Cybersecurity

Apple will make you prove you mean it before an AI agent reads your whole Mac

Adrian Kessler
Add us on Google

Apple is closing an easy route into everything stored on a Mac. Full Disk Access, the macOS permission that lets a single app read your files, mail, messages and browsing history in one go, will soon require what Apple calls very explicit user action before anyone can switch it on. The reason the company gives is new, and it is AI agents.

That matters if you have installed, or are thinking about installing, a desktop assistant that promises to clear your inbox or answer questions about your own life. Those tools work best when they can see everything, and several of them ask for exactly this permission during setup. Apple’s warning to users is plain. An agent holding this key can see far more than the task in front of it, including the private words of the people who write to you.

In a note to developers, Apple said Full Disk Access largely sidesteps the privacy controls macOS normally uses, and that it exists so backup apps can copy an entire drive. Some developers, it wrote, now use it in ways that expose everything on a user’s system without their full knowledge and understanding. For communication apps, Apple added, that can also compromise the privacy of the people users talk to, and the risk will grow substantially as agents become more capable and autonomous.

The statement landed days after a public dispute over Meta‘s Muse. Jason Aten, a columnist at Inc., reported that the Muse agent on his Mac mini surfaced details from his private Messages history, including a note from his editor, even though he says Full Disk Access was switched off. Meta disputes that account. Its executive David Singleton has said three separate layers of app and system permissions stand between Muse and a user’s messages, and that the macOS protections cannot be bypassed even by a bug in the app. Apple’s note names no app.

Muse is not the only agent that wants the keys. Engadget lists OpenClaw and OpenAI‘s Dots among desktop clients that encourage users to grant the same access, and TechCrunch pointed to a separate Wired report on a flaw in ChatGPT’s Mac app that could have exposed sensitive data. Some people have gone further and bought a second Mac mini purely to run an agent, keeping it away from the computer that holds their real life.

The announcement leaves the hard questions open. Apple gave no macOS version, no date and no description of the new controls, so nobody knows yet whether explicit means an extra confirmation screen, a password prompt or a trip into System Settings with a warning attached. Friction also cuts both ways. Backup software, antivirus tools and file-search utilities rely on the same permission for legitimate reasons, and a gate stiff enough to slow a careless agent will also slow a cautious user restoring a drive. Nor does a stricter switch help much if people keep clicking through prompts they do not read, which is how many of these grants happen today.

The change covers macOS itself, so it will reach every Mac regardless of country once it ships, unlike most agent features, which roll out market by market. Developers whose apps depend on Full Disk Access have not been told what they will need to change.

Apple posted the notice to developers on October 2 and said only that the controls will arrive going forward. Until a macOS update carries them, the existing list under Privacy & Security in System Settings is the only thing standing between an agent and your message history, and it shows every app that already holds the key.

Tags: , , , , ,

Add us on Google

Discussion

There are 0 comments.