- Apple updated macOS Full Disk Access on October 2, 2026, to require re-authorization for apps behaving as autonomous AI agents.
- The update specifically targets a gap where an app holding broad file access could act autonomously without triggering any new user prompt, since nothing it does technically exceeds what was already authorized.
- Windows 11 went through a similar reckoning in late 2025, when Microsoft reversed its Agent Workspace feature’s default folder access after public backlash, moving to the same consent-based model Apple is now adopting.
On October 2, 2026, Apple tightened macOS Full Disk Access after researchers demonstrated that a single broad permission grant could let AI agents sweep through personal documents, email databases and financial records without any further user approval. The update forces re-authorization whenever an app starts behaving as an autonomous agent, even if it already held open file system access.
What Apple Changed
The new rules roll out in stages over the current quarter. Under the previous model, granting Full Disk Access once at installation was sufficient: the app could read and write across the entire file system indefinitely. Apple says that model was adequate for conventional software, which behaves predictably, but autonomous AI agents present a different problem. Because they can act on their own initiative, a single permission grant effectively becomes a standing invitation to access far more than the user likely intended.
The core problem is detection: an app abusing broad access doesn’t necessarily do anything that exceeds what it was authorised to do, it just does more of it, or more sensitive versions of it, than a user would have agreed to if asked directly. The re-authorization requirement breaks that gap: any shift toward autonomous agent behaviour triggers a new consent request, regardless of what was approved at install time.
Developer and User Impact
For developers building AI-powered apps, the practical consequence is a permission model rebuild. Apps that currently rely on a single Full Disk Access grant will need to request access in narrower, context-specific steps and handle cases where users decline. That adds friction to development, but it also forces a cleaner separation between what an app needs for a specific task and what it has been holding in reserve.
Users will see more prompts when using certain AI applications, particularly third-party tools designed for file organisation, document analysis or system optimisation. Each prompt is the system confirming that an agent is about to access something sensitive, rather than operating under blanket consent. Windows 11 went through its own version of this reckoning in late 2025, when Microsoft reversed Agent Workspace’s default folder access after public backlash, moving to the same consent-based model Apple is now adopting. The two platforms are converging on this approach rather than diverging.


