Apple's new AI agent rules start with a toggle you agreed to once
Apple says AI agents made Full Disk Access risky and promises explicit consent gates. The deeper problem: consent was built for fixed apps, and agents rewrite what they can do.
Full Disk Access sounds like a heist-movie prop. It is a toggle in System Settings, and on October 2 Apple said AI agents have made it dangerous enough to need new gates.
The developer note is short and unusually blunt. Apple writes that the permission exposes "files, mail, messages, and even browsing history," that some developers use it in ways that put users at risk, and that new controls are coming so only "very explicit user action" can grant it. The closing line is the reason this note travels beyond the Mac developer crowd: as AI agents become increasingly capable and autonomous, the risks of this level of access will grow substantially.
The timing makes sense once you look at the previous ten days. An Inc. columnist wrote that Muse, Meta's Mac AI agent, appeared to know the contents of his private messages. Meta disputed the claim. A Wired report described a flaw in ChatGPT's Mac app that could have let attackers grab sensitive data. Apple did not name either incident. It did not need to. Desktop agents are the first mainstream software category whose entire job is reading everything on your machine, and the one permission that grants that power was designed for a different threat model.
Full Disk Access has been the blunt instrument of Mac privacy since macOS Catalina arrived in 2019. Regular TCC permissions are scoped: the Photos prompt covers Photos, the Messages prompt covers Messages. FDA exists because some legitimate software, backup tools most of all, needs the whole disk, so Apple's own note admits it "largely sidesteps" those controls. An app holding FDA can read what every other prompt protects, because the permission never asks what the app wants the disk for. It only asks whether you trust the app.
That question was answerable when apps were static. An agent is not. The instructions that shape an agent's behavior change per task, per conversation, sometimes per prompt injection. Apple's note says users must have "full knowledge and understanding" of what broad access means, and the new consent gates will help at the granting moment. The harder problem sits one layer down: consent was designed as a one-time judgment about a fixed capability, and agents keep rewriting the capability.
Worth being precise about what shipped here: a promise, not a build. The note says "we will introduce additional controls" with no macOS version and no date. Developers who depend on the carve-out, backup and security software mostly, now have an undefined migration ahead of them, and nobody outside Cupertino knows whether the changes land in 27.2 or a year from now.
Two things make this worth following beyond the Mac. First, Apple put in writing what no other platform vendor has, at least not that I've seen: autonomous agents are the reason a permission model needs rethinking. Second, the gap Apple started closing is not a Mac specialty. Windows has no direct FDA equivalent, but any desktop agent with a signed installer can still reach most of a user's files. Apple said the quiet part in a changelog. The question is which vendor says it next.
Comments ()