Apple is set to strengthen the safeguards surrounding ‘Full Disk Access’ on Macs, precisely because AI agents make this permission much riskier. The company has announced future controls requiring particularly explicit user action before an application can gain access that could expose files, emails, messages, browsing history and certain administrative data.
The measure was announced on 2 October 2026. However, Apple has not specified which version of macOS is affected, when it will be available, or exactly what form the new confirmations will take. It is therefore an officially announced development, but not yet a feature whose public rollout can be verified.
For creators, consultants, trainers and small businesses using an AI agent on their Mac, the right course of action is not to wait for future protection. It is to check straight away which apps already have ‘Full Disk Access’ and to revoke this permission where it is not justified by their use.
Information verified on 3 October 2026. Apple’s announcement is global and makes no mention of any country-specific restrictions.
What Apple has actually just announced
In a note published on its developer portal, Apple explains that its powerful APIs are normally accompanied by controls designed to protect private data. Full Disk Access is a significant exception, as this permission bypasses many of the usual safeguards to allow certain categories of apps, notably backup software, to function correctly.
Apple notes, however, that some developers are using this permission in a way that may expose users to risks they do not fully understand. The company cites files, emails, messages and browsing history. It adds that, for a messaging app, this access may also compromise the privacy of the people with whom the user is communicating.
Apple explicitly links this decision to the rise of AI agents:
The company therefore plans to introduce controls to ensure that an app can only be granted this permission following a very explicit user action.
There are three distinct states:
This announcement is not a disclosure of a specific attack and does not mean that an AI agent has compromised all Macs. Apple describes an architectural risk: a permission designed for a few powerful uses becomes more sensitive when software is capable of planning and chaining actions with greater autonomy.
What does ‘Full Disk Access’ actually do?
The name may seem abstract. According to Apple’s documentation, Full Disk Access allows an app to access all files on the computer, including data from other apps such as Mail, Messages, Safari and Home. It may also cover Time Machine backups and certain administrative settings relating to Mac users.
This permission is much broader than simply allowing access to the ‘Downloads’ folder or to a document selected by the user.
macOS has several categories of permissions which should not be confused:
An agent may request several of these permissions. Each must be assessed separately. Removing ‘Full Disk Access’ does not automatically revoke accessibility, automation or screenshot permissions.
Conversely, an application with Full Disk Access does not automatically become malicious. Backup, security, administration or migration tools may have a legitimate reason for reading a large number of files.
So the right question isn’t: ‘Is this app well-known?’ It is: ‘Does the function I’m using really need access to all this data?’
Why AI agents are changing the level of risk
A traditional application generally carries out a set of functions specified by its developer. An AI agent, on the other hand, can be given a much broader objective, decide on the intermediate steps, explore files, open tools and then adjust its plan based on what it discovers.
This flexibility is what makes it valuable. It also broadens the possible consequences of an ambiguous instruction, an error in reasoning or malicious content encountered by the agent.
Let’s imagine a simple instruction:
With a folder explicitly selected and read-only access, the scope is relatively clear. With Full Disk Access, the agent may technically come across email archives, contracts, identity documents, browsing histories, backups or documents that are completely unrelated to the assignment.
The risk does not stem solely from what the application intends to do. It also depends on what it is capable of doing if a page, an email or a document attempts to hijack its behaviour. A command hidden within content may seek to persuade the agent to copy information, open another file or alter its purpose. This type of attack is often referred to as a prompt injection.
The strongest form of protection remains the principle of least privilege: granting access only to the data, files and actions strictly necessary for the task at hand.
Two practical scenarios for creators and freelancers
A designer entrusts their archives to a content manager
A videographer wants their agent to analyse their transcripts, identify the best clips and prepare a series of posts. The app requests Full Access to the disk to automatically search for all available files.
‘Accept’ seems convenient. However, useful transcripts can be placed in a dedicated folder. There is no need for the agent to also be able to read personal emails, Messages conversations, administrative documents or Mac backups.
The best approach is to create a working folder, copy only the necessary content into it, and allow the application to use this folder if it supports it. The agent prepares the texts; the creator validates the information and authorises publication.
Approved content can then link to a LinkHub VIFLY to centralise resources, networks and services, without giving the agent full access to the computer.
A consultant uses an agent to organise her appointments
A consultant would like to receive, before each meeting, a summary of the prospective client, previous correspondence and documents relating to the assignment. Her Mac also contains contracts from other clients, invoices, family information and saved login details.
Full access to the drive would transform a targeted need into potentially cross-functional access. A more cautious approach involves using one directory per client, separating personal and work data, and then exposing only the folders necessary for preparation.
When the prospective customer wishes to make a booking, VIFLY Booking can provide a structured workflow without granting the agent the right to browse all local data. Booking, preparation and access to documents remain three separate permissions.
These examples illustrate a general rule: the more sensitive the information, the more explicit and easily revocable the scope must be.
A structured public presence on VIFLY also allows you to separate information intended for prospective clients from confidential working documents stored on the computer.
How to check your Mac’s permissions straight away
You don’t need to wait for the future update announced by Apple. An initial audit can be carried out in just a few minutes.
After each change, test the relevant workflow. If the application stops working, do not automatically re-enable all permissions: check its documentation, look for a restricted mode, or choose a tool with better isolation.
For teams, this audit must be documented. It is essential to know who approves access, for how long, for what purpose, and how to revoke it when an employee or a tool no longer requires it.
Nuances and points to bear in mind
First point to note: Apple has not announced either a date or a version of macOS. It would be incorrect to state that the new protection has already been rolled out, that it will be included in a specific update, or that it will automatically block all AI agents.
Second point: the announcement is aimed at full disk access in general. Apple cites the rise of agents to explain the urgency, but the future controls are not presented as a feature reserved solely for AI applications.
Third point: a more explicit confirmation improves consent without eliminating the risk. A user may still authorise an app out of habit, under pressure or without understanding the true scope of the access.
Fourth point: removing local access does not control what has already been sent to a cloud service. You should also check the tool’s privacy policy, retention period, connected services and deletion options.
Finally, a permission may be legitimate at the time of installation but subsequently become unnecessary. Software used once to migrate data does not necessarily need to retain full access indefinitely.
Agent security is therefore not limited to a confirmation screen. It combines minimum permissions, data segregation, human validation, logging and regular review.
The blog VIFLY will continue to monitor these developments, distinguishing between security measures already available and those that have merely been announced.
FAQ on AI agents and Full Disk Access
Has Apple already rolled out the new controls?
No. Apple announced them on 2 October 2026 without specifying their release date, the relevant version of macOS or their final interface.
What is Full Disk Access on a Mac?
This is a very broad permission that can allow an app to access files on the Mac, data from other apps, Time Machine backups and certain administrative settings.
Where can I check this permission?
Open System Preferences, Privacy & Security, then Full Disk Access. The list shows the apps that are authorised or have been added to this category.
Should this permission be revoked for all AI applications?
No, not blindly. You need to check whether the function being used actually requires this level of access. Where restricted access to a folder is sufficient, ‘Full Disk Access’ is generally disproportionate.
Does disabling access delete data that has already been sent?
No. Disabling this feature restricts future access on the Mac, but does not automatically delete data previously transferred or stored in a cloud service.
Could a backup application need this level of access?
Yes. Apple specifically cites backup apps as an example of a use case that may require extensive disk reading. You should check the function before revoking authorisation.