Apple to Tighten macOS Full Disk Access Controls as AI Agents Raise Privacy Risks
Introduction
Desktop AI agents are moving beyond chat interfaces. They can read local files, work with applications, and use personal information to complete tasks. That broader capability is putting new pressure on operating-system permission models. Apple says it will introduce additional controls around macOS Full Disk Access, with the stated goal of making consent more deliberate and understandable.
Key points
- Full Disk Access was designed for software, including backup tools, that needs unusually broad access to a Mac.
- The permission can expose files, mail, messages, and browsing history to an application.
- Apple says some developers are using the permission in ways that could expose users’ systems without their full understanding.
- Future controls will require users who genuinely want to grant this access to take a very explicit action.
- Apple has not disclosed the exact interface or rollout timetable.
- The announcement follows a disputed claim that Meta’s Muse knew the contents of private messages, as well as a Wired report about a flaw that could have exposed sensitive data through ChatGPT’s Mac app.
Consent is becoming part of the security boundary
Apple’s statement does not say that Full Disk Access will be removed or broadly capped. Instead, it focuses on the way users approve it. Historically, an application could receive the permission after a user enabled a setting in macOS. That model has a clear use case for backups and other system-level utilities, but it becomes more complicated when the application is an AI agent that can interpret instructions, retrieve information, and take actions across multiple applications.
There is a meaningful difference between an application reading a designated folder and an agent searching across a computer for relevant messages, documents, or browser history. The agent may be acting on a legitimate request, but its access can also be affected by product design, software bugs, prompt injection, or an overly broad interpretation of the user’s instructions. The source material does not specify what Apple’s new controls will do, so it would be premature to describe the change as a new technical limit. The more precise reading is that Apple wants to raise the bar for informed consent.
What changes for developers and users
Developers that rely on Full Disk Access may need to rethink when they request it, how they explain the need, and whether a narrower permission can support the same task. Products that minimize collection and keep access limited to the current job may be easier for users to evaluate and trust.
Users should also treat a request for Full Disk Access as a significant security decision, not as an ordinary setup step. Before approving it, they should consider why the application needs access to mail, messages, and browsing data, whether the information is retained, and whether it is transmitted to a remote service.
The broader issue extends beyond model quality. For desktop agents, the real safety boundary includes the operating system, application isolation, data flows, and the clarity of permission prompts. As agents become more autonomous, granting access to an entire digital life requires more than a hidden switch; it requires a clear explanation and an unmistakable decision.
Source: TechCrunch AI
Comments
Checking sign-in status...
Loading comments...