On October 2, 2026, Apple said in a post on its developer news site that it will add "additional controls" around Full Disk Access on macOS, because AI agents make that permission riskier. macOS 27 Golden Gate, released on September 14, does not include the new controls, and Apple has not described what they will look like or when they arrive.
So today nothing about how the permission works has changed. What has changed is that it is a good time to look at which apps on your Mac already have it.
What Apple actually said
Apple's message, as reported by MacRumors and TechCrunch, makes three points: some developers use Full Disk Access in ways that could expose everything on a Mac, including files, mail, messages, and browsing history; the risk grows as AI agents become more capable and autonomous; and Apple wants users to understand that before they grant it.
The announcement followed a dispute over Meta's Muse agent. A journalist claimed it knew the contents of his private messages. Meta disputed that, saying a user has to enable both Full Disk Access and a Messages connector before Muse can read any messages. We cannot settle that argument, and it is not needed to make sense of the permission.
What Full Disk Access lets an app read
Normally macOS protects sensitive locations one at a time: your Mail data, Messages, Safari history, and other apps' private data each have their own gate. Full Disk Access skips those gates. It exists mainly so backup tools can copy everything.
In practice, an app with it can read:
- Mail and Messages databases, including the content of conversations
- Safari history and other browsing data
- Files in protected folders, and data belonging to other apps
It is not limited to AI apps. MacStories points out that a typical power user has granted it to many everyday tools such as launchers, automation utilities, and file managers, not only backup software. That is why the proposed change could affect apps with nothing to do with AI.
Audit your Mac in two minutes
- Open the Apple menu > System Settings > Privacy & Security > Full Disk Access.
- Read the list. For each app ask whether you recognize it and whether it genuinely needs to see everything on the disk.
- Turn off the switch for anything you do not use or do not trust. For apps you have removed, select the entry and click the minus button.
- Quit and reopen any app you changed. A running app keeps behaving as if it still has the old permission until it restarts.
- Repeat for the neighbors that are almost as powerful: Accessibility (lets an app control your Mac) and Screen & System Audio Recording (lets it see your screen).
Most of what you find will be harmless. The goal is to catch the permission you gave years ago to a tool you no longer open.
Which apps really need it
| App type | Needs Full Disk Access? | Safer option |
|---|---|---|
| Backup and cloning tools | Usually yes | None. This is what the permission is for. |
| Security tools and disk utilities | Often yes | Grant only to software you trust and keep updated. |
| Terminal and developer tools | Only if scripts touch protected folders | Grant access to specific folders under Files & Folders first. |
| Launchers and automation apps | Depends on the feature you use | Try without it and add it only if a feature stops working. |
| AI assistants and agents | Rarely, and only for reading Mail or Messages | Folder-level access to the folders you choose. |
Should an AI agent get it?
Use one test: does the task need your mail and messages? If you want an assistant to summarize a project folder, folder-level access is enough. If the only reason it asks for Full Disk Access is that it would be more convenient, say no.
- Prefer agents that let you switch connectors on one at a time and tell you what each one reads.
- Grant Files & Folders access to named folders instead of the whole disk.
- Remember that agents act, not just read. Check Accessibility and Screen Recording as well.
- Review the list again after any update to the agent app, since new versions can ask for more.
For a worked example of what a mainstream agent needs on a Mac, see our ChatGPT Dots on macOS guide.
What to expect from the change
Reports say users will have to take extra, more explicit steps before an app can get Full Disk Access. That is all that is known. MacStories raised a concern that Apple's description of the permission as a backup feature might signal restrictions on which kinds of apps can use it at all. Apple has not said that, and we will not guess. If you rely on a tool that has Full Disk Access, keep an eye on its developer's notes after Apple publishes details.
If an app breaks after you remove access
- Add it back with the plus button in the Full Disk Access list, then quit and reopen the app.
- If the switch will not stay on, reset that app's stored record and approve again. First find its bundle
identifier:
osascript -e 'id of app "AppName"' - Then reset the Full Disk Access record for that identifier and relaunch:
tccutil reset SystemPolicyAllFiles com.example.app
Replace com.example.app with the identifier from the first command. Our
permissions guide covers the other
permission types and why stale records happen.
The short version
- Apple announced extra Full Disk Access controls on October 2, citing AI agents. They have not shipped yet.
- The permission bypasses macOS's per-folder protection and can expose mail, messages, and browsing history.
- Audit it now in System Settings > Privacy & Security > Full Disk Access and remove what you do not need.
- Give AI agents folder-level access unless a task truly requires reading your mail or messages.