Skip to content
TECH CEO Daily

Apple to tighten Full Disk Access over AI agent risks as Google, Microsoft curb access

Only Apple tied its change to AI agents, but Android 17 and Microsoft's Entra ID sign-in pages are also cutting off broad access that tools rely on.

By · Editor

· 4 min read · Fact-checked

The 60-second brief

  • 1Apple said on October 2 that granting Full Disk Access will require explicit user action, citing growing risks from AI agents.
  • 2Android 17's Advanced Protection limits accessibility services to verified accessibility tools, Google said on October 1.
  • 3Microsoft will block injected scripts on Entra ID sign-in pages from mid-October, BleepingComputer reported.

The news

Apple said on October 2 that it will add controls so Mac users can grant Full Disk Access, the macOS permission that lets an app reach nearly everything on a computer, only with explicit user action. It said AI agents will make that access riskier.

In a post for developers, Apple said the permission largely sidesteps the privacy controls on its other interfaces so that backup apps can work. Some developers, it said, are using it in ways that expose files, mail, messages and browsing history without users' full knowledge, which for communication apps can also compromise the privacy of the people users talk to. Apple did not say which macOS release will bring the change or when.

Apple wrote that as AI agents grow more capable and autonomous, the risks of this level of access "will grow substantially." The post came days after Inc. columnist Jason Aten reported that Meta Platforms' (META) Muse app knew the content of his private messages though he said he had not given it permission, a claim Meta disputed, TechCrunch reported. Muse optionally lets users turn on Full Disk Access, TechCrunch noted, and Wired had reported a flaw in ChatGPT's Mac app that could have allowed hackers to reach sensitive data.

Google moved on a parallel track. In Android 17, turning on Advanced Protection, a mode Google offers for at-risk and security-conscious users, automatically restricts AccessibilityService access to verified apps categorized as Accessibility Tools, the company said in an October 1 blog post. Google said attackers abuse accessibility services to read sensitive data, install malware or block uninstallation. The Hacker News reported that tools such as screen readers keep working and framed the change around banking trojans and spyware; Google's post did not mention AI agents.

Microsoft will start enforcing a Content Security Policy, a browser rule that limits which scripts a page may run, on Entra ID sign-in pages from mid-October 2026 and finish by late October, BleepingComputer reported, citing a Microsoft 365 message center notice. Only scripts from trusted Microsoft content delivery domains will run during browser sign-ins at login.microsoftonline.com. Microsoft told administrators to stop using browser extensions and tools that inject code or scripts into sign-in pages; the Microsoft Authentication Library and API-based sign-ins are not affected.

Only Apple tied its move to AI agents. Google cited malicious apps, and Microsoft cited cross-site scripting and credential theft. But all three changes narrow broad access that any software, harmful or not, can use to read a user's data or act on the user's behalf.

The numbers

Entra ID sign-in script blocking rollout
Mid- to late October 2026
When Microsoft first announced the Entra ID change
November 2025
Android 17 Intrusion Logging retention (optional)
12 months

Why CEOs should care

Mac fleet owners should inventory which apps hold Full Disk Access now, from backup tools, which Apple says the permission exists to serve, to any desktop AI agents employees have installed, and decide which truly need it. Apple has not said whether the new controls will change how access is granted through device-management profiles, so IT teams should ask their mobile device management vendor and their Apple contacts, then test agent and backup tools on each new macOS build.

Identity teams face the nearest deadline. Microsoft's rollout runs from mid- to late October 2026, so check now, before it reaches your tenant, for anything that injects scripts into Microsoft sign-in pages: browser extensions, sign-in helpers, testing tools and any browser automation, including agent tools, that works that way. Microsoft says users will still be able to sign in but such tools will stop working, so test first or expect a wave of help-desk tickets.

For chief information security officers (CISOs) and boards, the trend helps defense but carries a cost. Each change closes a path attackers use, and each can break tools the business relies on. Write a permission policy for AI agents now: which data they may reach, which accounts they run under, and who approves broad grants such as Full Disk Access. For executives and other high-risk staff on Android 17 devices, test Advanced Protection and check which apps lose accessibility access.

The bigger picture

AI agents that run on a desktop or in a browser are only as capable as the permissions they are given. Apple's statement signals that platform owners intend to decide how much of that access is on offer and on what terms, rather than leaving it to each app and each user's click.

That creates a trade-off for companies building agents. Broad permissions such as Full Disk Access make products more useful, and they also draw platform restrictions and user suspicion, as the dispute over Meta's Muse shows.

What’s next

Watch for Apple to name the macOS release that carries the new controls and explain how the explicit approval will work, for Microsoft's enforcement window between mid- and late October, and for Android 17 users with Advanced Protection to receive the notification Google says will appear when the new features reach their devices.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

AppleGoogleMicrosoftAI agentsEndpoint security

Earlier coverage of Apple

All Apple coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.