P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Apple will tighten Full Disk Access for AI agents; its post names no app, no date and no word on MDM

Apple's developer post of 2 October says Full Disk Access will need very explicit user action. It names no app, version or date and does not mention MDM, where Apple's own documentation says a profile can grant it without prompting the user.

By Parminder Kumar Sharma · · 21 min read

Editorial illustration for the briefing: Apple will tighten Full Disk Access for AI agents; its post names no app, no date and no word on MDM

Four of 24, and a post of 177 words

Apple's reference for managing Mac privacy permissions lists 24 services. For four of them, camera, microphone, screen capture and listening to input events, Apple says a profile can only deny access: "A profile can't grant access to the camera; it can only deny it." The service that covers Full Disk Access, SystemPolicyAllFiles, carries no such sentence. Apple's deployment guide describes it as access to "data like Mail, Messages, Safari, Home, Time Machine backups, and certain administrative settings for all users of the Mac".

Apple's developer post of 2 October 2026, "Updates to Full Disk Access in macOS", says Apple will "introduce additional controls" so that a user can grant an app this access only "with very explicit user action". By our count the post is 177 words in two paragraphs. It names no app, no macOS version and no date, and it does not mention MDM, device management, administrators or enterprise use (we searched its text for each). The Hacker News and Help Net Security covered it on 5 October. The post itself is dated Friday 2 October.

That is where the evidence stops. The post does not establish that any app has misused the access: it says some developers use Full Disk Access "in ways that could put users at risk", which is a statement about risk. It does not say how many apps hold the permission, whether the new control will stop a determined actor, or whether a grant made by an administrator through MDM is covered, exempt or untouched. And although The Hacker News ties the move to Meta's Muse agent, Apple names no one, and the columnist whose report started the Muse story says Full Disk Access was off on his Mac.

Judgement: for a UK organisation with Macs, the live question is the one the post leaves unanswered. An MDM profile is a documented way for a managed fleet to get Full Disk Access, and Apple's documentation describes that route as one where the user is not prompted.

What Apple's post states, and what it does not

The post has two paragraphs. The first says Full Disk Access "largely sidesteps these controls in order to allow backup apps to function properly on the Mac", and that some developers use it in ways that expose "everything on their systems" "without users' full knowledge and understanding". For communication apps it adds that the access "can also compromise the privacy of the people users are communicating with". The second paragraph makes the promise and gives the reason: "As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially."

Apple's developer post of 2 October 2026, read in full on 5 October 2026 at about 15:30 BST. "Not stated" means we found no sentence on the point.

  1. Question
    Who
    Stated
    Some developers use the access in risky ways; communication apps can expose other people
    Not stated
    Which developers or apps. No company is named
  2. Question
    What it exposes
    Stated
    Files, mail, messages and browsing history
    Not stated
    How many apps hold the access, or any case of misuse
  3. Question
    Why it exists
    Stated
    To let backup apps function properly
    Not stated
    Whether other uses are intended or acceptable
  4. Question
    What changes
    Stated
    Additional controls; access only with very explicit user action
    Not stated
    What the control is, or whether it reaches existing grants
  5. Question
    Why now
    Stated
    Risk will grow substantially as AI agents become more capable and autonomous
    Not stated
    Any named product or incident
  6. Question
    Where and when
    Stated
    Nothing
    Not stated
    A macOS version, beta, release or deadline
  7. Question
    Managed Macs
    Stated
    Nothing
    Not stated
    Whether MDM or profile grants are covered, exempt or changed

Several outlets add detail Apple did not give. MacRumors and 9to5Mac name Meta's Muse and OpenAI's Dots as the agents in the background, and TechCrunch ties the post to the Muse report and to a Wired report on a ChatGPT Mac app flaw. Those links are the outlets' inference. The Hacker News says as much: "Apple did not take any specific name", and the move "appears to be a response" to the Muse report.

What would "very explicit user action" be? A stronger confirmation step, an extra authentication step, or a limit on how an app can steer a user to the setting would all fit the post. Apple states none of them, so that list is inference. One thing is already documented: Apple's Platform Security guide says apps that need the full storage device "need to be explicitly added" in System Settings, and Apple's Mac User Guide tells the user to click +, choose the app and click Open. The gap the post names is understanding, "users clearly understand these risks before granting such access", not the absence of a user step.

