How the high-risk permission will change
Apple told developers that Full Disk Access in macOS largely bypasses normal separation between apps. Backup software may need it, but the same permission can expose files, mail, messages and browsing history without the user fully understanding the consequences. [1 · Apple Developer · Full Disk Access update, October 2, 2026] [3 · The Verge · explanation of the new Full Disk Access limits]
The company plans controls that will grant this reach only after especially explicit user action. It disclosed neither a technical design nor a release date. Developers therefore have a policy direction, not a new API or binding schedule. [1 · Apple Developer · Full Disk Access update, October 2, 2026] [3 · The Verge · explanation of the new Full Disk Access limits]
Why the announcement is tied to Muse
The move followed a columnist’s complaint that Meta Muse referred to private messages even though he believed access had not been granted. Reuters[1] and The Verge stress that the circumstances remain disputed and no public technical investigation has settled them. [2 · Reuters · Mac protection change after Muse complaints, October 2, 2026] [3 · The Verge · explanation of the new Full Disk Access limits]
Meta rejected the idea of hidden access. Its spokesperson said Muse can read Messages only when a user enables both Full Disk Access and a Messages connector, and that permission can be revoked. That position does not establish which steps occurred in the disputed case. [2 · Reuters · Mac protection change after Muse complaints, October 2, 2026] [3 · The Verge · explanation of the new Full Disk Access limits]
Sources
- Apple Developer · Full Disk Access update, October 2, 2026 — Primary statement on full-disk-access risks and the additional controls Apple plans to introduce.
- Reuters · Mac protection change after Muse complaints, October 2, 2026 — Context for Apple’s decision, the user allegation and Meta’s position that access is opt-in.
- The Verge · explanation of the new Full Disk Access limits — Independent description of the permission, affected data and the absence of a launch date.
Expert commentary
The established fact is Apple’s recognition that Full Disk Access is exceptional and needs another barrier. It is not established that Muse bypassed protection: the user and Meta disagree about consent, and no independent forensic account is public. This is a permissions-design event, not proof of a breach. [1 · Apple Developer · Full Disk Access update, October 2, 2026] [2 · Reuters · Mac protection change after Muse complaints, October 2, 2026] [3 · The Verge · explanation of the new Full Disk Access limits]
AI agents amplify the mechanism of harm. Conventional software uses broad access for a known function such as backup. An agent receives an open-ended goal and chooses actions; an email, message or web page may influence those choices. More data and tools make mistakes costlier and boundaries harder to predict. [1 · Apple Developer · Full Disk Access update, October 2, 2026] [3 · The Verge · explanation of the new Full Disk Access limits]
An extra confirmation can reduce accidental grants, but a dialog alone is insufficient. Users often cannot tell which folders and databases an agent truly needs. A stronger architecture grants narrow, time-limited access, displays an audit trail and lets people revoke one connector without disabling the entire product. [1 · Apple Developer · Full Disk Access update, October 2, 2026] [3 · The Verge · explanation of the new Full Disk Access limits]
Developers may face redesign costs. Products built around the whole disk will need to justify access, separate functions and handle refusal. Vendors that operate with least privilege gain trust and an advantage in enterprise procurement. Buyers will ask what was read, how long it is retained and whether it trains models. [1 · Apple Developer · Full Disk Access update, October 2, 2026] [2 · Reuters · Mac protection change after Muse complaints, October 2, 2026] [3 · The Verge · explanation of the new Full Disk Access limits]
Organizations can act before Apple ships anything: deny persistent Full Disk Access to agents by default. Run pilots in separate accounts with test data, approved connectors and logging. Labor savings are meaningful only after verifying that a changed task does not silently broaden the data boundary. [1 · Apple Developer · Full Disk Access update, October 2, 2026] [3 · The Verge · explanation of the new Full Disk Access limits]
Watch the confirmation design, data-level controls, action logs, release timing and developer response. The Muse case also needs a reproducible technical account. Another warning dialog would have limited effect; granular and temporary permissions could establish a more useful desktop-agent standard. [1 · Apple Developer · Full Disk Access update, October 2, 2026] [2 · Reuters · Mac protection change after Muse complaints, October 2, 2026] [3 · The Verge · explanation of the new Full Disk Access limits]