Apple says it is tightening macOS Full Disk Access — new controls requiring very explicit user action — because AI agents substantially raise the risks of full-system access, and whether these controls ship and become the baseline platform containment that desktop agent products and security guidance build on, or remain developer-blog rhetoric, resolves the episode.
state: corroboratedheat: lowuncertainty: mediumconvergesscott: highagentic-security macos-containment agent-sandboxingApple
Surfaced 2026-10-04T13:50:37Z — Apple tells developers that some are using Full Disk Access in ways that 'could put users at risk' and that 'as AI agents become increasingl — The main thread's 273→302/212 drift recycles the same skepticism themes (iOS-ification, 'users don't read prompts', 'one update from revocation') with no new facts on ship timing, mechanical delta, or adoption; the speedometer has flatlined (~0 pts/h, 14th percentile at 67h) and no new outlet, implementation, or community has appeared since Ars — the magnitude-valve flag reads the already-priced peak spread, not present motion, so heat cools to low. Meaning unchanged: announced platform policy explicitly attributed to agent risk, carried by the ship/mechanics/baseline-adoption watch.
What is this?
On October 2, 2026, Apple published a first-party developer notice stating it will add new controls to macOS Full Disk Access (FDA) requiring "very explicit user action" to grant the permission, explicitly attributing the change to AI agents: "as AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially." The notice cites some developers already using FDA in ways that "could put users at risk," exposing files, mail, messages, and browsing history. Independent coverage from TechCrunch, The Verge, Bloomberg, Ars Technica, and a 317-point Hacker News thread corroborates the announcement and Apple's stated agent-risk rationale; Apple declined TechCrunch's request for specifics. The ship vehicle (macOS version), mechanical delta over the existing admin-gated FDA grant flow, and whether desktop agent products (Muse, ChatGPT Mac) and security guidance adopt these controls as a baseline containment layer remain unresolved.
Why it matters to Scott
Apple — the most consequential desktop platform vendor — has enacted at OS level, explicitly attributing to agent risk, the exact containment posture Scott's SiloOS framework and Architecture, Not Vibes doctrine argue for ('can't beats shouldn't'). This is dated-receipts validation from the platform itself. The unresolved ship/mechanics/adoption watch directly bears on OpenClaw's macOS sandboxing model and LeverageAI's security guidance baseline: if these controls ship and harden into the platform containment floor, Scott's desktop-agent architecture and advisory baseline must build against them; if they remain rhetoric, the containment gap persists.
ip:framework.siloosip:framework.architecture-not-vibesip:concept.architectural-containmentip:concept.runtime-containmentdev:project.silo-osdev:project.openclawwork:project.leverageaiip:concept.containmentdev:concept.padded-cell-agent-architectureradar:aegis-inline-ebpf-agent-containmentradar:amazon-blocks-meta-muse-shoppingradar:agent-substrate-sandbox-runtimeradar:agentsec-static-config-auditingradar:agentshield-offline-agent-scannerradar:agenttrust-portable-execution-recordsradar:acs-local-skill-risk-catalogradar:ai-agent-security-incidents-datasetradar:agent-acid-rollback-guardrails
queries asked of Scott's wikis
- SiloOS architectural containment 'can't beats shouldn't' platform enforcement
- OpenClaw desktop agent sandboxing macOS permissions model
- LeverageAI security guidance baseline containment layers
- agentic security macOS FDA TCC sandbox escape patterns
- model sovereignty local inference desktop agent threat model
- platform vendor containment mandates as architectural primitives
Measured heat
now 0 pts/hpeak 62 pts/hcomments 0/hpeers p16momentum: steady2 platformsage 242h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion
How the heat travelled
pace: p86 vs 1188 stories at the 168h mark (now 242h old) — ahead of isaacs-flock-alpr-lawsuit (1.0x), behind cactus-needle3-on-device-automation (1.0x)
Evidence (8) — ⭐ canonical anchor
| source | object | author | score | comments |
| 🟧 hn | Apple is tightening macOS 'Full Disk Access' due to new risks from AI agentsRetrieved article excerptOpen article · Retrieved 2026-10-02T19:30:11.942805+00:00 Days after a journalist claimed that Meta’s Muse app on Mac read their private messages — a [claim that Meta disputed](https://techcrunch.com/2026/09/30/meta-disputes-claim-that-muse-read-a-users-private-messages-without-permission/) — Apple announced that it’s introducing additional controls around a setting called “Full Disk Access” on macOS. The feature was designed to allow backups to function properly, but AI agents have now increased “the risks associated with this level of access,” Apple said.
Apple’s statement comes shortly after Inc. columnist Jason Aten [reported](https://www.inc.com/jason-aten/metas-new-muse-ai-agent-read-my-private-messages-i-never-asked-it-to/91408202) that Muse knew the content of his private messages — even though he claimed to have not given the AI agent permission. The report raised questions about the level of security and trust users have in desktop-based AI, which can control things on their systems and read their files and messages.
