Policy

Apple restricts Mac disk access over AI agent security risks

Apple will require explicit user action for Mac apps to gain full disk access, a move designed to prevent increasingly autonomous AI agents from quietly reading sensitive personal data.

The Verge AI3 days agoPolicy
Image: The Verge AI

Apple is introducing stricter controls for the Full Disk Access permission on macOS to counter security vulnerabilities introduced by autonomous artificial intelligence. The company announced it will require "very explicit user action" before any application can obtain this sweeping level of system privilege. Apple warned that the rapid evolution of highly capable AI agents dramatically amplifies the dangers of granting unrestricted storage access to third-party software.

The policy shift follows a recent controversy involving Meta's Muse AI. A tech writer, Jason Aten, discovered the chatbot was privy to his private message history despite him not consciously granting it permission. Meta spokesperson Andy Stone defended the AI, stating that accessing messages is entirely opt-in and requires users to manually enable both Full Disk Access and a specific Messages connector. However, the incident highlighted how easily users can expose sensitive files, emails, and browsing histories without fully understanding the permissions they have granted.

Full Disk Access was originally designed to bypass standard macOS privacy boundaries so that system utilities, such as backup applications, could operate correctly. Because it bypasses these safeguards, an app with this permission can inspect almost any file on a Mac. Apple argues that some developers are now abusing this privilege, exposing highly personal user data to AI models that can autonomously process and potentially leak the information.

For software developers and AI practitioners, this update means that building agents with deep system integration on macOS will become significantly more difficult. Developers will no longer be able to rely on quiet or bundled permissions to ingest local user data for training or context retrieval. Instead, they must design clearer user interfaces that explicitly justify why an agent needs system-wide access, potentially increasing user friction during installation. Apple has not yet announced a specific release date for the security update.

This is our own summary of reporting by The Verge AI

More in Policy