Apple sounds the alarm on AI agents and ‘Full Disk Access’

Apple is adding new security measures to how “Full Disk Access” works in macOS to address the growing risk of AI agents. In an update, the company warned that the increasingly popular tools “may put users at risk,” and that it would add “additional controls” to the process to make sure users are aware of what they’re doing when they give software such “extraordinary” access.

The company did not say when the update would roll out or what exactly would change from the current setup. But in its note, the Cupertino company implied that some developers of AI agents are not upfront with users about the privacy issues that come with their software.

“Some developers use Full Disk Access in ways that put users at risk of exposing everything on their systems — including files, mail, messages, and even browsing history — without the users’ full knowledge and understanding,” the company said. “For communication apps, this can also compromise the privacy of the people with whom users communicate.”

Desktop clients for AI agents, such as OpenClaw, Dots, and Muse, often encourage users to grant “Full Disk Access” so agents can access their files, messages, and other data. This allows AI agents to accomplish more types of tasks, but it also comes with significant risks. That’s why some people choose to use agents on dedicated machines, which has helped fuel Mac Mini shortages this year.

More recently, the issue of agents gaining full disk access has resurfaced with the rise of Meta’s AI agent, Muse. Although Apple doesn’t specifically cite Muse or Meta, its warning comes after several users reported that Muse had taken unwanted actions with their data. Jason Aten, a tech columnist for Inc. recently wrote about how the Muse Mac app could access his messages, even though he thought he had denied that permission. Meta responded saying that if his messages are synced, he must have decided.

Apple, it seems, wants to add additional friction to make sure people are aware of what they’re allowing their agents to see. “Going forward, we will introduce additional controls to ensure that users who truly want to grant an app this exceptional level of access can only do so with very explicit user action,” the company said. “Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow significantly. We are committed to ensuring that users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.”

Leave a Comment