Judgement: a control can add a step. It cannot guarantee that the person taking the step knows that the app will afterwards be able to read other people's mail.

The Muse report: what it found, what Meta says, what is unsettled

The report most coverage points to is an Inc. column of 19 September 2026, labelled opinion, by the site's technology columnist. He writes that he installed Meta's new Muse agent on an iPhone and a Mac mini, that Muse then pushed a notification about a conversation he had been having and flagged a message from his editor, and that Muse, asked how it knew, said it relayed notification banners. He writes that Muse "does sync your messages from the local Messages database", that his copy had synced "to row 187,462", and "I never gave it permission to read my messages." On Full Disk Access he writes that the settings pane in the Muse Mac app "shows that Full Disk Access is not enabled".

Meta executive David Singleton replied the same day on Threads: "Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled." The first of the steps he lists is to grant Full Disk Access "within the Muse app", which he says the screen explains is opt-in. TechCrunch reported on 30 September that Meta's head of communications said the same on X. In a second column on 23 September the columnist quotes Singleton as saying "That's on us" about Muse's wrong notification explanation, says the Messages connector was enabled when he looked afterwards although he had declined it, and says he still has no answer on how Muse read his messages "with Full Disk Access turned off".

A two-panel timeline drawn to scale. The top panel runs from 24 September 2018, when macOS 10.14 Mojave was released, to 5 October 2026, 2,933 days, with Apple's post of 2 October 2026 at the right end. The lower panel enlarges 19 September to 5 October 2026: an Inc. column and a Meta executive's reply on 19 September, a second column on 23 September, TechCrunch on 30 September, Apple's post on 2 October and coverage on 5 October.
Drawn from Apple Newsroom, Apple Developer News, Inc., Threads, TechCrunch, The Hacker News and Help Net Security. Day counts are our arithmetic.

The arithmetic: Apple's post came 13 days after the 19 September column and three days before the 5 October coverage. Apple's profile reference lists the privacy payload from macOS 10.14, which Apple released on 24 September 2018. To 2 October 2026 that is 2,930 days, 8 years and 8 days. Apple's Platform Security guide dates the explicit-add rule for full storage access to macOS 10.13 or later, so "at least eight years" holds on either reading.

The Muse dispute, point by point, from the two Inc. columns, Singleton's Threads replies and TechCrunch. Read 5 October 2026.

  1. Point
    Was Full Disk Access on?
    Who says what
    Columnist: off, per the Muse settings pane. Meta: both settings are needed to read Messages
    What we could check
    Statements only. We found no system log or permissions capture that settles it in the text we read; we did not examine images
  2. Point
    Was the Messages connector on?
    Who says what
    Columnist: enabled when he checked later, though he says he declined it
    What we could check
    Statements only
  3. Point
    How much was read?
    Who says what
    Columnist: synced to row 187,462 of the Messages database
    What we could check
    His own figure. He says he is not sure how many messages that is, and rows are not messages
  4. Point
    Did Muse explain itself correctly?
    Who says what
    Muse said it relayed notification banners. Meta executive: that was wrong
    What we could check
    Both sides agree the explanation was wrong

So the story that is said to have triggered Apple's post does not show Full Disk Access, as Apple's pane records it, being misused. Inference: if the columnist is right, the access involved was not Full Disk Access as the pane shows it, and a tighter way of granting that setting would not have changed the outcome. If Meta is right, the setting was on, and the question is how a person came to grant it. The record read here does not say which. The Hacker News writes that Muse accessed the messages "after they granted it Full Disk Access". That states one side's position as fact. TechCrunch's 30 September report records that the columnist's account is that it was off.

Meta's 8 September post on how Muse was built describes a Sentinel service that is "the sole permission authority" for connector actions and network egress, with approvals that can be "one-time, session-scoped, task-scoped, time-bounded, or perpetual". We searched its full text and it has no match for macOS, Messages, notifications or Full Disk Access. The per-action design it describes and the macOS permission at the centre of the dispute are therefore not linked in anything Meta has published that we read. That is not evidence that they are unlinked in the product.

Method note. Everyone in this section has an interest. Meta ships the agent and has defended it. Apple controls the permission and the platform it runs on, and its post is also a statement of policy. The columns are one writer's account, and they are opinion. We therefore weigh each claim by what a reader can check, not by who made it.