The decision to limit the Mac feature also comes after a [Wired report](https://www.wired.com/story/a-flaw-in-chatgpts-mac-app-could-have-let-hackers-grab-sensitive-data/) cited that a flaw in ChatGPT’s Mac app could have allowed hackers to access sensitive data.
AI agents that run on the desktop allow users to provide their respective apps with greater access to the files, messages, and other personal content on their computers by adjusting macOS settings.
In Muse’s case, the AI optionally allows users to enable Full Disk Access. This setting, Apple explains, gives an app permission to access files, mail, messages, and even browsing history.
“Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems…without users’ full knowledge and understanding,” Apple said [in a new blog post](https://developer.apple.com/news/?id=p6zjojqw) aimed at developers.
The company says that, going forward, it will introduce new controls aimed at ensuring that users who “genuinely wish to grant an app this extraordinary level of access” can do so only with “very explicit user action.”
“Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy,” Apple wrote.
Apple did not respond to TechCrunch’s inquiry about the feature change.
Topics
[AI](https://techcrunch.com/category/artificial-intelligence/), [AI agents](https://techcrunch.com/tag/ai-agents/), [Apple](https://techcrunch.com/tag/apple/), [Apps](https://techcrunch.com/category/apps/), [Meta](https://techcrunch.com/tag/meta/), [Security](https://techcrunch.com/category/security/)
*When you purchase through links in our articles, [we may earn a small commission](https://techcrunch.com/techcrunch-affiliate-monetization-standards/). This doesn’t affect our editorial independence.*
Sarah Perez
Sarah Perez
Consumer News Editor
Sarah has worked as a reporter for TechCrunch since August 2011. She joined the company after having previously spent over three years at ReadWriteWeb. Prior to her work as a reporter, Sarah worked in I.T. across a number of industries, including banking, retail and software.
You can contact or verify outreach from Sarah by emailing [email protected] or via encrypted message at sarahperez.01 on Signal.
[View Bio](https://techcrunch.com/author/sarah-perez/)
Event Logo
October 13 – 15
San Francisco
**Get 50% off a second pass**
The Disrupt experience is meant to be shared. Get your pass and bring a colleague, partner, or peer at 50% off. Cover more ground by making connections, building momentum, and discovering what’s next in the startup ecosystem.
[**BOOK NOW**](https://techcrunch.com/events/techcrunch-disrupt/?utm_source=tc&utm_medium=ad&utm_campaign=disrupt2026&utm_content=ticketsales&promo=rightrail_rbplusbogo&display=)
## Most Popular
- ### [Google thinks SpaceX’s Starship has to launch 1,800 times before space data centers get off the ground](https://techcrunch.com/2026/10/01/google-thinks-spacexs-starship-has-to-launch-1600-times-before-space-data-centers-get-off-the-ground/)
- [Tim Fernholz](https://techcrunch.com/author/tim-fernholz/)
- ### [World’s first enhanced geothermal power plant completed in just 23 months](https://techcrunch.com/2026/10/01/worlds-first-enhanced-geothermal-power-plant-completed-in-just-23-months/)
- [Tim De Chant](https://techcrunch.com/author/tim-de-chant/)
- ### [Google releases Gemini 4 Argon, called its most powerful model yet](https://techcrunch.com/2026/09/30/google-releases-gemini-4-argon-called-its-most-powerful-model-yet/)
- [Lucas Ropek](https://techcrunch.com/author/lucas-ropek/)
- ### [The Pentagon taps Elon Musk and Palmer Luckey to help decide what the military should do next](https://techcrunch.com/2026/09/30/the-pentagon-taps-elon-musk-and-palmer-luckey-to-help-decide-what-the-military-should-do-next/)
- [Dominic-Madori Davis](https://techcrunch.com/author/dominic-madori-davis/)
- ### [OpenAI launches Dots, its bubbly agentic avatar](https://techcrunch.com/2026/09/29/openai-launches-dots-its-bubbly-agentic-avatar/)
- [Lucas Ropek](https://techcrunch.com/author/lucas-ropek/)
- ### [AMD will acquire Fei-Fei Li’s World Labs for $8.2B](https://techcrunch.com/2026/09/28/amd-will-acquire-fei-fei-lis-world-labs-for-8-2-billion/)
- [Tim Fernholz](https://techcrunch.com/author/tim-fernholz/)
- ### [Viral AI agent Instinct raises $1B Series C at a $10B valuation](https://techcrunch.com/2026/09/28/viral-ai-agent-instinct-raises-1b-series-c-at-a-10b-valuation/)
- [Sarah Perez](https://techcrunch.com/author/sarah-perez/) | speckx | 20 | 8 |
| 🟧 echo.blog ⭐ | Apple tells developers that some are using Full Disk Access in ways that 'could put users at risk' and that 'as AI agents become increasingl | Apple | — | — |
| 🟧 hn | Apple will limit Mac disk access as AI agents 'substantially' increase risk | qzervaas | 9 | 1 |
