# Why Apple Rewrote Full Disk Access for AI Agents: Permission Is a Lease, Judgment Is per Action

> Source: <https://dev.to/scriptmasterlabs01/why-apple-rewrote-full-disk-access-for-ai-agents-permission-is-a-lease-judgment-is-per-action-503j>
> Published: 2026-10-05 13:37:48+00:00

On October 2, 2026, Apple announced "additional controls" for macOS Full Disk Access — going forward it can only be granted with "very explicit user action." Apple's verbatim reason: *"Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems — including files, mail, messages, and even browsing history — without users' full knowledge and understanding."*

The reported trigger: Inc. columnist Jason Aten said Meta's Muse agent surfaced Apple Messages content without that scope; Meta disputed it (TechCrunch via intelligibberish, Oct 3). Apple gave no rollout date. Late 2025, Microsoft did the same thing on Windows 11 (reversed Agent Workspace's default folder access after backlash).

One line from the autonainews write-up names the whole failure mode:

An app abusing broad access doesn't necessarily do anything that exceeds what it was authorised to do — it just does **more of it**, or more sensitive versions of it, than a user would have agreed to if asked directly.

Apple's fix detects the *behavior class* — a shift toward autonomous agent behavior triggers re-authorization — and re-asks. That's a consent upgrade. But after the user re-taps "Allow," the 3 a.m. sweep of ~/Documents + the Messages DB + browsing history still passes every check, because every read is still technically authorized. **Apple detects the class; nobody scores the instance.**

The three layers:

Scored against the live decision gate at `https://scriptmasterlabs.com/api/harness/decide` (local-heuristic-v1, bands ≥0.80 auto / 0.50–0.79 confirm / <0.50 escalate), October 5, 2026 ~09:31 EDT:

Honest finding: the uncalibrated heuristic can't discriminate the exfiltration sweep from the user-requested read — both escalate. Fail-closed and safe, but it would block the tax summary too. A calibrated decider (TypeSafe's Jev class) is the upgrade. And note: the sweep's app *already passed* Apple's re-authorization. Layers 1 and 2 let it through. Only a per-action layer even asks the question.

Full canonical with dated receipts, the permission-vs-judgment table, Claim Receipts, and FAQ: [https://scriptmasterlabs.com/apple-full-disk-access-ai-agents](https://scriptmasterlabs.com/apple-full-disk-access-ai-agents)

Related: [decision-gated payments](https://scriptmasterlabs.com/decision-gated-payments) · [FTC AI agent liability](https://scriptmasterlabs.com/ftc-ai-agent-liability) · [continuous intent verification](https://scriptmasterlabs.com/continuous-intent-verification-ai-agents)