How Full Disk Access is granted today, and what MDM can do

The user route. Apple's Mac User Guide, in its macOS 27 form, describes the Full Disk Access pane as letting apps access "all files on your computer, including data from other apps (for example, Mail, Messages, Safari, and Home)", data from Time Machine backups, and "certain administrative settings for all users on this Mac". To add an app the user clicks +, selects the app and clicks Open. The page that The Hacker News links for the setting is a different Apple page, "Allow access to system configuration files". It describes a dialog with Allow and Don't Allow, then points to the same Full Disk Access pane. It mentions neither mail nor messages.

The MDM route. Apple's Privacy Preferences Policy Control payload lets a management service name an app by bundle ID or path, with its code signing requirement, and set the service SystemPolicyAllFiles. For the Allowed key Apple writes: "The user isn't prompted and can't change this value." The deployment guide, published 29 July 2024, gives its own example comment for a profile entry: "Allows my organization's app to interact with all files without prompting the user." Where payloads conflict, Apple says the most restrictive setting, deny, wins. Apple's Identity reference adds that helper tools embedded in an app bundle "automatically inherit the permissions of their enclosing app bundle".

Apple's own pages, drawn as a diagram. Left: a user adds an app in System Settings; an administrator can grant the SystemPolicyAllFiles service by MDM profile, where Apple says the user is not prompted. Middle: Full Disk Access, held per app. Right: what Apple lists it as reaching: all files, other apps' data, Time Machine backups, administrative settings. Below: 24 MDM privacy services, four deny-only, Full Disk Access not among them. Five things the post does not state.
Drawn from Apple Developer News, Apple's Mac User Guide, Platform Security guide, Platform Deployment guide and developer reference, read on 5 October 2026. The count of 24 and 4 is ours.

Apple already treats four services differently. Camera, microphone, screen capture and listening to input events (ListenEvent) are the four where its reference says a profile "can only deny". Apple does not say why Full Disk Access is not among them, and the post says nothing about moving it there. Two Apple pages also disagree on a detail that matters to an MDM owner: the developer reference marks the payload as needing user-approved MDM on macOS and shows supervision as not applicable, while the deployment guide says "Supervision is required if you apply this payload using a device management service". Check with your MDM vendor what your enrolment type allows.

What changed in macOS 27. Apple marks the whole Identity dictionary, which holds the Allowed and Authorization keys, as deprecated from macOS 27.0. It marks five services (Accessibility, Bluetooth, Camera, Microphone and Speech Recognition) deprecated too and, for three of them, points to the Privacy key of a declarative app settings configuration. That configuration shows the user a consent prompt listing the organisation's suggested defaults, and the user can accept or decline. The permission defaults Apple lists for it are accessibility, Bluetooth, camera, dictation, local network, location and microphone, plus location accuracy on iOS. None is file access. SystemPolicyAllFiles has no deprecation tag in the page we read. What a macOS 27 Mac does with an existing SystemPolicyAllFiles profile is not stated in the pages we read.

The macOS 27 release notes add three lines worth knowing. Access to other developer teams' app data containers "no longer prompts the user for authorization" and is denied by default. For a process without a bundle ID, the documented workaround is to "grant Full Disk Access to the process for the duration of the requirement". And "Apps can no longer access the local TCC database directly". Judgement: as Apple closes narrower doors, its own notes name Full Disk Access as the way through for some tools, and the notes describe no expiry for the grant. That is why the post's promised control matters, and why its silence on administrators matters more.

The label is not the control

Four labels in this story promise something other than what the sources show. A comforting name is not a control.

Each label against what the sources show. Read 5 October 2026.

  1. Label
    Full Disk Access
    What it suggests
    A setting about the disk
    What the sources show
    Apple: all files, plus other apps' data such as Mail and Messages, backups and administrative settings. The columnist replied on Threads that it "doesn't say anything about your message database"
  2. Label
    Opt-in
    What it suggests
    The person chose this
    What the sources show
    Meta: the Messages integration is opt-in. The columnist: "No one should be surprised that an AI Agent is reading their messages, regardless of what they clicked." Both can be true
  3. Label
    Messages connector
    What it suggests
    One switch for Muse's reading of Messages
    What the sources show
    A second, app-level switch beside the macOS permission. Meta counts three steps; the columnist found it enabled after he says he declined it
  4. Label
    Very explicit user action
    What it suggests
    A strong, specific consent
    What the sources show
    Not defined in the post

The deeper problem is time. A toggle labelled Full Disk Access is an operating-system control that a person, or an administrator through MDM, sets once. It then applies to everything the app does afterwards, including what an AI agent decides to do on its behalf. Consent at install time is not consent per action.

