Abstract:
Apple recently announced that it will further tighten the "Full Disk Access" permission control in macOS and plans to add new security mechanisms to reduce the privacy risks that may arise after AI agents gain access to a wide range of system data.

Apple said that "full disk access" was originally mainly to allow backup and other software to work properly, but as AI agents that can operate computers autonomously become more and more popular, the risks posed by this permission are significantly increasing. Apple believes that when an AI agent obtains this level of system access, its potential impact is different from that of traditional applications, so users must be more clear about what permissions they have granted to the application.
macOS currently allows users to manually grant applications "Full Disk Access" permission in the "Privacy and Security" of the system settings. After obtaining this permission, the application can access a large amount of sensitive data on the user's computer, including files, emails, messages, browsing history, etc. Apple has long required that such permissions must be actively authorized by the user.
The problem is that there are obvious differences in how traditional applications and new generation AI agents use these permissions. The AI agent can not only read files, but also perform a series of operations autonomously based on user instructions. When it simultaneously gains access to data such as files, messages, emails, etc., the AI model may actually possess a very wide range of user digital life information.
In a note to developers, Apple pointed out that some developers are using "full disk access" in a way that may put users at risk, resulting in apps being able to access a large amount of content on the user's device, and the user himself may not fully understand what this permission means.
As a result, Apple plans to add new controls starting in the future. For those apps that do require this "extraordinary level" of access, users will need to take more explicit action to grant permission. Apple hopes that by raising the authorization threshold and strengthening prompts, users will have a clearer understanding of what data an app can access before making a decision.
This change follows a series of incidents related to the security of Mac-side AI agents.
Recently, the Mac version of the AI agent Muse launched by Meta triggered a privacy controversy. Journalist Jason Aten claimed that Muse was able to read his private information, and he believed that he did not grant the corresponding permissions to the application. Meta subsequently denied that Muse could read the content in Messages without user authorization, and stated that the Messages function of the Mac version of Muse is completely opt-in. Users must turn on "Full Disk Access" and the Messages connector at the same time for Muse to read relevant content.
Meta also explained that Muse needs to go through multiple application layer and macOS system level permission steps to read Messages. Even if the application itself has vulnerabilities, it cannot bypass these system protections. However, related controversies have still raised concerns about the boundaries of desktop AI agent permissions.
Apple's announcement to adjust permission control does not mean that Muse has indeed bypassed the security mechanism of macOS, but it reflects that Apple is re-evaluating the new risks brought by AI agents from the operating system level.
In fact, this is not the first time Apple has redesigned the security mechanism for AI agents. At this year's WWDC, Apple has demonstrated a new security architecture for Xcode and AI coding agents. The new mechanism allows agents to access project files in a more restricted environment. When an agent attempts to read or write files, the system-level mechanism determines whether to allow the operation based on preset policies; if user authorization is required, the system explicitly makes a request.
At the same time, there have been recent reports of security vulnerabilities involving the Mac version of ChatGPT. The app reportedly had vulnerabilities that could have allowed attackers to obtain sensitive data. Although the specific vulnerability mechanism is not exactly the same as "full disk access", these incidents together illustrate that when AI applications transform from traditional chat software to "agents" that can directly operate computers, the risks faced by the traditional application permission system are changing.
One of the biggest differences between AI agents and ordinary applications is that they can not only perform one-time operations, but also complete tasks continuously based on context. For example, users can ask the agent to read files, organize information, modify documents, query emails or messages, and then proceed to the next step based on the results. If the scope of permissions is large enough, this means that an AI agent may continuously access and process large amounts of personal data without the user's intervention on an item-by-item basis.
Apple therefore specifically emphasizes that as AI agents become more autonomous and powerful, the risks posed by "full disk access" will increase significantly. Apple said its goal is not to prevent users from granting broad permissions to AI applications, but to ensure that users who really want to do so can complete the authorization through very clear actions and fully understand the data privacy risks they are taking.
This change also shows that AI agents are driving new changes in the security model of the operating system. In the past, system security mainly focused on whether a certain application can access a certain file, camera or microphone. In the future, the focus may further shift to "what an AI system that can act autonomously can do on behalf of the user."
For Apple, this means macOS needs to establish new permission boundaries between the convenience of AI agents and system security. As more and more AI products begin to be directly integrated into desktop operating systems, how to provide agents with the capabilities required to complete complex tasks while avoiding a single authorization that exposes the entire personal digital environment is becoming a new problem that operating system manufacturers must solve.
Comments