access during setup. When he asked Muse how it knew, it told him it was only syncing his device notifications.
Meta disputes all of it. As TechCrunch reported, Meta's Andy Stone said "the Messages integration in the Muse app for Mac is entirely opt-in. You have to enable both Full Disk Access and the Messages connector for Muse to be able to read your Messages content." David Singleton of Meta Superintelligence Labs described "three separate steps of application-level permissions and built-in macOS system-level protections" that "can't be circumvented even if the Muse application had a bug," and said the notification explanation Muse gave was incorrect.
Nobody outside the two parties has settled what happened on that machine, and this guide does not try to. What matters is the part both sides agree on: on a Mac, an agent reading your Messages history runs through Full Disk Access. That is the permission Apple is now putting behind a harder gate.
What is still unknown
Almost everything about the mechanism. Apple has not said which macOS release brings the change, what "very explicit user action" will look like, whether apps that already hold the permission will lose it or have to ask again, or whether developers will need a new entitlement or review step. The developer guidance amounts to this: the permission is meant for backup tools, and broader use will face more friction. Treat any article that describes the new screens in detail as guessing until Apple ships them.
What to do now
For what happens when an agent treats a closed door as a puzzle, see OpenAI's rogue agents. For the wider risk picture, LLM security and privacy for businesses covers the controls. The agents themselves are in every AI assistant in the directory, including Grok Bot. The day's news is in the October 4 briefing.
Explore curated tools related to this guide: