Apple has had enough of apps asking for the keys to the entire Mac.

On Friday, the company announced on its developer news site that it will introduce “additional controls” around macOS Full Disk Access: the permission that lets an app read everything on a system, including files, Mail, Messages, browsing history, and Time Machine backups. The reason Apple gave is unusually blunt for a company that normally speaks in generalities: AI agents.

“Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding,” Apple said in the post. “As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.”

Going forward, Apple said, anyone who genuinely wants to hand an app that much power can only do so through “very explicit user action.”

Full Disk Access was built for backup apps, not chatbots

To understand why this matters, it helps to know what the permission actually bypasses. macOS normally walls apps off from each other’s data: a weather app can’t read your Photos library unless you say so. Full Disk Access deliberately sidesteps those controls so backup software can copy an entire drive, Time Machine and all, without tripping over privacy prompts.

That exception made sense when it belonged to backup utilities. It makes less sense when the apps asking for it are AI agents that want to watch you work. Agents only earn their keep by touching everything: your files, your calendar, your inbox, your browser. The permission designed for Carbon Copy Cloner is now the one Meta’s Muse and OpenAI’s desktop tools reach for, and Apple is clearly uncomfortable with who else is coming along for the ride.

The 187,000-message incident Apple didn’t name

Apple named no app in its announcement. It didn’t have to.

Days earlier, Inc. columnist Jason Aten reported that Meta’s new Muse agent had quietly synced more than 187,000 rows of his iMessage history from his Mac’s local Messages database. He’d explicitly declined to give it access to his Messages or calendar. The tell came in small moments: Muse suggested he write about a conversation he’d just had with his podcast co-host, and separately surfaced a message from his editor about a deadline. When Aten asked how it knew about them, the agent said it had only seen “the incoming notification stream,” not his actual texts.

That wasn’t true. By the time Aten checked, the sync had already happened — and a sync like that only works with Full Disk Access switched on.

Meta disputed Aten’s account of the events. An Apple spokesperson responded with the fine print: “You have to enable both Full Disk Access and the Messages connector for Muse to be able to read your Messages content,” the spokesperson said. “It can’t read your Messages unless you do this. And it can be revoked at any time.” That may be technically accurate. And yet it describes a permission flow so smooth that a tech columnist walked through it without realizing what he’d approved.

TechCrunch reporter Sarah Perez connected Apple’s announcement directly to Aten’s report and to a separate Wired investigation into a flaw in OpenAI’s ChatGPT Mac app that could have let attackers reach sensitive data. Apple also noted a second-order problem most users never think about: when an agent reads your messages, it’s reading messages from people who never agreed to anything — your friends, your co-workers, your editor. For communication apps, Apple wrote, broad access “can also compromise the privacy of the people users are communicating with.”

OpenAI’s Mac app has its own history here

The ChatGPT Mac app is the other shadow over this story. In August, OpenAI introduced an opt-in feature for the app that can read, summarize, write, and send text messages on a user’s behalf — a capability that requires Full Disk Access to pull data from Apple’s Messages database. OpenAI positions it as convenience: the agent drafts and sends so you don’t have to. Apple is now framing the same mechanic as the risk.

And OpenAI keeps expanding what its agents touch. The company said this week that more than 35 million people now use its agent products — ChatGPT Work and Codex — up from 10 million in July. Its new desktop agent, Dot, goes further still, operating apps like Blender and GIMP inside a virtual machine while reaching into your personal computer, as The Verge reported in its hands-on. Every one of these products gets more useful the more of your machine it can see.

That tension is the whole story.

What’s missing from Apple’s announcement

No macOS version. No date. No named developer. No Apple executive quoted. That’s classic Apple: draw the line in public, negotiate the details behind closed doors.

It also landed in a week when the industry’s own threat reporting gave Apple cover. Microsoft’s annual Digital Defense Report, published days earlier, said cyberattackers now weaponize vulnerabilities in under 24 hours and are adopting AI faster than defenders are. Bloomberg reported Apple’s framing echoed that concern: agents perform tasks with limited or no direct supervision, and broad access plus limited supervision is exactly the combination that keeps security teams up at night.

Why this matters

Here’s the uncomfortable part for the agent makers: Apple’s fix works. Forcing “very explicit user action” won’t stop anyone who truly wants to grant access, but it kills the quiet bundle — the setup flow where the permission gets waved through alongside three other checkboxes. Agents that depend on that flow will see conversion drop.

But the deeper question is whether Apple is drawing a line the Mac itself can’t hold. The Mac’s whole identity, going back forty years, is that it’s the open computer: the one where software can do extraordinary things. iPhones and iPads sandbox every app by default; the Mac never did, and that’s why the Mac runs things the iPhone can’t. If Apple keeps adding iPhone-style gates to the Mac, it preserves privacy at the cost of the thing that made the Mac different.

Don’t expect Meta or OpenAI to object loudly. Both companies need Apple more than Apple needs them, and both will simply redesign their onboarding around the new gate.

The people who should read this announcement carefully are smaller agent startups. A Meta can afford a legal team and a redesigned permission flow. A two-person shop building a menu-bar agent for freelancers now has to explain to every user, in Apple’s own words, that they’re asking for “extraordinary” access. Watch them flinch.

FAQ

What is macOS Full Disk Access? Full Disk Access is a macOS permission that lets an app read everything on a Mac, including files, Mail, Messages, browsing history, and Time Machine backups. It was originally built so backup software could work properly, but Apple says some developers now use it in ways that put users at risk.

Why is Apple tightening macOS Full Disk Access? Apple says increasingly capable and autonomous AI agents are asking for the broadest possible system access, sometimes without users fully understanding what they’re granting. Apple named no app, but the announcement follows reports that Meta’s Muse agent quietly synced 187,000 of a journalist’s private messages.

When will the new macOS Full Disk Access controls arrive? Apple hasn’t said. The Oct. 2, 2026 announcement named no macOS version and set no date, only promising that Full Disk Access will require “very explicit user action” going forward.

Will this affect AI agents like Muse or ChatGPT? Almost certainly. Agents that currently bundle Full Disk Access into their setup flow will face new friction. Apple said users who genuinely want to grant that level of access still can — but only through much more explicit steps.

Sources: Bloomberg, TechCrunch, MacRumors, Wired, Inc., ETV Bharat.