CUPERTINO, Calif. — Buried in a quiet developer notice on October 2, Apple fired the first shot in what is shaping up to be the defining platform fight of the agentic AI era. The company announced it will tighten macOS Full Disk Access controls — and it named artificial intelligence agents as the reason. Apple wrote: "As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially."
Full Disk Access is the Mac's skeleton key. Where ordinary privacy prompts ask whether an app can use your camera, microphone, photos or contacts, Full Disk Access largely sidesteps those gates. It was carved out years ago so backup software could do its job across the whole drive. But once an app holds it, the reachable surface is enormous: Mail, Messages, Safari browsing history, contacts, photos, Time Machine backups. In a statement to TechCrunch, Apple said: "Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems…without users' full knowledge and understanding."
Going forward, Apple wrote in the notice — titled "Updates to Full Disk Access in macOS" on Apple Developer News — it "will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action." The company framed the change as critical to make sure users clearly understand the risks before approving access, so they can make informed decisions about their own data and privacy. Apple also flagged a blast radius that goes beyond the user: for communication apps, it said, the permission "can also compromise the privacy of the people users are communicating with." Your friend's messages to you are your messages — and if an agent can read yours, it can read theirs too.

The timing is not accidental. Inc. columnist Jason Aten recently said Meta's Muse Mac app read his private messages without his permission — a claim Meta disputed, with CTO David Singleton and spokesperson Andy Stone saying Muse can only read such content if a user manually enables both the macOS system-level permission and a specific Messages connector inside the Muse app. Separately, Wired previously documented a flaw in the ChatGPT Mac app that could have let attackers reach sensitive data. And in August, OpenAI itself added an opt-in feature to its ChatGPT Mac application that can read, summarize, write and send text messages on a user's behalf — a feature that requires Full Disk Access to pull information from Apple's Messages app, according to Bloomberg's reporting.
Apple's announcement, in other words, lands on a permission that AI companies now need for their flagship products. OpenAI said this week that more than 35 million people now use its agent products, ChatGPT Work and Codex, up from 10 million in July, Bloomberg reported. Meta's Muse reached the top of app-store download charts after its launch. Agents are no longer demos; they are installed base. That scale is exactly what makes the permission dangerous: a capable, autonomous agent with Full Disk Access is software that can act on your behalf across your entire Mac with limited or no direct supervision — which is the point of the product, and precisely Apple's worry.

Notably, Apple's notice names no app, no company, no macOS version and no ship date — and TechCrunch reported that Apple did not respond to questions about when the new controls will arrive. This is a policy signal, not a same-day flip of the existing setting. But it is the first time a major operating system vendor has updated a core permission specifically because of agents — not malware, not spyware, but software designed to work for you. macOS security researcher Patrick Wardle told Ars Technica that any app holding Full Disk Access can technically read non-root files, including chat histories and cookies — a reminder of why the grant is, in Apple's word, "extraordinary."
For anyone running an agent on their own machine, the practical rule is unchanged and worth stating: grant the narrowest access the job needs, and audit what's already granted. On the Mac, that lives in System Settings under Privacy & Security, where Full Disk Access lists every app holding the key. If a backup utility or developer tool legitimately needs it, it will still be grantable — Apple says users who genuinely need the permission will still be able to get it. The difference is that the next AI agent that asks for the keys to the kingdom will have to explain itself much more clearly first.

And there is a parallel crackdown happening on the hardware side of the AI boom. On October 1, federal prosecutors in Los Angeles arrested Greg Lui, 38, the owner of City of Industry-based Earthmade Computer Inc., on a three-count federal indictment returned September 29. The charges — conspiracy to violate the Export Control Reform Act, outbound smuggling, and conspiracy to commit money laundering — allege Lui spent 2023 and 2024 routing more than $300 million in export-controlled servers loaded with high-end Nvidia A100 and H100 GPUs to China through Malaysia and Singapore, on paperwork that falsely named buyers in countries where no export license is required. One cited purchase order covered 27 servers packed with H100 GPUs, worth about $7.6 million, shipped to Kuala Lumpur in January 2024; prosecutors say Earthmade received more than $176 million from two Malaysia-based shipping companies between January and October 2024.
"This defendant allegedly used false paperwork and shipments through third countries to smuggle more than US$300 million in export-controlled computer servers to China," said First Assistant U.S. Attorney Bill Essayli. "We will aggressively prosecute those who put our national security at risk for profit." Lui could face more than 20 years in prison if convicted on all three counts, and prosecutors are seeking detention without bail, arguing he is a flight risk. Nvidia, which has not been accused of wrongdoing, said in a statement: "This case shows yet again that smuggling is a losing proposition — legally, economically and technically. Our work with law enforcement has led to prosecutions, and we will continue to engage with law enforcement." The charges are allegations, and Lui is presumed innocent unless proven guilty beyond a reasonable doubt. Read our full account of the case.

Zoom out and the two stories rhyme. The AI era's scarcest assets — the chips that train the models, and the permissions that let agents act on your machine — are both being fenced with sharper rules. One fence is a federal indictment. The other is an Apple developer notice. Both say the same thing: the extraordinary access of the last few years was priced for a world where software waited for instructions. That world is ending, and the gatekeepers are rewriting the terms. For the latest on how the agent era is reshaping the industry's biggest model builders, see our coverage of Anthropic's Claude Sonnet 5.5 launch.
Reporting this story is based on
- Apple tightens macOS Full Disk Access as AI agents raise privacy risk
AI Tech Daily — 2026-10-02 - Apple to strengthen Mac privacy controls over growing AI agent risks
Storyboard18 (Bloomberg) — 2026-10-03 - Apple Tightens macOS Full Disk Access Over AI Agents
CellCog — 2026-10-04 - California man charged in $300M Nvidia chip smuggling case
TTNews — 2026-10-02 - California tech CEO charged in $300 million scheme to smuggle Nvidia chips to China
Startup Fortune — 2026-10-03


