Back to News
RSS feeddaringfireball.net

Apple Plans Tighter Mac Full Disk Access Controls for Agentic AI Apps

Summary

Apple says it will introduce additional controls for Full Disk Access in macOS, a permission that can largely bypass the system’s ordinary protections so backup and other applications can work. The company warns that some developers are using the permission in ways that may expose files, mail, messages, browsing history, and, in communication apps, information about other people communicating with the user. Apple specifically says the growing capability and autonomy of AI agents will substantially increase the risks associated with this level of access, and that users should have to take very explicit action after understanding those risks. The post does not identify particular applications. John Gruber interprets the announcement as a response to reports involving agentic applications such as Meta Muse, Grok Bot, Claude, and Dots, but those examples are his attribution rather than names supplied by Apple. He worries that a broad restriction could disrupt legitimate power-user workflows and applications that currently depend on Full Disk Access. At the same time, he argues that many Mac users may not understand that accepting an application’s requests can give it access to almost everything on the startup drive. He contrasts macOS with iOS and iPadOS, where approving ordinary permissions does not give third-party apps equivalent access to email or end-to-end encrypted messages; he notes that the European Union’s Digital Markets Act seeks to require broader access on Apple’s mobile platforms. Gruber hopes Apple will preserve a clearly acknowledged path for knowledgeable users while making the consequences much harder to misunderstand for everyone else. The article leaves the technical design, timing, and final scope of Apple’s new controls unspecified.