On October 3, 2026, Siften reported that Apple will add new controls to macOS’s Full Disk Access permission after warning that increasingly capable AI agents make broad local data access substantially riskier. The article, citing Apple’s October 2 developer notice and coverage from Ars Technica and TechCrunch, says Apple has not yet given a release date or full technical details for the changes.
This article aggregates reporting from 4 news sources. The TL;DR is AI-generated from original reporting. Race to AGI's analysis provides editorial context on implications for AGI development.
Apple is quietly redefining what it means to give an app deep access to your machine, and AI agents are the reason. Full Disk Access started as a blunt instrument so backup and security tools could function, but an always on agent that reads your messages, files and browser data turns that into a live surveillance and automation channel. By treating agentic apps as a distinct security category, Apple is acknowledging that the old permission model breaks when software can act and reason autonomously over everything it can see.
This matters for the AGI trajectory because the operating systems that host advanced agents are becoming an important control layer. If macOS, and eventually Windows and Linux distributions, start to encode norms like purpose bound access, shorter lived grants and auditable logs for agent actions, it will shape how aggressively developers can push toward fully autonomous desktop assistants. Safety by design at the OS level can reduce the risk that a misaligned or compromised agent quietly exfiltrates sensitive context or carries out high impact actions.
For the competitive race, platforms that move first on credible agent security will be more attractive to enterprises, even if they frustrate some early adopter developers. Apple is betting that making it harder to build reckless agents is worth the friction, especially given recent incidents where third party tools appeared to overreach on user data. Other platforms will face pressure to match or exceed that bar if they want to host serious, business critical agent ecosystems rather than a gray market of ungoverned bots.