The joint Careful adoption of agentic AI services guidance, co-authored by the NCSC and agencies in the US, Australia, Canada and New Zealand and first published on 1 May 2026, names the pattern. It warns that "if entitlements are evaluated only once at system startup rather than at each invocation, a malicious actor can exploit a stale 'allow' decision", and calls for "continuous runtime authentication with centralised policy decision points for each action". Meta's own post shows per-action approval can be built inside an app. In the Apple pages we read, the operating-system permission has no such step.

Earlier briefings share the thread. CloudSyncD turned on one typed password, a human prompt doing the work of a control. Glow's count of more than 13,000 internal images that AI agents put in public GitHub repositories covers neighbouring ground: a capability granted for one purpose and used by software for another. And Poper Blocker showed AI chats already being a collection target. Judgement: none of these proves anything about Full Disk Access. They show the same design question, who is asked, when, and about what.

UK angle: what UK guidance covers, and what it does not

No source we read names a UK victim, sector or organisation. The UK material here is about controls. One caution about the starting point: we assume, with no UK figure behind it, that developers, creative teams and legal teams are among the likeliest to install desktop agents, because their work sits in local files and mail. Treat that as illustration.

We searched ncsc.gov.uk on 5 October and found no NCSC publication on Full Disk Access or on Apple's post. The NCSC's macOS device security guidance, version 2.1, reviewed 13 May 2025 and last tested on macOS 14.6 and 15.5 in June 2025, lists essential profiles: encryption and Activation Lock escrow, a 10 minute screen lock, Gatekeeper, automatic updates, startup security, a password policy. It does not mention privacy permissions. The page offers recommended macOS settings from a GitHub repository; on 5 October that folder held a README only, which says the packs are under review and were last tested against macOS 10.16. Its third-party applications guidance says some platforms "may provide the ability to enterprise manage which permissions a third-party application can request, using MDM", which can "prevent risky apps accessing work data". On macOS, the nearest equivalent is the profile route described above, which is our reading, not the NCSC's.

On agents, the NCSC is clearer. The joint guidance recommends "never granting it broad or unrestricted access, especially to sensitive data or critical systems". The NCSC's 20 August blog says that where an agent has access to a host environment, with no compute isolation, "it may also be able to use credentials that are available to the user account under which it is running", and that agent activity should be treated as user activity in security monitoring. The shadow AI blog of 7 September says an attacker who exploits an agent "can gain access to the same data, services, and privileges that the agent has legitimate access to", and cites a study in which 71% of employees reported using unapproved AI tools. Inference: a desktop agent that runs as the user and holds Full Disk Access sits at the bottom level of the NCSC's compute isolation scale. The NCSC does not say this about Full Disk Access.

Cyber Essentials Requirements for IT Infrastructure v3.3, April 2026, asks organisations to "remove or disable unnecessary software (including applications, system utilities and network services)" and to grant users only as much access as their role needs. We searched its text and it names neither Full Disk Access nor app-level operating-system permissions. Judgement: a Mac with an over-permissioned agent could meet the letter of the scheme. Cyber Essentials is a baseline, not an audit of what each app may read.

Data protection: an agent that reads mail and messages reads other people

Apple's own sentence is the data protection point: for communication apps, the access "can also compromise the privacy of the people users are communicating with". On a work Mac those people are colleagues, customers, suppliers and counterparties, none of whom agreed to anything.

The ICO's Tech Futures report on agentic AI is the UK primary on this. It says AI agency "does not mean the removal of human, and therefore organisational, responsibility for data processing". On data minimisation: "Organisations should not give agentic AI systems access to information just because it might be useful in the future." It says controls over what an agent can access are "equivalent to the principle of least privilege", that organisations must carry out a data protection impact assessment where they assess that deployment will result in a high risk to people's information, and that transparency duties apply "even if the organisation has no direct relationship with the people whose information they are collecting". It also warns that agents may infer special category data.

Judgement, not legal advice: if an agent holds Full Disk Access on an organisation's Mac, the organisation either decided that, by profile, or allowed it. The mail and messages in reach include third parties' personal data and, for some teams, special category data or confidential client material. Whether the agent's vendor is a processor, a controller or neither depends on terms we have not seen. The columnist says Muse uploads the Messages data it syncs as a data source; whether any given tool does the same must be read from that tool's own documentation. We did not check professional regulators' guidance, for example for law firms.

