techaisecurityprivacy

Apple Tightens Mac Security as AI Agents Pose New Privacy Risks

Apple introduces stricter controls for Full Disk Access on macOS following privacy concerns about desktop AI agents reading user files without explicit consent.

Apple Tightens Mac Security as AI Agents Pose New Privacy Risks

Apple is making a significant move to protect Mac users from overzealous AI agents that have been granted too much access to their systems. The company announced new controls around a macOS setting called “Full Disk Access,” a feature originally designed to help backup applications function properly. But as desktop-based AI agents have become more capable and autonomous, the risks have multiplied dramatically.

The catalyst for this change came when Inc. columnist Jason Aten reported that Meta’s Muse app on Mac had read his private messages without his explicit knowledge or permission. While Meta disputed the claim, it highlighted a troubling gap between what users think they’re permitting and what these powerful applications can actually access on their machines.

The Full Disk Access Problem

Full Disk Access is a macOS permission that sounds exactly like what it does. When granted, an app can read files, emails, messages, and even your browsing history. It’s a nuclear option for system access, one that should rarely be necessary.

The problem is that some developers have been using this permission in ways that expose everything on users’ systems “without users’ full knowledge and understanding,” Apple explained in a developer-focused blog post. In Muse’s case, users could optionally enable Full Disk Access, but the implications of that choice weren’t always crystal clear.

This issue becomes even more critical when you consider what AI agents are capable of doing. Unlike traditional applications that passively sit on your computer, agents can actively control your system, access your data, and make decisions on your behalf. The autonomy baked into these systems means they need substantial permissions to be useful, but that same power creates extraordinary privacy risks.

A Pattern of Vulnerabilities

Apple’s announcement comes on the heels of other concerning discoveries. A Wired report revealed that a flaw in ChatGPT’s Mac app could have allowed hackers to access sensitive data. These aren’t isolated incidents, they’re symptoms of an entire category of applications that demand deep system access but may not be fully transparent about how they use it.

The timing suggests Apple is taking these risks seriously. As more companies rush to deploy AI agents on desktop platforms, the security landscape is becoming increasingly complicated. Users are caught in the middle, wanting the benefits of these powerful tools while having legitimate concerns about their privacy.

What’s Changing

Apple says it will introduce new controls to ensure that users who want to grant Full Disk Access can only do so through “very explicit user action.” Translation: no more burying permissions in settings menus or letting users accidentally opt into extraordinary access.

“Addressing this is critical,” Apple wrote. “As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.”

This is security theater at its best. Apple is essentially saying: “We’re going to make it harder for you to accidentally hand over your entire digital life to an AI agent.” It’s not a restriction on capability, but rather a friction point designed to force genuine user intent.

The Bigger Picture

The move highlights a fundamental tension in the AI age. Developers want their agents to have maximum capability to serve users better. Users want privacy and security. And platforms like Apple are caught trying to balance both while preventing outright abuse.

What’s particularly interesting is that Apple didn’t directly respond to TechCrunch’s inquiry about the feature changes. The company is letting its developer blog post speak for itself, which suggests they’re treating this as a systemic issue rather than responding to one company’s misstep.

As desktop AI becomes mainstream, expect more of these friction points. The question isn’t whether AI agents should have access to your system, it’s how to ensure you’re making that choice with full awareness of what you’re trading away.

Source: TechCrunch

Filed under
techaisecurityprivacy