← all articles

apple full disk access ai agents: what changed?

as of october 2026, apple full disk access ai agents policy is getting stricter because a disk-wide grant is riskier as agents get more autonomous. on october 2, 2026 apple said some apps use that permission in ways that expose files, mail, messages, and browsing history without users' full understanding, and that it will require "very explicit user action" before anyone can grant it.

apple did not name a product, a macos version, or a ship date. the whole first-party note is 1,129 characters. that short note is the first-party answer to apple full disk access ai agents questions.

judgement: treat full disk access as a last resort for backup-class tools, not a normal checkbox for an agent that wants to "help with your mac".

what did apple announce on october 2, 2026?

apple updates full disk access with a short developer news note, not a release notes dump.

the post is also listed on the apple developer news index for the same date. apple says full disk access largely sidesteps the privacy controls that protect private data, and that it exists so backup apps can work on the mac.

it then says some developers use the grant in ways that put users at risk, and that for communication apps the privacy of people you talk to can be compromised too.

what apple commits to next:

  1. additional controls so users who truly want this access can grant it only with very explicit action
  2. clearer risk understanding before the grant, because agent capability and autonomy are rising
  3. no product rollout sheet in the same note: no macos train, no api changelog, no calendar day

until apple ships the controls, the permission still works as it does today. the policy signal is already public.

what is full disk access on a mac?

full disk access macos is a privacy and security toggle that opens protected locations most apps cannot read. macos full disk access privacy settings are where you add or remove apps.

apple's own privacy and security settings guide describes it as access to all files on your computer, including data from other apps such as mail, messages, safari, and home, data from time machine backups, and certain administrative settings for all users on the mac. that matches the categories apple flagged in the october 2, 2026 note, including messages mail browsing history among the exposed stores.

you grant it in system settings under privacy and security, then full disk access. you usually add the app yourself, confirm, and relaunch it. apple still thinks that path is not deliberate enough for the agent era.

this grant is not the same as screen recording permission on a mac. screen recording sees pixels. full disk access can reach stored databases behind those pixels. for how agents combine see and act grants, see computer use agents on a mac.

why is apple tightening full disk access for ai agents?

apple's stated reason is risk growth as agents get more capable and more autonomous.

the company frames full disk access as an "extraordinary level of access". backup tools need something like it. general purpose agents that plan, call tools, and keep running do not need it by default, yet some products still ask because it is the fastest way to read mail, messages, and history.

apple also notes a second-order hit: when a communication app gets disk-wide reach, the people you message lose privacy they never consented to share. that is why apple called out communication apps specifically.

press coverage the same day, including dan goodin's ars technica report, reads the note against the late september muse and messages debate. that framing is useful context, not apple's named target. apple's text does not name meta or muse.

should you still grant full disk access to ai agents?

only for a narrow class of jobs, and only after you can explain what the app will read. the short form of should you grant full disk access to ai agents is usually no.

people still want agents that can search work context. the anthropic economic index for may 2026 ranked searching electronic sources as the top work task in sampled conversations at 4.95%, with reference searching at 3.74%, while work overall was 43.36% of classified conversations. that thirst for retrieval does not require disk-wide mail and message stores.

use this checklist before you add an agent to the full disk access list:

  1. name the job. backup, migration, or forensics style work can justify fda. "summarize my week" usually cannot.
  2. ask for a narrower path. files and folders, user-selected folders, or an in-app connector beat a disk-wide grant.
  3. read who else is exposed. if the agent can open messages or mail stores, other people's words are in scope.
  4. separate see from act. an agent with fda plus accessibility plus network is a much larger blast radius than a read-only archive.
  5. revoke when the job ends. apple's settings list is editable; leave it empty when you do not need it.

the honest answer to should you grant full disk access to ai agents on mac is usually no. same caution as broad screen access in is it safe to let ai see your screen and cloud recall-style archives in is microsoft recall safe.

estimate (author): for most people running chat or coding agents on a personal mac, refusing fda removes more risk than any later prompt filter.

how does full disk access compare to other mac privacy grants?

full disk access sits above folder picks and beside other high-power toggles, not next to a harmless notification.

grantwhat it mainly openstypical forrelative blast radius
files and foldersdesktop, documents, downloads style locationseditors, sync clientsmedium
screen and system audio recordingpixels and optional audiorecorders, some agentshigh for what is on screen
accessibilitydrive other apps' uicomputer-use agentshigh for actions
full disk accessprotected stores including mail, messages, safari data, backupsbackup and deep system toolsvery high for stored private data

an agent that asks for screen recording so it can watch a workflow is already asking for a lot. one that also asks for full disk access wants history that never appeared on screen during the session.

if you only need searchable work context, local-first software and on-device archives differ from disk-wide agent reach. more in private ai on your mac.

what does the muse press story add, and what does it not prove?

press pieces about muse explain why readers care this week. they do not rewrite apple's announcement.

techcrunch on september 30, 2026 reported meta disputing jason aten's claim that muse read private messages without permission. meta spokespeople said messages access needs full disk access plus an in-app messages connector.

ars technica on october 2, 2026 quotes researcher patrick wardle arguing that with fda, non-root files such as browsing history, cookies, and chats are readable in principle. those are press-reported claims and opinions. apple's note still does not name muse or settle that dispute.

use the press for timing and questions. use apple for what will change.

verdict: as of october 2026, apple has announced a direction, not a finished control panel. grant full disk access to an ai agent only when the product cannot work without it and you accept that mail, messages, files, and browsing history are in play. otherwise keep the toggle off.

keep work memory without a disk-wide grant

you can keep a searchable trail of your own work without handing an agent every protected store on the mac.

remynd is a mac app for that trail. it captures the focused window, runs ocr locally with apple vision, and keeps a searchable index on your mac. you can exclude apps and sites, and recordings are kept for 30 days by default. call transcription runs on device with mlx.

the agent window runs your own claude code or codex cli against that history with read-only access. settings accept a custom api endpoint compatible with the openai responses api. sign-in and cloud model calls still use the network, so the honest claim is that the archive lives on your mac, not that nothing ever crosses it. more detail sits on the security page.

download remynd for mac and keep the next agent install from demanding full disk access you do not need.

common questions

what did apple change about full disk access for ai agents? +
on october 2, 2026 apple said it will introduce additional controls so apps can get full disk access only with very explicit user action. it tied the change to rising risk from capable, autonomous ai agents, without naming a macos version or ship date.
should you still grant full disk access to ai agents on mac? +
only when you need a backup-style job that cannot work with narrower grants, and only after you understand the app can read files, mail, messages, and browsing history. for most chat-style agents, refuse fda and use screen recording or focused-window tools instead.
what can an app with full disk access read? +
apple's privacy settings describe full disk access as access to all files on the mac, including data from other apps such as mail, messages, safari, and home, plus time machine backups and some admin settings. that is why apple calls it an extraordinary grant.
did apple name meta or muse in the announcement? +
no. the october 2, 2026 developer news post does not name meta, muse, or any other product. press pieces about muse and messages are useful context, but they are not apple's stated target.
when do the new full disk access controls ship? +
apple has not published a macos version, api change, or rollout date. as of october 2026 the company has only committed to additional controls and clearer risk disclosure before users grant the permission.