Check Which Mac Apps Have Full Disk Access

Matthew Leo · Published October 4, 2026 · Guides

A laptop user reviews privacy settings at a sunlit home-office desk.

Apple plans to make Full Disk Access harder to grant as AI agents become more capable. The change has not shipped yet, but Mac users do not need to wait to see which applications already have the permission.

Full Disk Access is unusually broad. Apple says it can expose files, mail, messages and browsing history by allowing an application to bypass many of macOS's normal privacy controls.

Why Apple is changing the permission

In an October 2 developer notice, Apple said some developers are using Full Disk Access in ways that users may not fully understand. It plans additional controls that will require "very explicit user action" before an application receives that level of access.

Apple did not give a release date or explain the new approval flow. Do not assume the protection is already active after a routine macOS update.

The announcement followed complaints about Meta's Muse agent. Reuters reported that some users believed the agent reached private messages without a clear warning. Meta said message access is optional and requires the user to enable both Full Disk Access and a Messages connector. That dispute does not change the larger problem: one system permission can open far more information than a user may expect an agent to need.

Check the current list on your Mac

Open System Settings, choose Privacy & Security, then open Full Disk Access. The exact layout may vary slightly by macOS version, but the page lists applications that have requested this permission and shows which ones are enabled.

Review the list one application at a time:

What happens if you turn access off

Disabling Full Disk Access does not normally uninstall an application or delete its data. It can stop backups, searches, security scans or agent tasks that depend on protected files. Save current work and understand the application's role before changing it on a work-managed Mac.

After revoking access, quit and reopen the application. If it cannot perform an expected task, look for a narrower permission or a setting that limits the folders and services it can reach. Re-enabling broad access should be a deliberate decision, not the quickest way past an error message.

Use a smaller permission set for AI agents

An agent that summarizes one project does not automatically need every message, browser profile and local document. Start with the fewest connected services required for the task. Separate read access from permission to send, edit, buy or delete wherever the product allows it.

Mapletechie's guide to always-on OpenAI agents uses the same approach: begin with a narrow job, require approval for consequential actions and review the activity log during the first tasks.

Canadian workplaces should also check who owns the account, where retrieved information is processed and whether staff are connecting personal AI subscriptions to company files. Apple's future prompt will not answer those organizational questions.

What Apple still needs to explain

A better warning is useful, but the strongest design would let applications request limited access for a defined task or period. Apple has not said whether the new controls will provide that kind of scope, an expiry time or a record of what an agent accessed.

For now, the practical step is simple: check the existing Full Disk Access list and remove permissions that no longer have a clear purpose.

Sources

Tags: macOS, Full Disk Access, AI agents, Mac privacy, Apple

Read on Mapletechie