On 2 October 2026 Apple said on its developer news site that it will add controls so that users who "genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action." The post names AI agents as the reason: "As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially." Apple gave no release date, no macOS version and no list of apps.
What happened
Full Disk Access is a macOS permission that largely sidesteps the system's per-folder privacy prompts. Apple says it exists so backup apps can work. Its post warns that some developers use it in ways that expose "files, mail, messages, and even browsing history" without users' full understanding. It adds that for communication apps, this "can also compromise the privacy of the people users are communicating with."
The trigger was a dispute over Meta's always-on Muse agent. According to MediaNama's account, Inc. columnist Jason Aten wrote on 19 September that Muse synced his Mac Messages database even though Full Disk Access was off on his machine. Meta denies this. Communications chief Andy Stone said Muse cannot read Messages unless the user takes specific opt-in steps. David Singleton, an executive at Meta Superintelligence Labs, said access takes three separate permission steps. Apple did not name Meta or any other app.
This article does not take a side on what Muse actually did. The facts are contested, and Apple's change does not depend on resolving them.
The strongest case for stronger rules
The case for mandatory rules is serious. A permission that exposes everything on a computer is a poor fit for software that acts autonomously, runs continuously and connects to thousands of services. OpenAI's agents launched on 29 September and reportedly connect to more than 4,000 apps. A consent click given once, under a vague prompt, can turn into indefinite access. The harm also falls on third parties: a person whose messages sit in someone else's database never consented to anything. In the EU, GDPR Article 25(2) already requires that personal data "are not made accessible without the individual's intervention" by default. The European Data Protection Board's Guidelines 4/2019 on that article set out how default settings should be designed. Regulators could plausibly say this is a legal duty and not a product choice.
Why a platform gate is the better instrument
The argument for the platform approach is practical and rests on four points.
- It acts at the chokepoint. The operating system is the one place where every agent, from any developer in any country, must request access. A statute has to reach developers one jurisdiction at a time. A permission gate works the same everywhere on day one.
- It can change quickly. Agent behaviour is shifting month by month. Apple's post is a few paragraphs and can be revised in a point release. A definition of "agent" written into law risks being obsolete before it takes effect.
- It targets the capability, not the technology. The control is the access scope, not whether a model is involved. A conventional backup tool and an AI agent are treated alike, which avoids a regulatory category that could chill small developers.
- It leaves room for open competition. Users keep the ability to grant broad access when they have a reason to. A ban on broad file access would hurt legitimate backup, search and security tools.
The trade-off is concentrated power. When one company decides what counts as "very explicit," that definition can double as a competitive weapon against rivals' agents. Competition regulators in the EU, Japan and the UK have all examined how platform permission rules can favour a gatekeeper's own services. MediaNama's reporting flags the open question directly: whether the same consent standard will apply to Apple's own AI features.
What to watch
Three tests will show whether this is a privacy measure or a moat.
- Parity. Apple's own assistants and system services should face the same prompt friction as third-party agents. If they do not, the policy will be read, fairly, as self-preferencing.
- Specificity. Granular, revocable and time-limited grants, such as one folder or one app's database, are better than a harder all-or-nothing switch. Users should be able to give an agent what it needs without handing over everything.
- Disclosure for third parties. Apple itself notes that communication apps can expose other people's messages. A dialog cannot ask those people for consent, so developers need data-minimisation duties that go beyond the user's click.
There are also open questions Apple has not answered: whether apps that already hold Full Disk Access will lose it, how backup vendors will be affected, and when any of this ships.
The policy takeaway
Regulators should resist the urge to write agent-specific access mandates in response to a single disputed incident. Existing data-protection law already requires privacy-protective defaults, and the EDPB's guidance already tells developers how to build them. The practical gap is enforcement and transparency. A regulator that can obtain permission logs and audit whether an app read data outside its declared purpose can resolve disputes like Muse's with evidence instead of competing press statements.
Apple's move is a reasonable response and is worth welcoming. It should be judged on its details, on equal treatment of Apple's own software, and on whether users and developers get clear, granular controls rather than a more elaborate warning screen.