2026-10-11 16:37 UTC

Apple says it is tightening macOS Full Disk Access — new controls requiring very explicit user action — because AI agents substantially raise the risks of full-system access, and whether these controls ship and become the baseline platform containment that desktop agent products and security guidance build on, or remain developer-blog rhetoric, resolves the episode.

state: corroboratedheat: lowuncertainty: mediumconvergesscott: highagentic-security macos-containment agent-sandboxingApple
Surfaced 2026-10-04T13:50:37Z — Apple tells developers that some are using Full Disk Access in ways that 'could put users at risk' and that 'as AI agents become increasingl — The main thread's 273→302/212 drift recycles the same skepticism themes (iOS-ification, 'users don't read prompts', 'one update from revocation') with no new facts on ship timing, mechanical delta, or adoption; the speedometer has flatlined (~0 pts/h, 14th percentile at 67h) and no new outlet, implementation, or community has appeared since Ars — the magnitude-valve flag reads the already-priced peak spread, not present motion, so heat cools to low. Meaning unchanged: announced platform policy explicitly attributed to agent risk, carried by the ship/mechanics/baseline-adoption watch.

What is this?

On October 2, 2026, Apple published a first-party developer notice stating it will add new controls to macOS Full Disk Access (FDA) requiring "very explicit user action" to grant the permission, explicitly attributing the change to AI agents: "as AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially." The notice cites some developers already using FDA in ways that "could put users at risk," exposing files, mail, messages, and browsing history. Independent coverage from TechCrunch, The Verge, Bloomberg, Ars Technica, and a 317-point Hacker News thread corroborates the announcement and Apple's stated agent-risk rationale; Apple declined TechCrunch's request for specifics. The ship vehicle (macOS version), mechanical delta over the existing admin-gated FDA grant flow, and whether desktop agent products (Muse, ChatGPT Mac) and security guidance adopt these controls as a baseline containment layer remain unresolved.

Why it matters to Scott

Apple — the most consequential desktop platform vendor — has enacted at OS level, explicitly attributing to agent risk, the exact containment posture Scott's SiloOS framework and Architecture, Not Vibes doctrine argue for ('can't beats shouldn't'). This is dated-receipts validation from the platform itself. The unresolved ship/mechanics/adoption watch directly bears on OpenClaw's macOS sandboxing model and LeverageAI's security guidance baseline: if these controls ship and harden into the platform containment floor, Scott's desktop-agent architecture and advisory baseline must build against them; if they remain rhetoric, the containment gap persists.
ip:framework.siloosip:framework.architecture-not-vibesip:concept.architectural-containmentip:concept.runtime-containmentdev:project.silo-osdev:project.openclawwork:project.leverageaiip:concept.containmentdev:concept.padded-cell-agent-architectureradar:aegis-inline-ebpf-agent-containmentradar:amazon-blocks-meta-muse-shoppingradar:agent-substrate-sandbox-runtimeradar:agentsec-static-config-auditingradar:agentshield-offline-agent-scannerradar:agenttrust-portable-execution-recordsradar:acs-local-skill-risk-catalogradar:ai-agent-security-incidents-datasetradar:agent-acid-rollback-guardrails
queries asked of Scott's wikis
  • SiloOS architectural containment 'can't beats shouldn't' platform enforcement
  • OpenClaw desktop agent sandboxing macOS permissions model
  • LeverageAI security guidance baseline containment layers
  • agentic security macOS FDA TCC sandbox escape patterns
  • model sovereignty local inference desktop agent threat model
  • platform vendor containment mandates as architectural primitives

Measured heat

now 0 pts/hpeak 62 pts/hcomments 0/hpeers p16momentum: steady2 platformsage 242h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

