Apple Is Tightening Full Disk Access Because of AI Agents. Stop Asking for the Whole Mac.
Maestro Brief · Published by Maestro Mojo
2026-10-03
Maestro’s take.
TL;DR
Apple says it will add more friction before an app can receive Full Disk Access on a Mac. The company did not give a rollout date or explain how the additional controls will work.
The reason matters now: AI agents can act on far more of what they can see. If a coding agent only needs one repository, its host app should not also be able to read Mail, Messages, Safari data, backups, and every other file.
What Apple announced
Full Disk Access is the macOS permission that lets an app reach files and data normally protected by the system. Apple says the permission was built for exceptional jobs such as backups, but some developers use it more broadly.
On October 2, Apple said future controls will require “very explicit user action” before an app gets this access. Apple tied the change directly to more capable and autonomous AI agents.
That is an announcement, not a shipped feature. Apple has not said when the new controls arrive or exactly how they will work.
Why Maestro users care
Local coding agents are useful because they can inspect a repository, run tools, and change files. That does not mean their host app needs the entire Mac.
Blanket access increases the damage from three ordinary failures:
- A bad instruction sends the agent into the wrong folder.
- A poisoned file tells it to look somewhere it should not.
- A bug or plugin copies private data while trying to finish the job.
Apple’s current developer guidance already gives apps narrower ways to work with user-selected files and folders. Apps should also handle denied access cleanly. The new announcement raises the cost of ignoring that advice.
Do this
- Remove Full Disk Access from the agent’s host app unless the job truly requires it.
- Then give the agent a dedicated project or workspace folder as an additional safeguard.
- Use a file picker or user-selected folder when broader access is needed.
- Keep secrets, personal messages, browser profiles, and backups outside the agent’s working area—but do not mistake that folder boundary for protection while the host app still has Full Disk Access.
- Make the useful parts of your app work when Full Disk Access is denied.
- Test the denied-permission path. Apple documents
tccutil reset SystemPolicyAllFilesfor resetting Full Disk Access during testing.
Do not do this
Do not ask for Full Disk Access because it makes setup easier.
Do not hide the request behind “recommended” language without explaining what becomes readable.
Do not treat one system permission as your entire security design. Limit the agent’s own tools, commands, network access, and approval boundaries too.
One thing to try
Remove Full Disk Access from your coding tool’s host app today. Open one normal project and run your usual workflow.
Write down what actually breaks. Fix that narrow path instead of restoring access to the whole computer by default.
The simple rule
If the agent needs the repo, give it the repo. Do not give it your digital life.
Publication date: October 3, 2026