Apple to tighten macOS full disk access, citing AI agent risks – Unite.AI
Apple said on October 2, 2026, that it will introduce additional controls over full disk access in macOS, saying in a post on its Developer News site that some developers are using permission in ways that could put users at risk, and that the risks of that level of access will increase as AI agents become more capable and autonomous.
What Apple announced
The post, titled “Updates to Full Disk Access in macOS,” states that Full Disk Access largely bypasses controls that support Apple’s developer APIs so that backup apps can function properly on the Mac. According to Apple, some developers are using the permission in ways that could put users at risk by exposing everything on their systems, including files, mail, messages, and browsing history, without users’ full knowledge and understanding. When the affected apps handle communications, Apple said, the exposure can extend to the privacy of the people a user is communicating with.
Apple said the upcoming controls will ensure that users who truly want to grant an app this level of access can only do so through “very explicit user action.” The company called the issue critical and said it is committed to ensuring users clearly understand the risks before granting such access, so they can make informed decisions about their data and privacy. The post does not provide any date or macOS version for the change and does not name any developers or apps.
“As AI agents become increasingly capable and autonomous, the risks associated with this level of access will increase dramatically,” the post states.
What does full disk access guarantee today?
According to Apple’s Mac User Guide, Full Disk Access allows apps to access all files on your computer, including data from other apps like Mail, Messages, Safari, and Home, data from Time Machine backups, and some administrative settings for all Mac users. The setting is found in System Settings under Privacy & Security, and adding an app requires the user to click the Add button, select the app in the list, and click Open. A separate Files & Folders category lists apps that have requested access to files and folders in different locations on your Mac.
Apple’s platform security guide describes the consent model for this setting. Apple says in the guidance that users should have full transparency, consent, and control over what apps do with their data, and that in macOS 10.15 or later the system enforces the model by helping ensure that apps get user consent before accessing files in Documents, Downloads, Desktop, iCloud Drive, and network volumes. Starting with macOS 10.13, apps that require access to the entire storage device must be explicitly added in System Settings on macOS 13 or later or System Preferences on macOS 12 or earlier.
The guide also distinguishes the ways in which access is granted. File and folder requests, which cover desktop, documents, downloads, network volumes, and removable volumes, are handled via a message from the app, while full access to internal storage requires the user to change system privacy settings. Likewise, accessibility and automation features require user permission to ensure they do not bypass other protections.
How managed Macs handle authorization
For Macs enrolled in a device management service, Apple’s Platform Deployment Guide documents the Privacy Preferences Policy Control payload, which organizations use to manage settings in the Privacy pane of Security & Privacy preferences and which carries the identifier com.apple.TCC.configuration-profile-policy. The payload requires user approval, must be installed via a device management service, supports device enrollment and automated device enrollment, and requires oversight when applied via such a service. When more than one such payload is deployed to a device, the operating system applies the most restrictive settings.
A service within the payload, System Policy All Files, allows specific apps to access data such as Mail, Messages, Safari, Home, Time Machine backups, and some administrative settings for all Mac users. Organizations creating a custom payload must specify a bundle ID or file path, whether the app is allowed or denied access, and code signing requirements, which the guide says can be achieved by running codesign -dr - on the app or binary. The guide notes that each device management service developer implements these settings differently and directs administrators to their service’s documentation.



Post Comment