A planned tightening of macOS Full Disk Access follows reports that Meta's Muse app read synced messages after a user thought he had denied the permission.
Apple is using the consent layer to decide which AI agents scale on macOS. The friction it is adding around Full Disk Access is the substrate for the next tier of agent capability, not a brake on it. Full Disk Access is a permission that lets an app read nearly everything on a user's computer, including files, mail, messages, and browsing history.
On October 2, 2026, Apple posted a developer notice saying it will require "very explicit user action" before macOS grants an app Full Disk Access, citing the rise of AI agents as the reason. The post is a directional statement, not a shipping change: Apple did not announce a date, a control design, or the developers it is targeting. The company framed the move as platform-level, not a rebuke of any named product.
What changed is the threshold. Until now, a user could land on a Full Disk Access prompt, click Allow, and grant a desktop agent access to most of what is on the Mac. A desktop agent is the kind of program that reads a user's screen, drafts messages, and moves files on their behalf. Apple's argument is that the prompt was not specific enough for what was being asked. A permission that covers mail, messages, and browsing history should not be granted the same way a user grants a backup app access to a folder.
The reported trigger is a specific incident. In a column for Inc., journalist Jason Aten wrote that Meta's Muse Mac app accessed his synced messages after he believed he had declined the permission. Meta told the press that any synced messages required explicit opt-in, and that the user's account was inconsistent with the company's records. The dispute is not resolved, but it surfaces the gap the new controls are designed to close: when a user says "no" in their head and the system says "yes" in its log, neither side has a clean record of what was granted.
That gap is what third-party agent developers have been routing around. Engadget, TechCrunch, and MacRumors all describe a pattern in which desktop agents for AI tools, including OpenClaw, Dots, and Muse, coach users through granting Full Disk Access so the agent can read local files and act across apps. The same coverage notes that some users are buying dedicated Mac Minis to run a single agent, partly to bound the blast radius of Full Disk Access. Demand for the small desktop has been a factor in the Mac Mini's recent supply constraints, according to Engadget.
The capability argument runs the other way. Desktop agents need broad file and message access to do useful work, and any consent layer that is too aggressive will push useful automation into the browser, where the user has even less visibility into what an agent is reading. The strongest counterargument to Apple's move is that developers will route around a stricter Full Disk Access prompt, and users will click through a more explicit one, because the underlying work, letting an agent act on a person's files, still has to happen somewhere. That is the right criticism to hold onto. It is also the reason this round of controls is necessary rather than sufficient. The work of building consent infrastructure that scales with capability is not finished by a single prompt redesign.
What Apple is signaling is a category decision: the agents that earn user trust at the consent layer are the ones that get to operate at the OS layer. Full Disk Access is a single permission today. The next tier of agent capability will require a permission model that distinguishes between reading mail and reading a folder, between acting on a user's behalf and reading everything the user has ever seen. The friction is the feature. It is what makes the next product class possible instead of merely tolerated.