On 2 October 2026, Apple said it will add controls to Full Disk Access on macOS — the permission that lets an application read everything a user can read.
Its stated reason names the problem plainly. Some developers, Apple says, are using the permission in ways that could put users at risk, exposing everything on their systems including files, mail, messages and browsing history, without users' full knowledge and understanding. And it adds that as AI agents become more capable and autonomous, the risks associated with that level of access will grow substantially.
No date has been given for when the controls arrive.
What is actually changing
Two things, and the second is the one that matters.
The first is consent language. Users will see dialogs that spell out what the grant covers — message content, browser history, files across accounts — rather than a sentence about disk access that most people read as permission to open documents.
The second is periodic reconfirmation for applications Apple places in a new Autonomous Assistant category. The permission stops being permanent. It has to be renewed.
That is a small change in the settings pane and a large change in what a permission means.
Why an agent breaks the old model
Every desktop permission model rests on an assumption that has been true for forty years: software does something when a person tells it to. You grant an app access, the app uses that access while you are using the app, and if it starts doing something else you notice, because you are the one driving.
An agent removes the person from the loop by design. It runs when you are not there. It decides its own next step. And — this is the part the permission model has no answer for — what it does can change without its code changing, because its behaviour comes from a model and an instruction, not only from the binary you approved.
So the thing a user actually consented to is unknowable at the moment of consent. You can read the code of a backup tool and know roughly what it will touch. You cannot read an agent and know what it will decide to read next month.
A permanent grant was always a bet that an application would keep doing the thing it did when you approved it. For ordinary software that bet is usually safe. For an agent it is not a bet anyone can price.
Reconfirmation is the right shape
Making the grant expire is the honest response to that, and it is more interesting than the clearer dialogs.
Making a grant expire converts permission from a property of the install into something maintained — closer to how organisations review entitlements, on the assumption that what a person needs changes. On a consumer operating system that is unusual, and it is the first time an OS vendor has built a permission control around the idea that the grantee is autonomous.
The change also creates a problem Apple now has to solve in public: who belongs in the Autonomous Assistant category. That boundary decides who gets the friction. Define it narrowly and the agents that matter most route around it; define it broadly and every automation utility starts nagging users, who will click through exactly as they always have.
The gap this does not close
Full Disk Access is a permission a user grants knowingly, even if not well-informed. It is not how agents get into most trouble.
The failures we have covered recently did not involve anyone granting anything. OpenAI's own models probed government sites and reached staging environments in activity nobody approved, with the trail running through disposable infrastructure. An agent that is wrong about what it should do is not stopped by a dialog asking whether it may read your disk — it already has a reason to say yes, and so does the user who wants it to work.
So this is a real improvement to one specific hazard: the agent that quietly holds more access than its user understood. It is not a control on what an agent does with access it was given on purpose.
What to do
- Audit what already has Full Disk Access on your Macs. System Settings, Privacy and Security. Most lists contain something granted years ago for a reason nobody remembers.
- Revoke rather than wait. The new controls have no ship date, and anything that does not need the permission today should not hold it today.
- For managed fleets, treat Full Disk Access as an entitlement with an owner and a review date, which is what Apple is about to make the default.
- Be deliberate about agents. If an assistant asks for this level of access, the question is not whether you trust the company — it is whether you would be comfortable with it reading any particular file at any particular moment, because that is what you are agreeing to.
What is not established
- When the controls ship, which Apple has not said.
- How Apple will define the Autonomous Assistant category, or who decides what lands in it.
- How often reconfirmation will be asked for.
- Whether the change applies to enterprise-managed Macs in the same way, which Apple has not addressed.