10-01 14:00⭐ origin echo-reconstructedApple tells developers that some are using Full Disk Access in ways that 'could put users at risk' and that 'as AI agents become increasingl
Apple on blog (echo) · attributed from hn.story.49937239
—
10-02 19:03first on hacker news · published · +29.1hApple is tightening macOS 'Full Disk Access' due to new risks from AI agents
speckx
—
10-02 19:03amplified on hacker newshn.story.49937239
speckx
peak 20 · 8 comments · 5% of case engagement
10-02 19:37amplified on hacker news 👑hn.story.49937631
notfirstpost
peak 317 · 220 comments · 91% of case engagement
10-02 20:33amplified on hacker newshn.story.49938271
qzervaas
peak 9 · 1 comments · 2% of case engagement
10-02 21:36amplified on hacker newshn.story.49938891
mfiguiere
peak 3 · 1 comments · 1% of case engagement
10-03 07:18amplified on hacker newshn.story.49942045
joozio
peak 6 · 0 comments · 1% of case engagement
10-04 16:02amplified on hacker newshn.story.49955068
chanux
peak 1 · 2 comments · 1% of case engagement
1 more amplifiers in ainews.case_chain
10-02 19:21our radar first saw it · +29.4hdiscovery anchor: hn.story.49937239—
10-04 09:27reached heat=high · +67.5h · via ledger——
pace: p86 vs 1188 stories at the 168h mark (now 242h old) — ahead of isaacs-flock-alpr-lawsuit (1.0x), behind cactus-needle3-on-device-automation (1.0x)

Evidence (8) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnApple is tightening macOS 'Full Disk Access' due to new risks from AI agents
Retrieved article excerpt

Open article · Retrieved 2026-10-02T19:30:11.942805+00:00

Days after a journalist claimed that Meta’s Muse app on Mac read their private messages — a [claim that Meta disputed](https://techcrunch.com/2026/09/30/meta-disputes-claim-that-muse-read-a-users-private-messages-without-permission/) — Apple announced that it’s introducing additional controls around a setting called “Full Disk Access” on macOS. The feature was designed to allow backups to function properly, but AI agents have now increased “the risks associated with this level of access,” Apple said.

Apple’s statement comes shortly after Inc. columnist Jason Aten [reported](https://www.inc.com/jason-aten/metas-new-muse-ai-agent-read-my-private-messages-i-never-asked-it-to/91408202) that Muse knew the content of his private messages — even though he claimed to have not given the AI agent permission. The report raised questions about the level of security and trust users have in desktop-based AI, which can control things on their systems and read their files and messages.

The decision to limit the Mac feature also comes after a [Wired report](https://www.wired.com/story/a-flaw-in-chatgpts-mac-app-could-have-let-hackers-grab-sensitive-data/) cited that a flaw in ChatGPT’s Mac app could have allowed hackers to access sensitive data.

AI agents that run on the desktop allow users to provide their respective apps with greater access to the files, messages, and other personal content on their computers by adjusting macOS settings.

In Muse’s case, the AI optionally allows users to enable Full Disk Access. This setting, Apple explains, gives an app permission to access files, mail, messages, and even browsing history.

“Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems…without users’ full knowledge and understanding,” Apple said [in a new blog post](https://developer.apple.com/news/?id=p6zjojqw) aimed at developers.

The company says that, going forward, it will introduce new controls aimed at ensuring that users who “genuinely wish to grant an app this extraordinary level of access” can do so only with “very explicit user action.”

“Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy,” Apple wrote.

Apple did not respond to TechCrunch’s inquiry about the feature change.

Topics

[AI](https://techcrunch.com/category/artificial-intelligence/), [AI agents](https://techcrunch.com/tag/ai-agents/), [Apple](https://techcrunch.com/tag/apple/), [Apps](https://techcrunch.com/category/apps/), [Meta](https://techcrunch.com/tag/meta/), [Security](https://techcrunch.com/category/security/)

*When you purchase through links in our articles, [we may earn a small commission](https://techcrunch.com/techcrunch-affiliate-monetization-standards/). This doesn’t affect our editorial independence.*

Sarah Perez

Sarah Perez

Consumer News Editor

Sarah has worked as a reporter for TechCrunch since August 2011. She joined the company after having previously spent over three years at ReadWriteWeb. Prior to her work as a reporter, Sarah worked in I.T. across a number of industries, including banking, retail and software.
  
