
Apple Tightens Full Disk Access—but the New Controls Have No Date

In an October 2, 2026 developer notice, Apple announced additional controls for macOS Full Disk Access that will require “very explicit user action” before an app receives the permission, citing growing risks from increasingly autonomous AI agents. The plan gives no release date or macOS version. Mac users still have the existing permission settings while the new controls remain unspecified.
An October 5 TechRadar report found no change to the Full Disk Access interface and no sign of the controls in the first two macOS 27.2 betas, both of which preceded the announcement. That observation does not establish which release will contain the change. The immediate privacy question is which apps already hold broad access, particularly apps that can carry out tasks with limited supervision.
What Full Disk Access exposes now
Full Disk Access is an app-level permission with a much wider reach than a request to open a particular document. The Mac User Guide’s Privacy & Security entry describes access to all files on the computer, including data from Mail, Messages, Safari and Home, Time Machine backups, and certain administrative settings for all users of the Mac. A person approving the permission for one useful function may therefore make unrelated personal material available to that app.
System-wide backup is a clear reason an app might need such reach: it cannot make a complete backup if protected material is outside its scope. An assistant asked to work on a selected file presents a different case. The same broad grant could give that assistant access to information far beyond the task, even if the user never intended to share it.
The permission describes what an app can reach, not a record of what it has actually read. Nor does a grant alone show that information was transmitted elsewhere. Those distinctions matter when assessing risk: broad technical access creates an opportunity for unnecessary reading, while the app’s behavior determines what happens with the data.
Why agents change the privacy calculation
An autonomous agent can decide which steps to take while pursuing a user’s request. If its host app has Full Disk Access, those steps may be carried out with permission to reach correspondence, browsing data and other files unrelated to the request. Consider a hypothetical request to summarize one project document: the intended input is narrow, but the app’s available data may be much wider. This is a risk created by the combination of autonomy and permission scope, not a claim about every agent-enabled app.
The exposure can extend beyond the Mac owner. Mail and message histories contain conversations with people who did not choose the app or approve its access. As an agent takes more steps on its own, the difference between the task a user authorized and the material the app can inspect becomes more consequential. A consent decision made when installing or setting up an app may also be easy to forget as the app’s features change.
Which existing permissions Mac users can review
Mac users can inspect current grants in System Settings under Privacy & Security. The useful question for each listed app is whether its present function calls for that level of access. An old grant may have been reasonable for a backup tool and excessive for an app now used only with selected material.
- Full Disk Access: Review every listed app, including background utilities and agent-enabled assistants. Identify apps no longer used and those whose current work does not call for access across the Mac. Turning off a grant can affect a function that depends on it, so judge the permission against the function you still use.
- Files & Folders: Review location-specific access separately. Permission to reach files in particular locations has a different scope from Full Disk Access; seeing an app in this list does not mean it has the broader grant.
- Automation and Accessibility: Check these entries for apps that take actions on the user’s behalf. Automation concerns access to and control of other apps; Accessibility can allow scripts and system commands to control the Mac. Their presence helps explain what an agent-enabled app can do alongside any disk access it holds.
This review addresses permissions already available in macOS. It cannot supply the additional consent control planned for a future release. It can, however, expose a mismatch between an app’s current purpose and the access previously granted to it.
What developers can prepare for
Developers whose apps request Full Disk Access have a reason to examine each function behind that request. A backup utility may need broad access to do its job; an agent handling a document chosen by the user may be able to work within a narrower scope. Reducing the data available to a task limits the consequences if the app takes an unexpected step.
Clear explanations of why an app needs protected material also become more consequential when the app can act autonomously. Developers can describe the required access in terms of the feature the user is enabling, while treating the design of the future consent process as unsettled. The planned controls have no published interface, developer requirement or treatment of existing grants yet. Release notes or developer guidance specifying those details will determine what changes apps must make and when users will encounter the new consent step.
Also read:
Related articles


DigitalOcean vs Hetzner: A 22% CPU Lead Meets a 2.5× Price Gap

7 Signs You've Outgrown Spreadsheet-Based Cap Table Management

Cohere North 2 Gives Agents Memory—and Admins Token Caps

Vocca Raises $20M—One Million Monthly AI Calls Still Need Context

ChatGPT vs Perplexity for Research: Source Credibility Changes the Winner
Subscribe to our newsletter
Get the latest Web3, AI, and crypto news delivered straight to your inbox.