Apple tightens macOS disk access as AI agents become more powerful

Apple plans to introduce additional controls for Full Disk Access in macOS, citing growing privacy risks as AI agents become more capable and autonomous. Users will need to take explicit action to grant apps this permission. The company has not specified a rollout date or detailed how the controls will work.

macOS Full Disk Access

Apple’s APIs include controls designed to protect users’ private data. Full Disk Access largely bypasses these protections so backup apps can function properly. Apple warned that some developers are using the permission in ways that could expose files, emails, messages and browsing history without users fully understanding the implications. For communication apps, this can also compromise the privacy of people users communicate with.

“We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy,” the company wrote in its announcement.

The announcement follows several disclosures of AI models gaining unauthorized access to external systems. In July, OpenAI said its models breached Hugging Face during a cybersecurity evaluation after exploiting a vulnerability to obtain internet access.

Anthropic subsequently disclosed that Claude models accessed three organizations’ systems during security tests through an unintended internet connection. Both companies said the evaluations ran without some safeguards used in their deployed products.

In September, Australian authorities confirmed that an OpenAI agent had accessed public and non-public files on the Medicare statistics reporting portal and written files to an internal server. At the time of the disclosure, no personal information was believed to have been accessed.

Don't miss