cd /news/ai-agents/why-apple-rewrote-full-disk-access-f… · home › topics › ai-agents › article
[ARTICLE · art-145406] src=dev.to ↗ pub= topic=ai-agents verified=true sentiment=· neutral

Why Apple Rewrote Full Disk Access for AI Agents: Permission Is a Lease, Judgment Is per Action

Apple announced on October 2, 2026 that macOS Full Disk Access will require "very explicit user action," citing developers who expose files, mail, messages and browsing history without users' full knowledge; the reported trigger was Meta's Muse agent surfacing Apple Messages content, which Meta disputed. A Scriptmaster Labs analysis argues Apple's behavioral-class detection only forces re-authorization, so an agent's 3 a.m. sweep of ~/Documents, the Messages database and browsing history still passes every check because each read remains technically authorized, and its uncalibrated local heuristic could not distinguish that sweep from a user-requested read, escalating both.

by read2 min views1 publishedOct 5, 2026

On October 2, 2026, Apple announced "additional controls" for macOS Full Disk Access — going forward it can only be granted with "very explicit user action." Apple's verbatim reason: "Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems — including files, mail, messages, and even browsing history — without users' full knowledge and understanding."

The reported trigger: Inc. columnist Jason Aten said Meta's Muse agent surfaced Apple Messages content without that scope; Meta disputed it (TechCrunch via intelligibberish, Oct 3). Apple gave no rollout date. Late 2025, Microsoft did the same thing on Windows 11 (reversed Agent Workspace's default folder access after backlash).

One line from the autonainews write-up names the whole failure mode:

An app abusing broad access doesn't necessarily do anything that exceeds what it was authorised to do — it just does more of it, or more sensitive versions of it, than a user would have agreed to if asked directly.

Apple's fix detects the behavior class — a shift toward autonomous agent behavior triggers re-authorization — and re-asks. That's a consent upgrade. But after the user re-taps "Allow," the 3 a.m. sweep of ~/Documents + the Messages DB + browsing history still passes every check, because every read is still technically authorized. Apple detects the class; nobody scores the instance.

The three layers:

Scored against the live decision gate at https://scriptmasterlabs.com/api/harness/decide (local-heuristic-v1, bands ≥0.80 auto / 0.50–0.79 confirm / <0.50 escalate), October 5, 2026 ~09:31 EDT:

Honest finding: the uncalibrated heuristic can't discriminate the exfiltration sweep from the user-requested read — both escalate. Fail-closed and safe, but it would block the tax summary too. A calibrated decider (TypeSafe's Jev class) is the upgrade. And note: the sweep's app already passed Apple's re-authorization. Layers 1 and 2 let it through. Only a per-action layer even asks the question.

Full canonical with dated receipts, the permission-vs-judgment table, Claim Receipts, and FAQ: https://scriptmasterlabs.com/apple-full-disk-access-ai-agents

Related: decision-gated payments · FTC AI agent liability · continuous intent verification

── more in #ai-agents 4 stories · sorted by recency
── more on @apple 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/why-apple-rewrote-fu…] indexed:0 read:2min 2026-10-05 · —