Tech & AI

Apple Clamps Down on Mac Privacy Setting as AI Agents Raise New Security Fears

Published

on

Apple is tightening one of the quietest but most powerful privacy controls on the Mac, citing the growing risk that desktop AI agents pose to users’ personal files, messages and browsing history. The company announced it will add new safeguards around “Full Disk Access,” a macOS permission that, once granted, effectively hands an app the keys to everything stored on a computer.

The setting has existed for years, largely in the background, designed to let backup software and system utilities do their jobs without constantly prompting users for permission. But Apple says that purpose has been overtaken by a new generation of AI tools that act less like passive programs and more like autonomous assistants capable of reading, interpreting and acting on whatever data they can reach.

“Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems…without users’ full knowledge and understanding,” Apple wrote in a blog post aimed at developers. The company said it would require “very explicit user action” before granting an app this level of access going forward, rather than allowing it to be buried in a settings toggle a user might not fully understand.

Apple’s announcement follows a string of unsettling incidents involving AI software on the Mac. Inc. columnist Jason Aten recently reported that Meta’s AI-powered Muse app appeared to know the contents of his private messages, despite his belief that he had never authorized that level of access. Meta has disputed the characterization of what happened, but the episode fueled broader anxiety about how much trust users are implicitly placing in desktop AI tools that request sweeping system permissions.

Advertisement

Compounding the concern, a separate report from Wired detailed a security flaw in OpenAI’s ChatGPT app for Mac that researchers said could have let hackers access sensitive user data. Taken together, the incidents paint a picture of a security model built for a simpler era of software — one where apps mostly did what users told them to, rather than independently parsing files, conversations and histories to act on a user’s behalf.

That shift is precisely what worries Apple. Full Disk Access was never meant to be handed out casually; it exposes mail, messages, files and even a user’s browsing history to whatever app receives it. In the past, that risk was largely theoretical for most consumers, since the apps requesting it were typically narrow-purpose backup or security tools. AI agents change the calculus because they are explicitly designed to roam across a user’s data, synthesize it and take action — which is exactly the kind of capability that makes an over-permissioned app dangerous if it misbehaves, gets compromised, or simply oversteps what a user actually intended to allow.

“As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially,” Apple said. “We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.”

Apple did not respond to a request for further comment on exactly how the new controls will work or when they will arrive for developers and users. But the move signals a broader reckoning taking shape across the tech industry as AI agents move from cloud-based chatbots into deeply embedded, on-device assistants with far-reaching permissions.

Advertisement

The tension is not unique to Apple’s ecosystem. As companies race to make AI agents more “agentic” — capable of booking appointments, managing files, drafting messages and acting across apps without constant supervision — the very usefulness of these tools depends on giving them access to sensitive personal data. That creates an uncomfortable trade-off: the more autonomous and helpful an AI agent becomes, the more catastrophic the consequences if its access is abused, hijacked, or simply misunderstood by the person who granted it.

For now, Apple’s answer is friction: making sure users can’t stumble into granting an AI agent total access to their digital life without a clear, deliberate choice. Whether that is enough to keep pace with how quickly AI agents are gaining capability — and how aggressively some developers are pushing for deeper system access — remains an open question, one that is likely to keep surfacing as more of these tools compete for a permanent, privileged place on people’s desktops.

Sources:

You must be logged in to post a comment Login

Leave a Reply

Cancel reply

Trending

Exit mobile version