
Apple’s Full Disk Access Reckoning: AI Agents Need Smaller Keys
The best desktop AI agent isn’t the one with access to everything. It’s the one that earns access to exactly what it needs.
That runs against the current pitch: connect your files, messages, mail, and browser history, then watch the magic happen. I’m genuinely excited about assistants that can work across a development project instead of making me paste context into a chat window. But handing one my entire digital history? That’s a spectacularly expensive shortcut to better autocomplete.
On October 2, 2026, Apple announced stronger consent controls for macOS Full Disk Access. Good. The interesting opportunity here isn’t a scarier warning dialog. It’s better agent architecture.
A backup permission meets an autonomous assistant
Apple’s developer announcement explains that Full Disk Access largely bypasses privacy controls so applications such as backup tools can function. Some developers, Apple says, are using it to expose files, mail, messages, and browsing history without sufficiently informed consent.
Apple promises additional controls requiring:
<> “very explicit user action”/>
Its stated concern is that increasingly capable, autonomous AI agents make broad access riskier.
This is not a ban on desktop agents. Apple has published no release date, target macOS version, new API, or migration rules. Expiring grants and approval for every operation are not announced features.
Also, Full Disk Access doesn’t mean root access. POSIX permissions, access-control lists, and other protections still apply. But “not literally omnipotent” is a pretty low bar for software reading your personal life.
The Elephant in the Room
Meta’s Muse hangs over this announcement, even though Apple names no developer.
Inc. columnist Jason Aten accused Muse of reading private Messages content and said he hadn’t enabled Full Disk Access. Meta spokesperson Andy Stone disputed that account: according to Meta, Muse requires both the macOS permission and its own Messages connector, and access is revocable. Reuters reported those competing accounts; Apple’s post does not resolve them.
Security researcher Patrick Wardle raised the deeper architectural issue: an application’s connector setting and the operating system’s permission are different boundaries. A product toggle describes intended behavior. The OS grant defines underlying capability.
That’s where my skepticism kicks in. “Our assistant won’t read that” is weaker than “our assistant cannot read that.”
Separately, Ars Technica reported a Muse vulnerability on September 21 involving a transcription endpoint, authentication-token exposure, and control of the assistant. Meta released a hotfix. That incident was separate from the Messages dispute, but it illustrates why securing broad-access agents requires more than good onboarding copy.
Give the agent a project, not a biography
Here’s the part that excites me: macOS already supports a more useful starting point for document-oriented assistants—user-selected files and folders.
Sandboxed apps can preserve authorized access with security-scoped bookmarks. The implementation has concrete machinery:
- Create persistent bookmarks with
withSecurityScope. - Resolve them and handle stale bookmarks.
- Pair
startAccessingSecurityScopedResource()withstopAccessingSecurityScopedResource(). - Use read-only access when writing isn’t needed.
These aren’t universal replacements for protected databases or communication integrations. But a coding assistant working inside a selected repository is a compelling product, not a consolation prize.
I’d rather install an agent that says “choose the project I can help with” than one that demands my messages before demonstrating anything useful.
Keep the Mac powerful—and the consent honest
John Gruber’s October 2 Daring Fireball essay raises a legitimate concern: stronger protection shouldn’t make backup tools and power-user workflows impractical. I agree. Repeated permission nagging would be miserable design, and Apple hasn’t announced it.
The sharper challenge is making consent understandable without disabling capable software. Developers should support denial, explain data categories plainly, and keep reduced-function modes useful.
Apple also flags something onboarding screens routinely ignore: your correspondents have privacy interests too. Your permission exposes their words.
Desktop agents can become fantastic tools. But the permission to help with my work shouldn’t quietly become permission to ingest everyone who has ever emailed me.

