๐Ÿ” AI & Technology

Apple Tightens Full Disk Access on Mac

Apple is adding new controls around Full Disk Access on macOS. We explain what prompted the change and how small businesses can review AI agent permissions safely.

TG
Thind Global Services
3 October 2026 ยท 10 min read
Apple Tightens Full Disk Access on Mac

Apple has announced new limits around Full Disk Access on macOS, responding to concerns about how powerful AI agents can use broad system permissions. The company says it is rolling out additional controls so that granting this level of access requires very explicit user action. Apple has not said when the update will arrive. For small businesses using Macs, the immediate issue is therefore not a new setting to configure today, but whether existing AI tools and other apps already have more access than they need.

Key point What is known
What Apple said Apple said it will add new controls around Full Disk Access so users can only grant this extraordinary level of access through very explicit action.
Why Apple is acting Apple said some developers are using Full Disk Access in ways that could expose files, mail, messages and browsing history without users fully understanding the consequences, and that AI agents increase the risks associated with this level of access.
Muse report A report said Meta's Muse AI knew the contents of messages despite the user not believing they had explicitly granted that access. Meta disputed the characterisation and said Messages access requires both Full Disk Access and the Messages connector to be enabled.
ChatGPT Mac app report A recently patched vulnerability in the macOS ChatGPT app could have allowed an attacker who already had malware on a machine to take over ChatGPT and access data stored by the app and connected sessions.
What has not been announced Apple has not given a date for the new controls.

What Has Apple Actually Announced About Full Disk Access?

Apple said on Friday 2 October that it is introducing additional controls for Full Disk Access on Mac. Its stated aim is to make sure users who genuinely want to give an app such broad access have to take very explicit action to do so.

Apple described Full Disk Access as an extraordinary level of permission. It said some developers are using it in ways that could put users at risk by exposing everything on their systems, including files, mail, messages and browsing history, without users having full knowledge and understanding of what is being opened up.

The company also tied the issue directly to the development of AI agents. Apple said that as agents become more capable and autonomous, the risks associated with giving them this level of access will grow substantially. In the developer-focused blog post that carried the announcement, Apple said it was critical that users clearly understand those risks before granting access, so they can make informed decisions about their own data and privacy.

What Apple has not provided is a rollout date. Businesses should therefore treat this as an announced platform change rather than something already available on every Mac.

What Is Full Disk Access on macOS?

Full Disk Access is a macOS permission that gives an app access to a user's entire system. Apple says the permission largely sidesteps the privacy controls otherwise offered to users.

That breadth is not accidental. The feature exists so that backup applications can function properly. A backup tool may need wide access because its job is to copy data from across the system rather than work only with a narrow set of files.

The problem is that a permission designed for such a broad technical task can also be attractive to software that wants extensive access for other reasons. Desktop AI agents are part of that discussion because users can give them greater access to files, messages and other personal content by changing macOS settings.

The practical question for a business is therefore not whether Full Disk Access is always good or always bad. It is whether a particular application genuinely needs that level of access for the work it is expected to do.

What Happened in the Meta Muse Messages Dispute?

Apple's announcement came shortly after a report about Meta's Muse AI. Jason Aten of Inc. reported that Muse appeared to know the contents of his messages despite his not having given the chatbot explicit permission to access them on his iPhone or Mac.

Meta disputed that interpretation. Spokesperson Andy Stone said access to Messages is entirely opt-in and that Muse can only read Messages content when a user has enabled both Full Disk Access and the Messages connector.

That disagreement matters because it illustrates the gap Apple appears to be trying to address: a user may technically enable permissions while still not fully appreciating how much information those permissions allow an AI agent to reach.

Muse can optionally be given Full Disk Access. Apple's response was broader than that one product, however. Its statement referred to developers using Full Disk Access in ways that could expose users' systems and said the growing capability and autonomy of AI agents increases the risk.

What Was the ChatGPT Mac App Security Flaw?

A separate Wired report described a recently patched vulnerability in the macOS version of OpenAI's ChatGPT app. Researchers at the Objective-See Foundation discovered the flaw, and OpenAI publicly acknowledged the issue and fix in its system change log on 25 September.

According to the report, the vulnerability could have been exploited to take over ChatGPT on a victim's computer, giving an attacker access to chat logs and other data stored by the app, as well as connections such as browser sessions.

There was an important limitation: the attacker would already have needed malware installed on the target machine. The report therefore did not describe a flaw that could be exploited from nowhere on an otherwise uncompromised Mac.

Objective-See researcher Patrick Wardle said his proof of concept required only about a dozen lines of code. He compared agents to a building manager holding keys to every room: if that manager is corrupted or subverted, less privileged code may gain access to far more than it otherwise could.

OpenAI spokesperson Shane Bauer said the company continues to evolve its security practices while recognising the need to move faster.

Why Do AI Agent Permissions Matter for a Small Business?

