In short: On 2 October 2026 Apple announced it will add stricter controls to macOS's "Full Disk Access" permission — the setting that lets an app read every file, email, message and browsing-history entry on a Mac. The trigger is the rise of always-on AI agents such as Meta's Muse and OpenAI's Dots, which request this level of access while, in Apple's own words, users don't always "fully understand" what they're granting. The new controls will require a deliberate, explicit action before a Mac grants that level of trust to any app; Apple has not said when the change ships.
What Apple actually announced
In a post on its Developer News portal, Apple said some developers use Full Disk Access "in ways that could expose everything" on a user's system — files, Mail, Messages and Safari history — without the user fully grasping the scope of the grant. The coming update narrows that door: genuinely wanting an app to have this access will still be possible, but only through a clear, deliberate confirmation step, not a buried checkbox in a permissions dialog. The move was first reported by MacRumors and TechCrunch, and picked up in Russian-language coverage by EADaily.
It's a notable moment: this is one of the first OS-level changes explicitly framed around AI agent risk rather than classic malware. If you're exploring how much access a chat assistant already has on your own devices, it's worth first checking how much an AI assistant on your phone can actually see — the Mac story is the same pattern, one layer up.
Why AI agents changed the calculus
Full Disk Access isn't new — backup tools and some antivirus software have needed it for years, and macOS has long gated it behind a manual approval in System Settings. What changed is who is asking for it. "Always-on" AI agents — persistent assistants that run continuously in the background, watch what's on screen, and act on a user's behalf — need broad visibility to be useful at all. That is precisely what makes the permission dangerous if it's misused or misunderstood: it stops being a one-time integration grant and becomes an open channel to everything on the machine.
Apple's announcement came days after a journalist publicly claimed that Meta's Muse app for Mac appeared to have read the content of their private messages — a claim Meta disputed — following a separate columnist report describing similar behavior. Neither claim has been independently confirmed in full, but together they illustrate exactly the ambiguity Apple is trying to close: users often can't tell whether an AI agent is summarizing a visible screen, or quietly reading everything behind it.
What this means if you use an AI agent on a Mac
For most people, nothing changes immediately — Apple hasn't set a rollout date. But the announcement is a useful prompt to audit what's already been granted. Full Disk Access sits in System Settings → Privacy & Security → Full Disk Access, and it is worth opening that list today: every app there can, right now, read your Mail, Messages, Photos and any file on disk, whether or not you remember approving it. If an AI assistant, browser extension helper, or utility you installed months ago is on that list and you don't actively rely on its full-system features, turning the toggle off costs you nothing and closes a real exposure. The same caution applies to browser-based AI tools — see our look at the privacy risks of AI browsers for the broader pattern.
Beyond the permission screen: the parts a toggle can't fix
A tighter Full Disk Access prompt controls what a local app can read on your Mac. It does nothing for what leaves your network. Many AI agents, cloud backup tools and browser assistants phone home constantly — sending telemetry, snippets of context, or full documents to a vendor's servers. On a shared office network, a hotel Wi-Fi, or any connection you don't fully control, that outbound traffic (and the metadata around it, like which services you're using and when) can be observed by anyone positioned on the same network segment.
That's a separate layer from the one Apple is patching, and it needs a separate defense: a VPN that encrypts your traffic end to end and hides your real IP address, so no one on the local network — or your ISP — can map which cloud AI services you connect to or intercept the data in transit. LiMP VPN is a no-logs VPN for Android, Windows and Chrome; see the features and pricing, and more privacy coverage on our blog.
Sources
This report draws on MacRumors, TechCrunch and EADaily, reporting on Apple's 2 October 2026 Developer News announcement.
