The permission was built for backups

Full Disk Access exists for one job: backup apps. It was designed to sidestep the normal privacy controls so backup tools can read everything on the drive. A reasonable exception for backup software. A very different proposition as the standard permission for an app that chats with you like a friend.

Meta's Muse asks for it. The agent needs it to do the agent things — cancelling subscriptions, reading documents, acting across apps. The problem is not that the permission exists. It is what the user understood they granted. Apple says some developers are using it “in ways that could put users at risk, exposing everything on their systems... without users' full knowledge and understanding.”

The details of the dispute are contested

Meta disputes the story that set this off. Inc. columnist Jason Aten reported that Muse knew the content of his private messages even though he claimed never to have granted permission; Meta says it accessed nothing improperly. Those facts are contested. The timing is not: Apple's crackdown landed days later, and Apple named the pattern rather than the company.

Worth remembering this is the second incident, not the first. Wired reported a flaw in the ChatGPT Mac app that could have let hackers reach sensitive data. Apple is reacting to a trend, not a single bug.

What changes in practice

Apple says people who “genuinely wish to grant an app this extraordinary level of access” still can. The keyword is extraordinary. Full Disk Access is being reclassified from a routine developer setting into the nuclear option, and the new prompts will spell out what it actually covers: files, mail, messages, browsing history.

Apple added a line about communication apps that deserves a second read: for those, the access “can also compromise the privacy of the people users are communicating with.” Your agent's permissions leak onto your contacts.

Developers split on the move. Some on Hacker News welcomed finer per-folder granularity; others bristled at the “extraordinary” framing, one noting that full access used to be the default assumption for software running on hardware you own. A fair point. But agents are not ordinary software. They act, with growing autonomy. As Apple put it: “the risks associated with full disk access will grow substantially as AI agents become increasingly capable and autonomous.”

That sentence is the whole story. Apple is not regulating agents. It is regulating the doors agents walk through.

Sources

  1. [1] TechCrunch, “Apple says it's tightening macOS 'Full Disk Access' controls due to new risks from AI agents” (Oct 2, 2026)Read source
  2. [2] IANS, “Apple to tighten Full Disk Access on Mac after AI agent concerns over user data” (Oct 3, 2026)Read source
  3. [3] WeSearch, coverage roundup including Bloomberg and 9to5Mac (Oct 2, 2026)Read source