Apple has announced tightened Full Disk Access controls in macOS in light of the risks posed by continuously evolving AI agents.
Apple introduced Full Disk Access in macOS Mojave (10.14) to provide users with control over applications’ access to the entire system. The feature can be toggled on or off from Apple menu > System Settings > Privacy & Security.
By default, macOS restricts applications from accessing system-protected areas and sensitive user data. Granting an application Full Disk Access waives these protections, allowing that software to read or modify private files, including a user’s mail, messages, and browsing history.
Improperly managed Full Disk Access permissions may result in malicious applications gaining access to sensitive information, and Apple is now planning tightened controls around it, as AI agents and modern applications are increasingly requesting Full Disk Access.
According to Apple, some applications are using Full Disk Access in ways that could put users at risk by exposing their files, mail, messages, and browsing history without users’ full knowledge and understanding.
“For communication apps, this can also compromise the privacy of the people users are communicating with,” Apple said on Friday.
Citing risks posed by more potent AI agents, the company will introduce additional controls ensuring that applications are provided with this level of access only with the users’ explicit consent.
“As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy,” Apple said.
The company did not specify when the additional controls will be rolled out, nor did it say what exactly determined it to introduce them.
Two weeks ago, tech journalist Jason Aten revealed that Meta’s personal assistant Muse accessed his private iMessages even though he believed Full Disk Access was disabled. Meta executives disputed the claim, maintaining that both Full Disk Access and a Messages connector must be explicitly enabled.
Related: Social Engineering Detection Moves Into the Live Conversation
Related: Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports
Related: AI Agents Aimed SQL Injection at US and Canadian Government Sites
Related: Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass
