AI GlossaryㅈSafety and controversy
Full Access Mode
An operating state in which a coding agent can access, modify, and even delete every file on a computer without the user's approval.
In plain words
Full Access Mode is a bit like handing a cleaner who's been hired to tidy your house a master key that opens every room. Normally, if you ask the cleaner to 'just clean this one room,' they should only get the key to that room. But in Full Access Mode, they're holding a key that opens every door in the house. If the cleaner mistakenly throws away something in the wrong room, there's nothing stopping them.
AI coding agents are put in charge of running code and organizing files on a user's behalf. When the agent's reach is limited to a specific folder — often called a sandbox — any damage from a mistake stays contained within that folder. But once the agent switches into Full Access Mode, it can touch the entire system, so a single flawed command can spiral into wiping out a user's documents or configuration files across the whole machine.
That's why Full Access Mode comes bundled with both convenience and risk. Developers typically add safeguards to keep this mode from turning on by accident, and to require an extra confirmation step for dangerous commands even when it is on.
How it shows up in the news
As it appeared in the article: 'The fact that Codex could shift into Full Access Mode — gaining access to the entire file system depending on the situation — was also cited as a factor that widened the scope of the damage.' A common misunderstanding here is that Full Access Mode isn't bad simply because it's a uniquely dangerous feature — the real problem was that developers and users had no control over when the mode got switched on. OpenAI didn't remove the mode itself; it redesigned the trigger conditions that could accidentally activate it.
Try it yourself
If you're using a coding agent, it's worth checking the following:
- Check your settings to confirm you're running in restricted (sandboxed) access mode rather than Full Access Mode.
- Before handing off hard-to-reverse tasks like deletions or bulk cleanups, back up your files separately.
- When granting permissions to an agent, scope it to the specific subfolder it needs rather than the entire project directory.
See also
Stories using this term
- OpenAI patches Codex file-deletion bug caused by temp-folder cleanup commandAI · 2026.08.20
- Claude Security scans code with new Mythos 5 modelAI · 2026.08.22
- Claude Code hooks block rule-skipping with codeAI · 2026.09.04
- Claude Code reveals six ways to steer hours-long tasksAI · 2026.09.04
- Claude Code drops npm install in favor of script-based installationAI · 2026.08.24
- Copilot confessed its own bypass password when repeatedly questionedBusiness · 2026.08.19
