Apple said on October 2, 2026 that it will add controls around Full Disk Access in macOS, arguing that some developers use the permission in ways that expose files, mail, messages and browsing history. The warning appeared in a Developer News post titled "Updates to Full Disk Access in macOS". The company said risks from this level of access will grow substantially as AI agents become more capable and autonomous. For business, this signals tighter limits on tools that read across the whole Mac.
Why Apple is changing Full Disk Access
According to Apple, Full Disk Access largely bypasses the controls behind its developer APIs so backup applications can work properly on the Mac. Some developers, the company said, use the permission in ways that could put users at risk by exposing everything on their systems without full knowledge and understanding. When the apps handle communications, Apple added, the exposure can extend to the privacy of other people involved in those exchanges. The post gives no date or macOS version for the change and names no developer or app.
Future grants of this access will require what Apple called "very explicit user action" from people who genuinely want to allow it. The company called addressing the issue critical and said users should clearly understand the risks before granting such access. The stated goal is informed decisions about personal data and privacy. The mechanism of the new confirmation step, its wording and the number of screens were not described in the post.
The setting already sits in System Settings under Privacy & Security, where adding an app requires clicking Add, selecting the app and clicking Open. Apple's Mac User Guide says the permission opens all files on the computer, including data from Mail, Messages, Safari and Home, Time Machine backups and certain administrative settings for all users. A separate Files & Folders category covers narrower requests for files in different locations. Since macOS 10.13, full-storage access has required an explicit addition in System Settings or System Preferences.
What this means for companies using Macs
For companies that rely on Mac utilities, backup products, search tools and AI assistants, the practical effect is more friction at installation and support. Broad file reading will remain possible, but only after a deliberate action by the user rather than a routine prompt from the app. Small firms without centralized setup may face more help-desk questions during onboarding. Large fleets can continue using the Privacy Preferences Policy Control payload with identifier com. apple. TCC. configuration-profile-policy to manage Privacy pane settings.
Managed deployment keeps its own constraints that buyers should verify before renewing agent-style software. The payload requires user approval, installation through a device management service and supervision for some enrollment routes, while overlapping payloads resolve toward the more restrictive settings. A custom entry for System Policy All Files needs a bundle ID or file path, an allow or deny value and a code-signing requirement obtainable with codesign -dr -. Apple notes that each device management developer implements these settings differently.
The marker to watch is the follow-up specification of the new consent step: the macOS version, release timing and documentation for managed devices. If Apple publishes those details and updates the Platform Security and Platform Deployment guides, vendors will need to revise install flows and administrator instructions. That publication will show whether broad Mac access for AI agents stays an exception or becomes a tightly controlled path.