| 🟧 hn | Updates to Full Disk Access in macOS | notfirstpost | 317 | 220 |
| 🟧 hn | Apple to Tighten Mac Data Controls in Guard Against AI Agents | mfiguiere | 3 | 1 |
| 🟧 hn | Apple changes full-disk access permissions to curb abuse from AI agents | joozio | 6 | 0 |
| 🟧 hn | Apple says it's tightening macOS privacy controls amid the rise of AI agents | chanux | 1 | 2 |
| 🟧 hn | Privacy, Full Disk Access and AI Agents | eustoria | 1 | 0 |
Interpretation history
2026-10-09T02:53:09Z
grounded: converges/high — Apple — the most consequential desktop platform vendor — has enacted at OS level, explicitly attributing to agent risk, the exact containment posture Scott's Si
2026-10-09T02:38:57Z
The flagged substantive attachment (hn.story.50010973) is a 1-point, 0-comment blog echo of the already-established announcement — commentary drift, not new facts on ship timing, mechanics, or baseline adoption. Meaning unchanged: announced Apple platform policy explicitly attributed to agent risk, corroborated across TechCrunch/Verge/Bloomberg/Ars, now fully cooled (0.17 pts/h at 180h, momentum steady but flatlined); the case rides on the ship-vs-rhetoric watch-item and is carried at low heat until an OS release or hardening signal arrives.
2026-10-08T23:06:44Z
evidence attached: hn.story.50010973 — Blog post directly discusses Apple's tightening of macOS Full Disk Access due to AI agent risks, corroborating the open case about platform containment controls.
2026-10-04T17:09:08Z
The flagged 'substantive_evidence' attachment (hn.story.49955068) is a 1-point dupe thread whose top comment is a dupe pointer — dupe drift, not new substance; the main thread's 302→308/216 tail adds only recycled themes. No new outlet, implementation, or community has appeared since Ars, so the magnitude-valve flag reads the already-priced peak spread, not present motion. Meaning unchanged: announced platform policy explicitly attributed to agent risk, held at corroborated with heat low, carried by the ship/mechanics/baseline-adoption watch.
2026-10-04T16:42:23Z
evidence attached: hn.story.49955068 — Additional independent coverage of Apple tightening macOS privacy controls explicitly because of AI agents — direct evidence for the open Full-Disk-Access containment case.
2026-10-04T09:27:07Z
magnitude valve eligible (multi-platform, top-decile engagement) and never alerted; deterministic escalation to deliver
2026-10-03T08:45:21Z
No substantive change: the Ars Technica attachment and the main thread's 168→184-point drift are the announcement's press tail cooling out, not new facts about ship timing, mechanical delta, or containment-baseline adoption. The case's meaning is unchanged — announced platform policy explicitly attributed to agent risk, awaiting the ship/mechanics/adoption watch — so it holds at corroborated rather than accelerating on engagement alone.
2026-10-03T08:24:41Z
evidence attached: hn.story.49942045 — Ars Technica's coverage is independent press spread of the open Apple full-disk-access case, one of its resolution signals.
2026-10-03T05:52:17Z
The watch-item's first half resolved: Apple's first-party developer post, independently echoed by TechCrunch, The Verge, and Bloomberg and driven by a 168-point/104-comment HN thread, establishes the Full Disk Access tightening as announced platform policy explicitly attributed to agent risk — no longer mere rhetoric. Open questions now carry the case: which macOS release ships the controls, what they mechanically change (lapcat's observation that FDA grants already required admin-level System Settings action sharpens this), and whether agent vendors and security guidance adopt them as baseline containment.
2026-10-02T22:26:24Z
evidence attached: hn.story.49938891 — Bloomberg report on Apple tightening Mac data controls against AI agents moves the tracked policy from rhetoric toward shipping platform containment.
2026-10-02T21:29:13Z
evidence attached: hn.story.49937631 — First-party Apple developer announcement confirming the Full Disk Access tightening is shipping — the exact artifact the open case is waiting on.
2026-10-02T21:29:13Z
evidence attached: hn.story.49938271 — The Verge coverage is independent press spread of the same Apple disk-access-for-agents development, corroborating the open watching case.
2026-10-02T19:56:30Z
grounded: converges/high — Apple — arguably the most consequential party possible — is enacting at OS-platform level, and explicitly attributing to agent risk, the exact containment postu
2026-10-02T19:49:38Z
case created — A platform vendor's first-party security change explicitly attributed to agent risk, triggered by the Meta Muse and ChatGPT Mac-app incidents — a material agentic-security episode with transferable containment lessons and no matching open case.
