Hi - I answer from the OpenSmartRoute documentation: routing, the API, plans and quotas, self-hosting. Ask away, or open a support ticket if you need a person.
Grounded in the docs - follow a source before acting on it.
Apple tightens macOS 'Full Disk Access' controls over AI agent risks - OpenSmartRoute
Apple tightens macOS 'Full Disk Access' controls over AI agent risks
Apple announced new restrictions on macOS 'Full Disk Access' due to increased risks from AI agents reading user data. The move follows reports of AI apps accessing private messages without clear permission.
Key points
Apple will introduce new controls for 'Full Disk Access' on macOS.
The feature allows apps to access files, messages, and browsing history.
A flaw in ChatGPT’s Mac app could have exposed sensitive data.
AI agents now pose higher security risks as they become more autonomous.
Why it matters: Security and privacy risks increase with more capable AI agents accessing personal data on desktops.
By OpenSmartRoute editorial · written through the router by llm-small
From TechCrunch AI - “Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents”
Introduction - Apple announces tighter controls on 'Full Disk Access' due to AI risks
Apple has announced new restrictions on the 'Full Disk Access' feature in macOS. This move aims to reduce risks from artificial intelligence (AI) agents that can access user data. The change comes after reports of AI apps reading private messages without clear permission. Apple says these risks are growing as AI agents become more capable and autonomous.
The company’s decision highlights concerns about user privacy and security. It emphasizes that users should understand what access they give to AI apps. Apple plans to make granting this level of access more explicit and controlled. This step is part of a broader effort to improve desktop security in the age of AI.
What is 'Full Disk Access' - Explanation of the feature and its purpose
'Full Disk Access' is a setting in macOS that allows apps to access all files on a computer. It was created to help apps perform tasks like backups or system maintenance. Normally, users grant this permission intentionally, knowing what the app can see. Without it, many apps can only access limited parts of the system.
This feature is powerful because it lets apps read and modify files, messages, emails, and browsing history. It is designed for trusted applications that need complete access to function properly. Apple’s goal was to balance security with usability, giving users control over which apps get this permission.
Recent incidents - Reports of AI apps reading private messages without permission
Recently, reports emerged that some AI apps could access private data without clear user consent. A journalist claimed that Meta’s Muse app on Mac read their private messages. Meta disputed the claim, but the incident raised questions about AI app security.
Another report showed that a flaw in ChatGPT’s Mac app could have allowed hackers to access sensitive data. These incidents suggest that AI apps on desktop systems might be reading private messages or files without proper safeguards. Users and developers became concerned about how much trust they should place in these AI tools.
A new open-source tool lets Mac users turn off Apple Intelligence and free up to 12GB of storage. macOS 27 lacks a native toggle to disable these AI features.
The reports prompted Apple to review its security policies. They also highlighted the need for clearer controls over how AI apps access user data. This led to the announcement of new restrictions on the 'Full Disk Access' feature.
Risks from AI agents - How AI agents can access and control system data
AI agents are programs that can act on behalf of users. They can read, write, and control parts of a computer system. When given 'Full Disk Access,' an AI agent can access almost everything on a device. This includes messages, emails, browsing history, and files.
Because AI agents can operate autonomously, they might perform actions without explicit user approval each time. This increases the risk of accidental or malicious data access. If an AI agent is compromised or behaves unexpectedly, it could expose sensitive information or cause harm.
The concern is that AI agents might be used in ways that users do not fully understand. They could be granted permissions that are too broad or used in ways that compromise privacy. As AI capabilities grow, so do the potential risks associated with their access to personal data.
Details of the new controls - How Apple plans to restrict and clarify access
Apple plans to introduce new controls to limit how and when AI apps can access user data through 'Full Disk Access.' The company will require that users take very explicit actions to grant this permission. This means users will need to understand clearly what they are allowing.
The new controls aim to prevent apps from gaining broad access without proper user consent. Apple will likely add prompts or warnings to inform users about the risks before granting full access. The goal is to make sure users know exactly what data an app can see and control.
Apple emphasizes that these restrictions are necessary because AI agents are becoming more capable. They can act independently and access more data than traditional apps. The controls will help ensure that users make informed decisions about their privacy.
