Apple tightens macOS safeguards as AI agents seek access to sensitive data
Developing story first seen 1 hour ago
Apple is introducing new safeguards to how "Full Disk Access" works in macOS, responding to growing concerns about artificial intelligence agents accessing sensitive user data without full transparency. The company warned that AI developers have been requesting this extraordinary level of access to users' files, messages, browsing history and other data without being sufficiently upfront about the privacy risks involved.
AI agent applications such as Meta's Muse, OpenClaw and Dots require Full Disk Access to perform more complex tasks, but this also grants them unprecedented visibility into users' personal information. The issue came to a head recently when a tech columnist reported that Meta's Muse app accessed his messages despite him believing he had denied permission; Meta claimed he must have opted in. Apple will add additional controls requiring users to take explicit action before granting such access, though the company has not yet announced when this update will be rolled out.
- Apple adding safeguards to Full Disk Access for AI agents to protect user privacy.
- AI apps like Meta's Muse access files and messages without users' full knowledge or understanding.
- New controls will require more explicit user action before granting extraordinary system access to software.
New here? Start with this
Apple's macOS operating system allows applications to request special permissions to perform certain functions. One of the most powerful permissions available is called Full Disk Access, which gives an application the ability to access everything stored on your computer, including personal files, messages, emails, web browsing history and other sensitive data. Most everyday applications do not require this level of access.
Artificial intelligence applications, known as AI agents, are increasingly asking for this extensive access to perform complex tasks. These programmes need Full Disk Access to search through your files and information in order to assist you effectively. The concern is that developers have not been sufficiently clear about what data their applications will access or how it might be used, raising questions about privacy and data security.
The privacy risks became more apparent recently when users noticed that AI applications were accessing their personal data in ways that were not fully transparent. Meta's AI assistant, for instance, was reported to have accessed a user's private messages in a manner that prompted questions about whether the user had properly consented. These incidents have highlighted how easily users might grant powerful permissions without fully understanding what they are enabling.
Both sides, in good faith
The strongest fair case each way — we don't pick a winner.
The case for
AI developers argue that broad system access is a technical necessity for agents to perform genuinely useful tasks like automating complex workflows, managing files across applications, and providing comprehensive productivity assistance. They contend that Full Disk Access permissions already exist and users who grant them have explicitly agreed to the access involved; adding further friction to this process may handicap innovation in AI tools that could benefit millions of users, whilst existing permission systems already give users ultimate control over what gets installed.
The case against
Privacy advocates argue that most users do not meaningfully understand what Full Disk Access entails and the scope of data exposure it creates, particularly with autonomous AI agents that can learn from and potentially act upon sensitive information. The current system places responsibility on users to grasp complex technical implications, creating an asymmetry of knowledge that sophisticated developers can exploit, as evidenced by incidents where even technically-aware users were confused about what they had permitted. Additional safeguards requiring explicit acknowledgement of privacy risks represent a reasonable step toward genuine informed consent without preventing legitimate access.
More coverage
Read the full article at the source →
Originally published by Engadget as “Apple sounds the alarm on AI agents and ‘Full Disk Access’”.