  
You can contact or verify outreach from Sarah by emailing [email protected] or via encrypted message at sarahperez.01 on Signal.

[View Bio](https://techcrunch.com/author/sarah-perez/)

Event Logo

October 13 – 15

San Francisco

**Get 50% off a second pass**  
The Disrupt experience is meant to be shared. Get your pass and bring a colleague, partner, or peer at 50% off. Cover more ground by making connections, building momentum, and discovering what’s next in the startup ecosystem.

[**BOOK NOW**](https://techcrunch.com/events/techcrunch-disrupt/?utm_source=tc&utm_medium=ad&utm_campaign=disrupt2026&utm_content=ticketsales&promo=rightrail_rbplusbogo&display=)

## Most Popular

- ### [Google thinks SpaceX’s Starship has to launch 1,800 times before space data centers get off the ground](https://techcrunch.com/2026/10/01/google-thinks-spacexs-starship-has-to-launch-1600-times-before-space-data-centers-get-off-the-ground/)

  - [Tim Fernholz](https://techcrunch.com/author/tim-fernholz/)
- ### [World’s first enhanced geothermal power plant completed in just 23 months](https://techcrunch.com/2026/10/01/worlds-first-enhanced-geothermal-power-plant-completed-in-just-23-months/)

  - [Tim De Chant](https://techcrunch.com/author/tim-de-chant/)
- ### [Google releases Gemini 4 Argon, called its most powerful model yet](https://techcrunch.com/2026/09/30/google-releases-gemini-4-argon-called-its-most-powerful-model-yet/)

  - [Lucas Ropek](https://techcrunch.com/author/lucas-ropek/)
- ### [The Pentagon taps Elon Musk and Palmer Luckey to help decide what the military should do next](https://techcrunch.com/2026/09/30/the-pentagon-taps-elon-musk-and-palmer-luckey-to-help-decide-what-the-military-should-do-next/)

  - [Dominic-Madori Davis](https://techcrunch.com/author/dominic-madori-davis/)
- ### [OpenAI launches Dots, its bubbly agentic avatar](https://techcrunch.com/2026/09/29/openai-launches-dots-its-bubbly-agentic-avatar/)

  - [Lucas Ropek](https://techcrunch.com/author/lucas-ropek/)
- ### [AMD will acquire Fei-Fei Li’s World Labs for $8.2B](https://techcrunch.com/2026/09/28/amd-will-acquire-fei-fei-lis-world-labs-for-8-2-billion/)

  - [Tim Fernholz](https://techcrunch.com/author/tim-fernholz/)
- ### [Viral AI agent Instinct raises $1B Series C at a $10B valuation](https://techcrunch.com/2026/09/28/viral-ai-agent-instinct-raises-1b-series-c-at-a-10b-valuation/)

  - [Sarah Perez](https://techcrunch.com/author/sarah-perez/)
speckx208
🟧 echo.blog ⭐Apple tells developers that some are using Full Disk Access in ways that 'could put users at risk' and that 'as AI agents become increasinglApple——
🟧 hnApple will limit Mac disk access as AI agents 'substantially' increase riskqzervaas91
🟧 hnUpdates to Full Disk Access in macOSnotfirstpost317220
🟧 hnApple to Tighten Mac Data Controls in Guard Against AI Agentsmfiguiere31
🟧 hnApple changes full-disk access permissions to curb abuse from AI agentsjoozio60
🟧 hnApple says it's tightening macOS privacy controls amid the rise of AI agentschanux12
🟧 hnPrivacy, Full Disk Access and AI Agentseustoria10

Interpretation history

Decision trace