Skip to content
Agentsmedium signalverified

Apple will add controls to Full Disk Access on macOS, citing risks from AI agents

Apple said on October 2, 2026, that it will add controls to Full Disk Access, the macOS permission that lets an app read nearly everything on a Mac. The company says some developers use the permission in ways that expose files, mail, messages, and browsing history without users fully understanding it. Apple expects the risk to grow as AI agents become more capable and autonomous. The post gives no date, no macOS version, and no description of the new controls.

By Redakcija WebAiRadarPublished 2 min readwritten by a model
Image: Apple

The notice appeared on Apple's developer news page under the title Updates to Full Disk Access in macOS. It is two paragraphs long and names no app. Apple says the way a user grants this permission will change, and that affects any desktop AI agent that asks for it.

What Full Disk Access is

Apple describes Full Disk Access as a permission that largely sidesteps the controls macOS uses to protect private data. The company says it exists so that backup apps can work properly on the Mac.

According to the post, some developers now use it in ways that could put users at risk. Apple lists what the permission exposes: files, mail, messages, and browsing history. It adds that for communication apps the exposure also affects the privacy of the people you write to.

Apple's Mac User Guide defines the setting the same way. An app with Full Disk Access can read all files on the computer, including data from other apps such as Mail, Messages, and Safari, and data from Time Machine backups. The same Privacy & Security page has a separate Files & Folders setting. That one lets you allow an app to reach files in specific locations only.

What Apple says will change

Apple says it will introduce additional controls. Their stated purpose is that a user who wants to give an app this level of access can do so only by taking a very explicit action.

The company ties the change to AI agents. It expects the risks of this access to grow substantially as agents become more capable and autonomous. Apple also says it wants users to understand those risks before they grant the permission.

The context TechCrunch reports

Apple's post does not say what prompted it. TechCrunch reports that it came days after Inc. columnist Jason Aten wrote that Meta's Muse app on the Mac knew the content of his private messages. Aten said he had not given the app permission. Meta disputed that claim, according to TechCrunch.

The same report says Muse lets users optionally turn on Full Disk Access. TechCrunch also says Apple did not immediately respond to its questions about the change.

What is not confirmed yet

Apple has not said when the controls will arrive or which macOS version will include them. The post does not describe the controls. It also does not say what happens to apps that already hold Full Disk Access.

„Addressing this is critical.“
Apple, Apple Developer News

Sources

Related

Customize Claude Code with mods in TypeScript | Claude by Anthropic
Agentsstrong signal

Claude Code mods are not sandboxed, and version 2.1.289 fixes a deny rule they could override

Anthropic introduced mods for Claude Code on October 1, 2026. They are TypeScript functions, shipped inside plugins, that can rewrite prompts, change tool calls, and redraw parts of the interface. The documentation says mods are not sandboxed and run with your permissions, which covers your files, environment variables, and API keys. On Team and Enterprise plans a built-in mod named sec-default loads first and restricts the mods that users install. Versions 2.1.288 and 2.1.289 fix several cases where permission rules did not hold.

Anthropicverified

Agentsmedium signal

GitHub Copilot retires four models and makes Balanced its default code review effort

GitHub deprecated four models across all Copilot experiences on October 2, 2026: Gemini 3.5 Flash, Gemini 3.6 Flash, Kimi K2.7 Code, and Claude Opus 4.7. On the same day it made Copilot code review available through the REST and GraphQL APIs. Balanced is now the default review effort level, a change that took effect on September 28, 2026. According to GitHub's documentation, a Balanced review consumes more AI credits than a Lite one.

GitHub Changelogverified

AWSBusiness+the lowest Support plan with access to the age
Agentsmedium signal

AWS previews Well-Architected Agent, limited to Business+ Support plans and above

AWS announced a preview of AWS Well-Architected Agent on October 1, 2026. The service scans your AWS accounts on a schedule and returns recommendations for cost, security, resilience, and performance, ranked against business goals that you write yourself. Remediation scripts come attached, and the agent also reviews infrastructure-as-code templates on demand. Access requires an AWS Support plan at the Business+ tier or higher, and agent profiles are hosted in three US Regions.

AWSverified