Apple is adding stricter approval steps to one of macOS’s broadest permissions, citing AI agents as the reason.
In a developer post titled “Updates to Full Disk Access in macOS,” published October 2, 2026, Apple said granting an app Full Disk Access will soon require “very explicit user action.” The company tied the move directly to autonomous software, warning that “as AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.”
Full Disk Access, originally meant for backup tools, “largely sidesteps” macOS privacy controls and can expose files, mail, messages, and browsing history. An agent holding that grant inherits all of it.
For enterprise and federal teams, the framing matters more than the feature. Apple is treating autonomous agents as elevated-risk processes that need endpoint containment. This gives security architects a concrete baseline for agent-permissioning policies instead of relying on vendor assurances. It also suggests the next governance layer for agentic AI sits on the device, alongside network and cloud API controls that Zero Trust programs already cover.
One caution: Apple’s post gives no macOS version, no rollout date, and no specific entitlement or permission-flow mechanism. The secondary tracker CellCog confirmed no beta or release-note documentation had appeared as of October 4, 2026. Implementation details remain unverified.
Teams piloting agents on Mac fleets should inventory which apps currently hold Full Disk Access before the stricter flow ships to avoid workflow breakage.



Leave a Reply