Why Apple Rewrote Full Disk Access for AI Agents: Permission Is a Lease, Judgment Is per Action Apple announced on October 2, 2026 that macOS Full Disk Access will require "very explicit user action," citing developers who expose files, mail, messages and browsing history without users' full knowledge; the reported trigger was Meta's Muse agent surfacing Apple Messages content, which Meta disputed. A Scriptmaster Labs analysis argues Apple's behavioral-class detection only forces re-authorization, so an agent's 3 a.m. sweep of ~/Documents, the Messages database and browsing history still passes every check because each read remains technically authorized, and its uncalibrated local heuristic could not distinguish that sweep from a user-requested read, escalating both. On October 2, 2026, Apple announced "additional controls" for macOS Full Disk Access — going forward it can only be granted with "very explicit user action." Apple's verbatim reason: "Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems — including files, mail, messages, and even browsing history — without users' full knowledge and understanding." The reported trigger: Inc. columnist Jason Aten said Meta's Muse agent surfaced Apple Messages content without that scope; Meta disputed it TechCrunch via intelligibberish, Oct 3 . Apple gave no rollout date. Late 2025, Microsoft did the same thing on Windows 11 reversed Agent Workspace's default folder access after backlash . One line from the autonainews write-up names the whole failure mode: An app abusing broad access doesn't necessarily do anything that exceeds what it was authorised to do — it just does more of it , or more sensitive versions of it, than a user would have agreed to if asked directly. Apple's fix detects the behavior class — a shift toward autonomous agent behavior triggers re-authorization — and re-asks. That's a consent upgrade. But after the user re-taps "Allow," the 3 a.m. sweep of ~/Documents + the Messages DB + browsing history still passes every check, because every read is still technically authorized. Apple detects the class; nobody scores the instance. The three layers: Scored against the live decision gate at https://scriptmasterlabs.com/api/harness/decide local-heuristic-v1, bands ≥0.80 auto / 0.50–0.79 confirm / <0.50 escalate , October 5, 2026 ~09:31 EDT: Honest finding: the uncalibrated heuristic can't discriminate the exfiltration sweep from the user-requested read — both escalate. Fail-closed and safe, but it would block the tax summary too. A calibrated decider TypeSafe's Jev class is the upgrade. And note: the sweep's app already passed Apple's re-authorization. Layers 1 and 2 let it through. Only a per-action layer even asks the question. Full canonical with dated receipts, the permission-vs-judgment table, Claim Receipts, and FAQ: https://scriptmasterlabs.com/apple-full-disk-access-ai-agents https://scriptmasterlabs.com/apple-full-disk-access-ai-agents Related: decision-gated payments https://scriptmasterlabs.com/decision-gated-payments · FTC AI agent liability https://scriptmasterlabs.com/ftc-ai-agent-liability · continuous intent verification https://scriptmasterlabs.com/continuous-intent-verification-ai-agents