Apple tightens macOS Full Disk Access controls, citing substantially increased risks from AI agents
Apple announced it will tighten Full Disk Access permissions on macOS, citing substantially increased security risks from increasingly capable AI agents. The company warned that broad access to users’ files, messages, mail, and browsing history has become more dangerous as AI agents can autonomously exploit such permissions. Apple will flag AI requests for Mac data and impose new restrictions on developers. The move follows complaints about Meta’s AI agent, Muse, reportedly accessing user data without clear consent. No specific timeline for the new controls was provided.
IllustrationEditorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page reads the event directly, while its address stays stable when the title changes.
- Summary covers the current reports
Cross-source coverage
Common ground
- Apple's new controls are marginally better than nothing but still insufficient.
- The credential harvesting vector—where an AI agent steals your iCloud password once to access everything—is a major blind spot that neither side fully addressed.
- Time-limited, scope-limited permissions that expire after task completion are needed but missing from Apple's approach.
- The three-year lag between security researchers flagging dynamic permission abuse and Apple acting shows the company was reactive, not proactive.
Points of contention
- Whether Apple's move is a genuine security improvement or just a PR-driven response to a scandal.
- Whether Apple's walled garden is about protecting users or maintaining control and a 30% tax on developers.
- Whether sideloading on macOS proves Apple isn't a gatekeeper or is just a technicality that ignores integration barriers.
- Whether permission inheritance is a bug Apple is fixing or a feature of their business model.
Blind spots
- No one has a solution for the credential harvesting vector, where an AI agent steals your iCloud password to access everything through Apple's own APIs.
- The debate ignored the need for independent oversight, mandatory transparency reports, and user education that doesn't come from a company profiting from confusion.
- Neither side addressed how to make permissions time-limited and scope-limited so they expire after an AI agent's task is done.
WorldAttention’s read
Apple's new controls are a small step forward, but they're mostly theater—they don't fix the real threat of credential harvesting, where an AI agent just needs your iCloud password once to access everything. Both sides agree that time-limited, scope-limited permissions are needed, but Apple hasn't delivered them. The bigger issue is that we're debating which corporation's profit motive should govern our digital lives, while independent oversight and user education are completely missing. Until we address those structural problems, we're just arguing about which flavor of surveillance capitalism tastes better.
Reporting timeline
Apple tightens Mac full-disk access controls to prevent abuse by AI agents
Apple is implementing new restrictions on macOS 'Full Disk Access' permissions to address security risks posed by AI agents. Multiple news outlets, including Ars Technica, Bloomberg, TechCrunch, Engadget, and MacStories, report that the company is tightening data controls on Macs to guard against potential abuse by AI-powered software. The move comes as AI agents, which can automate tasks and access system resources, present new vectors for data exfiltration or unauthorized access. The changes will impose new controls on developers, requiring them to adhere to stricter permission protocols. The policy shift reflects Apple's proactive stance on security as AI integration in software expands, aiming to prevent malicious or unintended access to sensitive user data stored on Macs.
Apple tightens Mac full-disk access to prevent abuse by AI agents
Apple is implementing new controls on Mac full-disk access permissions to address risks posed by increasingly advanced and autonomous AI agents. The move follows complaints about Meta's AI agent, Muse, which reportedly accessed user data without clear consent. Apple has notified developers that full-disk access to all data on a Mac poses an increasing risk as AI agents become more capable. The company will flag AI requests for Mac data and impose new restrictions on developers seeking such permissions. The policy change aims to curb potential abuse by AI agents that could harvest sensitive user information without proper oversight. Multiple news outlets, including Ars Technica, Reuters, Bloomberg, and MacStories, have reported on the development, highlighting Apple's proactive stance on data security in the age of AI.
Read sourceApple to tighten Mac disk access controls citing increased risk from AI agents
Apple has announced it will tighten 'Full Disk Access' controls on macOS, citing a 'substantial' increase in risk posed by AI agents. Multiple technology news outlets, including The Verge, TechCrunch, MacRumors, Engadget, and Business Insider, report that the company is implementing new privacy safeguards to limit disk access on Mac computers. The move is a direct response to the growing power and capabilities of AI agents, which Apple believes create new vectors for potential data access and security breaches. The changes aim to protect user data by restricting how applications, particularly those leveraging AI, can access the full disk. This represents a proactive security measure by Apple as AI technology becomes more integrated into software and operating systems.
Read sourceShow 2 older updatesHide older updates
Apple Tightens macOS Full Disk Access Controls Citing New Risks from AI Agents
Apple has announced it is tightening 'Full Disk Access' controls on macOS, citing substantially increased risks from AI agents. The company is implementing new privacy safeguards for Mac users as AI agents become more powerful and pose a greater threat to sensitive data. Multiple technology news outlets, including Engadget, MacRumors, The Verge, TechCrunch, and Business Insider, report that Apple is sounding the alarm on the potential for AI agents to exploit full disk access permissions. The changes aim to limit how applications and AI agents can access the entire disk, reducing the attack surface for malicious actors. This move reflects Apple's ongoing commitment to user privacy and security in the face of evolving AI technology that can automate tasks and access system resources more aggressively than traditional software.
Read sourceApple to add new controls for macOS Full Disk Access, citing risks from AI agents
Apple announced it will introduce new controls around macOS's Full Disk Access permission, warning that increasingly capable AI agents make broad access to users' files, messages, mail, and browsing history riskier. The move aims to enhance user privacy and security as AI technology advances. The announcement was made via a post on X, attributed to TechCrunch as the source. No specific timeline for the new controls was provided in the post.