Seeing who holds Full Disk Access

Apple's pages give a user view and a profile view, and no supported fleet-wide report that we found. The user view is the Full Disk Access list in System Settings. The profile view is whatever your MDM holds for the Privacy Preferences Policy Control payload. Apple's deployment guide also publishes a log command for identifying the process Apple attributes an access to when prompts persist after a profile is deployed. It is a diagnostic, not an inventory.

log stream --debug --predicate 'subsystem == "com.apple.TCC" AND eventMessage BEGINSWITH "AttributionChain"'

Scripts that read the local TCC database are the obvious shortcut, and Apple's macOS 27 notes say apps can no longer access it directly. If your inventory depends on one, ask your MDM or EDR vendor what they support on macOS 27 before you trust a clean result. We did not test any such script. Whether an app granted by profile appears in the Settings list is not stated in the pages we read.

What to do, in the order worth doing it

Cheapest and most revealing first. Nothing here needs an agent tool installed, and none of it waits for Apple.

Take this with you

Checklist for UK organisations that run Macs

  • Inventory first. On a sample of managed and unmanaged Macs, open System Settings, Privacy & Security, Full Disk Access and list every app that holds it. For the fleet, ask your MDM or EDR vendor for a supported report. Do not build the inventory on reading the TCC database, which Apple's macOS 27 notes say apps can no longer access directly.
  • Search your MDM for Privacy Preferences Policy Control profiles that include SystemPolicyAllFiles. For each, record who asked, which app (bundle ID and code requirement) and the business reason.
  • Remove Full Disk Access from tools that do not need it. Apple's own stated purpose is backup apps. Treat every other holder as an exception with a named owner.
  • Never pre-approve Full Disk Access by profile for an agentic tool without a data protection review, and a data protection impact assessment where the processing is likely to be high risk. Apple's reference says a profile grant means the user is not prompted.
  • For agent tools you have not approved, consider a deny entry for their bundle IDs in a profile. Apple says deny wins where payloads conflict. Test it on a pilot Mac first, and note that it does not remove the app.
  • Review each approved agent's own permissions and logs: which connectors are on, which local sources sync (mail, messages, files), where the data goes and for how long it is kept, and whether you can see what the agent did after the event. Treat agent activity as user activity in monitoring, as the NCSC advises.
  • Keep consumer agent apps off work Macs by allow list rather than deny list, as the NCSC's third-party guidance prefers, and offer an approved alternative. The NCSC cites a study in which 71% of employees reported using unapproved AI tools.
  • Wait for Apple's change without relying on it. There is no date, version or MDM statement. Re-read Apple's developer news and the macOS release notes monthly, and re-test a pilot Mac after every macOS update.

What we could not verify

The question this leaves

Apple's promise is that a user will have to act explicitly before an app can read everything on a Mac. On a managed Mac, an administrator's profile can already say yes in advance, and Apple's own documentation says the user is not prompted.

So ask it of your own estate. For each app that holds Full Disk Access today, who said yes, did they know it covers other people's mail and messages, and who would be asked again on the day an agent starts using it?