Decision trace
- 10-09 13:53repriceThe flagged substantive attachment (hn.story.50010973) is a 1-point, 0-comment blog echo of the already-established announcement — commentary drift, not new facts on ship timing, mechanics, or baselin
- 10-09 13:53groundApple — the most consequential desktop platform vendor — has enacted at OS level, explicitly attributing to agent risk, the exact containment posture Scott's SiloOS framework and Architecture, No
- 10-09 10:15attention_routeThe editor compared this story and chose to keep watching.
- 10-09 10:06attention_candidateattach
- 10-09 10:06attachBlog post directly discusses Apple's tightening of macOS Full Disk Access due to AI agent risks, corroborating the open case about platform containment controls.
- 10-09 10:05propose_attachBlog post directly discusses Apple's tightening of macOS Full Disk Access due to AI agent risks, corroborating the open case about platform containment controls.
- 10-05 04:09repriceThe flagged 'substantive_evidence' attachment (hn.story.49955068) is a 1-point dupe thread whose top comment is a dupe pointer — dupe drift, not new substance; the main thread's 302→308
- 10-05 03:42attachAdditional independent coverage of Apple tightening macOS privacy controls explicitly because of AI agents — direct evidence for the open Full-Disk-Access containment case.
- 10-05 03:42propose_attachAdditional independent coverage of Apple tightening macOS privacy controls explicitly because of AI agents — direct evidence for the open Full-Disk-Access containment case.
- 10-05 00:50pushApple tells developers that some are using Full Disk Access in ways that 'could put users at risk' and that 'as AI agents become increasingl — The main thread's 273→302/212 drift r
- 10-04 20:27repriceThe main thread's 273→302/212 drift recycles the same skepticism themes (iOS-ification, 'users don't read prompts', 'one update from revocation') with no new facts on shi
- 10-04 20:27alert_heldApple tells developers that some are using Full Disk Access in ways that 'could put users at risk' and that 'as AI agents become increasingl — The main thread's 273→302/212 drift r
- 10-04 20:27alert_routeApple tells developers that some are using Full Disk Access in ways that 'could put users at risk' and that 'as AI agents become increasingl — The main thread's 273→302/212 drift r
- 10-04 04:20sensor_dirtycomment_update
- 10-04 00:20sensor_dirtyvelocity_spike
- 10-03 23:21sensor_dirtycomment_update
- 10-03 18:45repriceNo substantive change: the Ars Technica attachment and the main thread's 168→184-point drift are the announcement's press tail cooling out, not new facts about ship timing, mechanical delta,
- 10-03 18:24attachArs Technica's coverage is independent press spread of the open Apple full-disk-access case, one of its resolution signals.
- 10-03 18:24propose_attachArs Technica's coverage is independent press spread of the open Apple full-disk-access case, one of its resolution signals.
- 10-03 16:21sensor_dirtyvelocity_spike
- 10-03 15:52repriceThe watch-item's first half resolved: Apple's first-party developer post, independently echoed by TechCrunch, The Verge, and Bloomberg and driven by a 168-point/104-comment HN thread, establ
- 10-03 11:20sensor_dirtycomment_update
- 10-03 10:21sensor_dirtycomment_update
- 10-03 08:26attachBloomberg report on Apple tightening Mac data controls against AI agents moves the tracked policy from rhetoric toward shipping platform containment.
- 10-03 08:26propose_attachBloomberg report on Apple tightening Mac data controls against AI agents moves the tracked policy from rhetoric toward shipping platform containment.
- 10-03 08:20sensor_dirtyvelocity_spike
- 10-03 07:29attachFirst-party Apple developer announcement confirming the Full Disk Access tightening is shipping — the exact artifact the open case is waiting on.
- 10-03 07:29attachThe Verge coverage is independent press spread of the same Apple disk-access-for-agents development, corroborating the open watching case.
- 10-03 07:29propose_attachFirst-party Apple developer announcement confirming the Full Disk Access tightening is shipping — the exact artifact the open case is waiting on.
- 10-03 07:27propose_attachThe Verge coverage is independent press spread of the same Apple disk-access-for-agents development, corroborating the open watching case.
- 10-03 07:21sensor_dirtycomment_update
- 10-03 05:56groundApple — arguably the most consequential party possible — is enacting at OS-platform level, and explicitly attributing to agent risk, the exact containment posture Scott's SiloOS canon argues (age
- 10-03 05:49createA platform vendor's first-party security change explicitly attributed to agent risk, triggered by the Meta Muse and ChatGPT Mac-app incidents — a material agentic-security episode with transferab