Apple announced on Friday that it will implement enhanced controls for the "Full Disk Access" permission within macOS. The company cited the growing capabilities of AI agents as a primary driver for this change, warning that broad access to user data presents escalating risks. This move aims to ensure users are fully aware of the implications when granting such extensive permissions to applications.

The "Full Disk Access" feature on macOS allows applications to bypass standard security restrictions and access all files on a user's system. While this has been necessary for certain functions, such as backup software, Apple stated in a developer update that some developers are utilizing this broad access in ways that could endanger users. The company noted that this could expose sensitive information including files, emails, private messages, and browsing history without the user's complete knowledge. Furthermore, for communication applications, this level of access can also jeopardize the privacy of the individuals users are communicating with.

"As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially," Apple communicated in its developer update. The company emphasized its commitment to ensuring users clearly understand these risks before granting such access, enabling them to make informed decisions regarding their data and privacy. Apple did not specify when these new controls would be implemented.

This decision follows recent concerns surrounding AI agents, such as Meta's Muse application. Reports have surfaced of users experiencing unintended access to their private messages and emails by AI agents, even when explicit permission was believed to have been denied. Apple's announcement acknowledges these developments without naming specific applications or companies. The company indicated that the broad access granted by "Full Disk Access" largely sidesteps the standard security controls designed to protect user data.

Apple's existing security framework generally restricts applications to specific areas of the file system. Users can grant broader access, such as reading and writing to user-selected documents, or sharing files between applications. However, "Full Disk Access" represents a more significant delegation of authority. The company stated that the new controls are intended to ensure that users who genuinely wish to grant this "extraordinary level of access" must do so through "very explicit user action".

The move by Apple reflects a broader trend of increasing scrutiny on how AI applications handle user data. As AI agents become more integrated into operating systems and perform more complex tasks, the need for transparent and explicit user consent becomes paramount. The company's action suggests a shift towards making the interface itself a more integral part of the security model, requiring developers to be clearer about the scope and implications of the permissions they request.