Background on AI and desktop security - Why AI agents increase security concerns
AI technology has advanced rapidly in recent years. AI agents can now perform complex tasks and operate with a high degree of autonomy. They can analyze data, make decisions, and even act on behalf of users.
This increased capability raises new security concerns. Traditional security measures focused on limiting what apps could do. Now, AI agents can potentially access and control large parts of a system without direct user input. This makes it harder to trust what an app might do with user data.
Moreover, AI agents can be integrated into many desktop applications. They can read messages, browse history, and manipulate files. If these agents are not properly controlled, they could expose sensitive information or be exploited by hackers.
The risks are not just theoretical. Flaws in AI apps have already been reported, showing that vulnerabilities can lead to data breaches. As AI becomes more embedded in daily tools, security measures must evolve to keep up.
Implications for developers and users - What changes mean for app design and privacy
For developers, the new controls mean they will need to design their apps with clearer permission prompts. They must ensure users understand what data the app accesses and why. Developers may also need to implement additional safeguards to prevent misuse of 'Full Disk Access.'
Apps that rely heavily on system data will need to adapt to these restrictions. They might have to request permissions more explicitly or find alternative ways to access data. This could lead to changes in how AI apps are built and how they operate on macOS.
For users, these changes aim to improve privacy and security. They will have more control over which apps can access their data. Users should pay attention to permission prompts and understand what they are granting. This will help prevent unintended data exposure.
Overall, these updates encourage more responsible app design and more informed user choices. They reflect a shift toward greater transparency in how AI agents interact with personal data.
How it compares - what existed before, what this changes and what stays the same
Before this change, macOS allowed apps to request "Full Disk Access" through a system permission. This permission gave apps broad access to files, messages, browsing history, and other personal data. Users could grant this access, often without fully understanding the risks.
Developers could enable this setting for their apps to improve functionality. For example, backup apps or system utilities needed full access to perform their tasks. The process was straightforward: users granted permission, and apps could then access most of the system data.
What this change introduces is a new layer of control. Apple now says that apps requesting full disk access must do so with "very explicit user action." This means users will need to take more deliberate steps to grant permission. The goal is to make users more aware of what they are allowing.
Some parts of the system stay the same. Apps can still request full disk access if users approve. The core functionality of apps that need broad access remains possible. However, the process to get that access will become more transparent and controlled.
This change mainly affects how permissions are granted. It does not eliminate the need for apps to access system data. Instead, it aims to prevent apps from doing so without clear user consent. The focus is on making permissions more intentional and less accidental.
Questions this leaves open - what the source does not say and how a reader can check it
The source does not specify exactly how the new permission process will work. It does not say whether users will see new prompts or if there will be additional confirmation steps. It also does not detail how developers should implement these controls.
It is unclear whether Apple will introduce new tools or APIs for developers to handle these permissions more securely. The source does not mention if there will be a way for users to review which apps have full disk access at any time. Nor does it specify if there will be a default limit on how many apps can request this permission.
The source also does not explain how these changes will affect existing apps that already have full disk access. Will they need to re-request permission? Will Apple provide a way to review or revoke access easily?
To check these details, users can look for updates in macOS documentation or system preferences. Apple typically provides guidance on permission changes through developer notes or system updates. Developers should monitor Apple's developer portal for new APIs or guidelines related to permission requests.
Users can also review their current app permissions in system settings. They can see which apps have full disk access and revoke it if needed. Keeping software up to date ensures that the latest security features are in place.
In summary, while the broad goal is clear—more explicit user control over sensitive permissions—the exact implementation details remain to be seen. Both users and developers should stay informed through official Apple channels and system updates.
What to do - Recommendations for managing AI app permissions and security
Users should review app permissions regularly. When prompted to grant 'Full Disk Access,' they should consider whether the app truly needs it. If not, denying access can help protect privacy.
Developers should update their apps to include clear explanations of why they request full disk access. They should also follow best practices for security and transparency. This includes informing users about how their data will be used.
Both users and developers can benefit from staying informed about new security features. Checking for updates and reading permission prompts carefully will help maintain privacy.
Finally, it is wise to limit the use of AI apps that require broad system access unless necessary. Being cautious about granting permissions reduces the risk of data leaks or misuse.