Apple sounds the alarm on AI agents and “full disk access”

Apple sounds the alarm on AI agents and “full disk access”

Apple is adding new safeguards to how “full disk access” works in macOS to address the growing risk posed by AI agents. In an update, the company warned that the increasingly popular tools “could put users at risk” and that it would add “additional controls” to the process to ensure users are aware of what they are doing when granting such “extraordinary” access to software.

The company did not specify when the update would be rolled out or what exactly would change from the current configuration. But in its note, the Cupertino company suggested that some AI agent developers are not being upfront with users about the privacy tradeoffs of using their software.

“Some developers are using full disk access in a way that could put users at risk, by exposing everything on their systems, including files, mail, messages, and even browsing history, without users’ knowledge or understanding,” the company said. “For communications applications, it may also compromise the privacy of people with whom users communicate.”

Desktop clients for AI agents, like OpenClaw, Dots, and Muse, often encourage users to grant “full disk access” so agents can access their files, messages, and other data. This allows AI agents to perform more types of tasks, but it also carries significant risks. That’s why some people choose to use agents on dedicated machines, which has helped fuel the Mac Mini shortage this year.

More recently, the question of full disk access for agents has arisen again with the rise of Meta’s AI agent, Muse. Although Apple doesn’t specifically cite Muse or Meta, its warning comes after some users reported that Muse took unintended actions with their data. Jason Aten, tech columnist for Inc. recently explained how the Muse Mac app was able to access his messages even though he thought he had denied permission. Meta responded by saying that if his messages were synced, he must have signed up.

Apple, it seems, wants to add extra friction to make sure people are aware of what they’re allowing their agents to see. “In the future, we will introduce additional controls to ensure that users who actually want to grant an app this extraordinary level of access can only do so with very explicit user action,” the company said. “Addressing this issue is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will increase significantly. We are committed to ensuring that users clearly understand these risks before granting such access, so that they can make informed decisions about their own data and privacy.”

Similar Posts