For a small or medium-sized business, the central issue is concentration of access. An AI agent that can work across files, messages or browser-connected sessions may be useful precisely because it can reach more of the user's working environment. The same breadth of access can increase the consequences if the application, its integrations or the machine itself is compromised.

This is not an argument that businesses should avoid desktop AI agents. It is a reason to treat permissions as part of deployment rather than as a box that individual users click through once and forget.

Practical guidance: decide what each AI tool is supposed to do before granting broad access. If its role only requires a limited part of a user's working environment, giving it access to an entire system deserves additional scrutiny.

Practical guidance: consider permissions alongside integrations. The Muse dispute is a useful reminder that access may depend on more than one setting or connector, and the resulting capability may be wider than a user expects from any single prompt.

Practical guidance: avoid assuming that a permission is safe merely because macOS allows it. Apple's announcement is specifically about making the consequences of Full Disk Access clearer and making the act of granting it more explicit.

How Should a Business Audit AI Agent Permissions on Company Macs?

The following is practical guidance for businesses rather than a description of Apple's forthcoming controls. The aim is to understand what is already authorised on company Macs and whether that access still matches a genuine business need.

  1. List the AI agents and desktop assistants in use. Include tools formally approved by the business and any that staff may have installed for day-to-day work.
  2. Review Full Disk Access. On each relevant Mac, review which applications hold Full Disk Access in the Privacy and Security settings.
  3. Ask why each app needs it. For every application with Full Disk Access, identify the task that requires such broad system access rather than accepting the permission by default.
  4. Remove unnecessary access. If an application can still perform its intended role without Full Disk Access, consider reducing its permissions.
  5. Review connectors as well as system permissions. An AI tool may combine macOS access with optional connections to other data sources. Check whether those connections remain necessary.
  6. Separate testing from routine use. If you are evaluating a new agent, avoid immediately giving it the widest permissions simply to see what it can do.
  7. Make permission decisions visible. Keep a simple record of which tools have broad access, why that access was approved and who is responsible for reviewing it.
  8. Revisit permissions when a tool changes. New features can broaden what an agent can do, so review access again when the way the business uses the tool changes.
  9. Prepare for Apple's update. Because Apple has announced new controls without giving a rollout date, keep an eye on future macOS changes and reassess your process when the controls become available.

What Does Apple's Announcement Not Change?

Apple's announcement is a change to how macOS will control a powerful permission. It is not a change to UK law.

General data protection obligations continue to apply. Businesses should therefore avoid treating Apple's forthcoming controls as a substitute for their own decisions about which applications can access company information, what employees are allowed to connect to AI tools and how those permissions are reviewed.

It also does not mean Full Disk Access is inherently inappropriate. Apple says the feature exists so backup applications can function properly. The relevant question remains whether an application has a legitimate reason to hold that permission and whether the user or business granting it understands the consequences.

Finally, Apple has not said when the new controls will roll out. There is no reason to wait for an unspecified future update before reviewing access already granted to applications on company Macs.

What Should UK Businesses Do Now About Desktop AI Agents?

The sensible response is governance rather than panic. Desktop AI agents can become more useful as they gain access to more parts of a user's working environment, but that same access needs to be deliberate.

Practical guidance: start with an inventory of the AI applications being used, check which of them hold Full Disk Access, and challenge any permission that does not have a clear operational reason behind it. Treat connectors and related integrations as part of the same review rather than looking only at the macOS permission itself.

It is also worth making the review repeatable. A one-off clean-up may remove permissions that are no longer required, but it will not help if new tools are later installed and given broad access without oversight.

Apple's announcement points towards a more explicit permission process in future. Businesses do not need to wait for that process to arrive before adopting the same principle themselves: broad access should be intentional, understood and limited to applications that genuinely need it.

Frequently Asked Questions About Full Disk Access and AI Agents

Has Apple Already Changed Full Disk Access on macOS?

Apple has announced additional controls intended to make granting Full Disk Access more explicit, but it has not said when the update will roll out. Businesses should therefore review current permissions now rather than assuming the new controls are already in place.

Does an AI Agent Need Full Disk Access to Work on a Mac?

Not necessarily. Full Disk Access gives an application access to the user's entire system, and Apple says the permission was designed so backup applications could function properly. Whether an AI agent needs it depends on what the application is expected to do. Businesses should assess that need rather than granting broad access automatically.

Is Apple's Full Disk Access Update a Change to UK Law?

No. Apple's announcement concerns macOS permission controls, not UK law. General data protection obligations continue to apply, so businesses still need to make their own decisions about access to company data and the use of AI tools.

What Should We Check First on Company Macs?

As practical guidance, start by reviewing which applications hold Full Disk Access in the Privacy and Security settings, then identify whether each one still needs that level of access. Pay particular attention to AI agents and any connectors that extend what those applications can reach.

Need help putting this into practice?

Talk to our Birmingham team โ€” free consultation, no obligation, fixed quotes.

Get a free quote