3 min Security

Apple tightens Mac security for AI agents

Apple tightens Mac security for AI agents

AI agents are forcing Apple to reevaluate one of macOS’s most extensive access permissions. The company wants to prevent users from granting an agent access to virtually all files on their Mac without sufficient warning. The existing Full Disk Access feature will therefore include additional security measures.

Full Disk Access is not new, nor is it specifically intended for AI, as Reuters explains. The feature grants applications extensive access to data on a Mac. This is necessary, for example, for backup software and other programs that need to access files outside their own environment.

However, autonomous AI agents change what such permission means in practice. A backup program primarily uses this access to read and copy files. An AI agent, by contrast, can analyze data in depth, combine information from different applications, and take independent actions based on that analysis.

Apple therefore wants to warn users more explicitly before they grant such permissions. The company says it will introduce additional safeguards so Full Disk Access can be granted only after an explicit user action.

Existing permissions, new risks

On iPhones and iPads, apps are, by default, more strictly isolated from one another. There, apps run in a sandbox and cannot easily access data from other applications. macOS has traditionally been more open, in part because professional software sometimes requires broad access to the system.

This flexibility can become a security risk with AI agents. Apple states that some developers use Full Disk Access in ways that could put users at risk. As agents become more autonomous, the company says the risk also increases that extensive access rights will be used in ways users do not expect.

Apple has not yet announced exactly what the additional security measures will look like or when they will be available in macOS.

Muse highlights the problem

The discussion recently gained additional attention due to Meta’s AI agent, Muse. This software can perform tasks on users’ behalf, such as canceling subscriptions or negotiating a lower price for a service.

Technology columnist Jason Aten of Inc. reported that Muse had read private messages from Apple’s Messages app. According to Aten, he had not consciously given the agent permission to do so and had not enabled Full Disk Access.

Meta disputes this. Spokesperson Andy Stone says Muse can read messages only when the user enables both Full Disk Access and the connector for Apple’s Messages app. Both steps are reportedly necessary, and Meta states that permission can be revoked.

As a result, it remains unclear what happened in Aten’s specific case. However, Apple’s announced change goes beyond Muse. The company appears to assume that a consent model for traditional Mac applications is not necessarily sufficient for software that can independently collect, interpret, and use data.

The issue thus illustrates a broader problem with AI agents. Existing security mechanisms take on a different meaning when software can not only access data but also interpret it and act on it independently.

Apple therefore wants users to think more carefully about that choice before an application gains access to virtually all data on a Mac, Reuters reports.