# Apple is changing Full Disk Access in macOS

> Source: <https://sixcolors.com/post/2026/10/apple-is-changing-full-disk-access-in-macos/>
> Published: 2026-10-05 13:22:52+00:00

### By Dan Moren

# Apple is changing Full Disk Access in macOS

In [a post on Apple’s Developer News site](https://developer.apple.com/news/?id=p6zjojqw), the company says it will be updating the Full Disk Access permissions:

Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action. Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.

Nick Heer has [a detailed analysis of this announcements](https://pxlnv.com/blog/macos-full-disk-access-restrictions/), though, as he points out, it’s impossible to make any conclusive judgments as we don’t yet know exactly what these “additional controls” will look like. But the reactions from [some developers whose apps rely on this permission](https://mas.to/@dnanian/117376817070514189) were wary, at best.

Security and convenience are a tough line to walk, there’s no question. The competing models of macOS and iOS take very different approaches to the idea of, oh, let’s call it “messing around and finding out.” Even giving an app access to every single permission on iOS—unwise as it might be—can’t touch certain parts of the system; that’s not true on the Mac. But, on the flip side, it unlocks a possibilities for apps on your Mac that simply aren’t possible on the iPhone.

Specifically, as Apple calls out here, AI agents. The AI agents that you can use on your phone can get access to information that you granularly share with them, but there are limits. An AI agent will Full Disk Access to your Mac is capable of much more. If I can draw an imperfect analogy, it’s akin to giving the agent power of attorney to act autonomously on your behalf, without your full knowledge. At least until after the fact.

But there are plenty of legit uses for Full Disk Access. Just looking at my MacBook Air this morning, I’ve given that permission to three apps<sup>[1](#fn-41717-daemons)</sup>: Terminal, BBEdit, and SuperDuper. All apps that I trust with that level of power because of their long history and because in order to do what they do best (or at all), they need that access.<sup>[2](#fn-41717-trusted)</sup> (Interestingly, on my Mac mini, that list also includes SpamSieve, [KnockKnock](https://objective-see.org/products/knockknock.html), and Shortcuts—though not BBEdit, for whatever reason.)

As Nick explains, this move was likely a response to [Jason Aten’s recent story in Inc.](https://www.inc.com/jason-aten/metas-new-muse-ai-agent-read-my-private-messages-i-never-asked-it-to/91408202) about Meta’s Muse having access to his Messages, despite supposedly not permitting it.<sup>[3](#fn-41717-confusing)</sup> But it’s also a recognition that this is going to become more and more of an issue as AI agents become more commonplace, and no doubt ask for Full Disk Access, because these kind of apps want as much power and information as you will give them, and it’s far more efficient for *them* if they can just ask for disk access than enumerating all the individual data stores. Especially, in an era where [we’re besieged by permission dialogs](https://sixcolors.com/post/2023/11/a-picture-is-worth-a-thousand-permissions-requests/).

I don’t think Apple has done the best job with its permissions user experience—it surely could be improved. But I also have to admit that my own behavior has changed over time as Apple has instituted more and more granular controls. Perhaps it was simply the callowness of youth, but I was once far more willing to grant permissions to apps I installed<sup>[4](#fn-41717-wildwest)</sup>—these days, I find myself scrutinizing them more and more: Why do you need Bluetooth access, app? What devices on my local network are you really accessing? My default is to not allow things, unless I have a very clear understanding of why the app is requesting them—and, in the cases where I am overly cautious and impeded an app’s functionality, going and turning on permission I disabled.

But I also realize that I’m hardly the average user. I think there *is* a good argument for protecting Full Disk Access further, but there’s also only so much you can do to protect a user from themselves. Ultimately, this is a cat-and-mouse game, and while I don’t want my data purloined or misused, I also don’t want my computer locked down to the point that I can’t use it for all the things I want to do.

1. 
The Privacy & Security panel also shows that two system level processes have access: `smbd` , the file-sharing daemon, and sshd-keygen-wrapper, which helps manage the remote login protocols.[↩](#fnref-41717-daemons)
2. 
Perhaps another argument for the existence of some sort of [trusted developer program](https://lexontech.org/the-app-store-review-process-needs-fixing) ?[↩](#fnref-41717-trusted)
3. 
The story here, as several people have noted, is a little confusing; it’s unclear exactly how this happened. [↩](#fnref-41717-confusing)
4. 
It was also the earlier days of computing, when our devices were neither as capable nor as far-reaching in their data as they are now. [↩](#fnref-41717-wildwest)

[***Dan Moren** is the East Coast Bureau Chief of Six Colors, as well as an author, podcaster, and two-time Jeopardy! champion. You can find him on Mastodon at [@dmoren@zeppelin.flights](https://zeppelin.flights/@dmoren) or reach him by email at dan@sixcolors.com. His next novel, the sci-fi adventure [Eternity's Tomb](https://dmoren.com/eternitys-tomb/), will be released in November 2026.*]

**If you appreciate articles like this one, support us by [becoming a Six Colors subscriber](https://sixcolors.com/subscribe/). Subscribers get access to an exclusive podcast, members-only stories, and a special community.**
