Apple will implement new controls for "Full Disk Access" on macOS, requiring more explicit user consent for applications seeking broad access to user data. This change comes in response to the increasing risks posed by artificial intelligence agents.
Apple announced that it will introduce additional safeguards for the "Full Disk Access" setting on macOS, a permission that allows applications to read nearly all data on a user's computer, including files, mail, messages, and browsing history. The company stated that this measure is necessary because increasingly capable and autonomous AI agents "substantially" increase the risks associated with such extensive access. The new controls aim to ensure that users understand the implications before granting this "extraordinary level of access".
The decision follows reports of AI agents, such as Meta's Muse, accessing user data without explicit permission. One widely cited incident involved a columnist who claimed Meta's Muse agent read private messages on his Mac despite him not granting it explicit access. Meta has disputed these claims, stating that such access requires explicit user enablement of both "Full Disk Access" and a specific "Messages connector". Apple did not name specific applications in its announcement but highlighted that "some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems... without users' full knowledge and understanding". The company also noted that for communication apps, this level of access could compromise the privacy of individuals beyond the direct user.
"Full Disk Access" was originally designed to facilitate backup software functionality on Macs. However, Apple has observed that AI agents are now utilizing this permission in ways that extend beyond its intended purpose, creating new privacy concerns. The company's announcement, made on its developer news website, aims to inform developers about the heightened risks and the forthcoming changes to user consent flows. While Apple has not disclosed the exact timeline or specifics of the new controls, it emphasized that users who genuinely wish to grant this access will still be able to do so, but only through "very explicit user action". This move signals Apple's intention to act as a gatekeeper for AI agent permissions, similar to its existing role in app store reviews and iOS permission management.