Key facts

Sources

  1. PrimaryUpdates to Full Disk Access in macOS (2 October 2026). The post this briefing is about; read in full, every quotation taken from itApple Developer Newsaccessed 2026-10-05
  2. PrimaryPrivacyPreferencesPolicyControl.Services: the 24 privacy services, including SystemPolicyAllFiles and the four where a profile can only deny; macOS 27 deprecationsApple Developer Documentationaccessed 2026-10-05
  3. PrimaryPrivacyPreferencesPolicyControl.Services.Identity: the Allowed and Authorization keys, 'The user isn't prompted', helper-tool inheritance, deprecation from macOS 27.0Apple Developer Documentationaccessed 2026-10-05
  4. PrimaryPrivacyPreferencesPolicyControl payload: conflict rule (deny wins), user-approved MDM, supervision marked not applicableApple Developer Documentationaccessed 2026-10-05
  5. PrimaryAppSettings declaration (macOS 27+): the consent-prompt privacy permission defaults, which list no file accessApple Developer Documentationaccessed 2026-10-05
  6. PrimaryPrivacy Preferences Policy Control payload settings (published 29 July 2024): System Policy All Files description, example comment, supervision wording, log commandApple Platform Deploymentaccessed 2026-10-05
  7. PrimaryChange Privacy & Security settings on Mac (macOS 27): how Full Disk Access is described and how a user adds an appApple Mac User Guideaccessed 2026-10-05
  8. PrimaryAllow access to system configuration files: the page The Hacker News links for the setting; points to the Full Disk Access paneApple Mac User Guideaccessed 2026-10-05
  9. PrimaryControlling app access to files in macOS: full storage access must be 'explicitly added' in System SettingsApple Platform Securityaccessed 2026-10-05
  10. PrimarymacOS 27 Golden Gate Release Notes: app data container denials, the Full Disk Access workaround, TCC database no longer directly accessible to appsApple Developer Documentationaccessed 2026-10-05
  11. PrimarymacOS Mojave is available today (24 September 2018): release date used for the age arithmeticApple Newsroomaccessed 2026-10-05
  12. PrimaryMeta's New Muse AI Agent Read My Private Messages. I Never Asked It To (19 September 2026): the opinion column behind the Muse story; read in fullInc.accessed 2026-10-05
  13. PrimaryMeta Keeps Apologizing For Muse. Its Explanations Miss the Point Entirely (23 September 2026): the follow-up column; read in fullInc.accessed 2026-10-05
  14. PrimaryDavid Singleton's replies of 19 September 2026: the Full Disk Access plus Messages connector statement and the columnist's replyThreadsaccessed 2026-10-05
  15. PrimaryHow We Built Safety Into Muse (8 September 2026): Sentinel and approval grant types; searched for macOS, Messages, notification and Full Disk Access terms, no matchMeta AI Researchaccessed 2026-10-05
  16. PrimaryCareful adoption of agentic AI services (1 May 2026): privilege risks, stale allow decisions, per-action authenticationAustralian Cyber Security Centre, with CISA, NSA, Canadian Cyber Centre, NCSC-NZ and NCSC-UKaccessed 2026-10-05
  17. PrimaryManaging the cyber risk of agentic AI (20 August 2026): compute isolation levels, credentials available to the user account, monitoringNCSCaccessed 2026-10-05
  18. PrimaryThinking carefully before adopting agentic AI (15 May 2026): least privilege and human accountabilityNCSCaccessed 2026-10-05
  19. PrimaryThe hidden risks of shadow AI (7 September 2026): attacker inherits the agent's access; the 71% studyNCSCaccessed 2026-10-05
  20. PrimaryDevice security guidance: macOS (version 2.1, reviewed 13 May 2025): essential MDM profiles; no mention of privacy permissionsNCSCaccessed 2026-10-05
  21. PrimaryDevice Security Guidance Configuration Packs, Apple/macOS: README only on 5 October 2026; packs under review, last tested against macOS 10.16NCSC (GitHub)accessed 2026-10-05
  22. PrimaryUsing third-party applications on devices (version 2.1): MDM-managed permissions, allow listsNCSCaccessed 2026-10-05
  23. PrimaryCyber Essentials: Requirements for IT Infrastructure v3.3 (April 2026): secure configuration and user access control wordingNCSCaccessed 2026-10-05
  24. PrimaryICO tech futures: Agentic AI, data protection and privacy risks: controllership, minimisation, DPIA, transparencyInformation Commissioner's Officeaccessed 2026-10-05
  25. Reported byApple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access (5 October 2026): the pointer story; its Muse framing is checked against the Inc. columnsThe Hacker Newsaccessed 2026-10-05
  26. Reported byApple tightens macOS disk access as AI agents become more powerful (5 October 2026): second pointer; no rollout date or detailHelp Net Securityaccessed 2026-10-05
  27. Reported byApple says it's tightening macOS 'Full Disk Access' controls (2 October 2026): timing and what Apple did not sayTechCrunchaccessed 2026-10-05
  28. Reported byMeta disputes claim that Muse read a user's private messages without permission (30 September 2026): Meta communications statementTechCrunchaccessed 2026-10-05
  29. Reported byApple Announces Full Disk Access Changes (2 October 2026): Muse and Dots named by the outlet, not AppleMacRumorsaccessed 2026-10-05

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

How often

Every new briefing in one email, at 7am, or at 7am, 12:30pm and 6pm. Nothing is sent when nothing is new. Unsubscribe any time.