Apple to Tighten macOS Full Disk Access, Citing AI Agent Risks – Unite.AI

0
1



Apple said on October 2, 2026, that it will introduce additional controls around Full Disk Access in macOS, stating in a post on its Developer News site that some developers are using the permission in ways that could put users at risk and that the risks tied to that level of access will grow as AI agents become more capable and autonomous.

What Apple Announced

The post, titled “Updates to Full Disk Access in macOS,” said Full Disk Access largely bypasses the controls that back Apple’s developer APIs so that backup apps can work properly on the Mac. According to Apple, some developers are using the permission in ways that could put users at risk by exposing everything on their systems, including files, mail, messages, and browsing history, without users’ full knowledge and understanding. When the apps involved handle communications, Apple said, the exposure can extend to the privacy of the people a user is communicating with.

Apple said the coming controls will ensure that users who genuinely want to grant an app this level of access can do so only through “very explicit user action.” The company called addressing the issue critical and said it is committed to making sure users clearly understand the risks before granting such access, so they can make informed decisions about their own data and privacy. The post gives no date or macOS version for the change and names no developer or app.

“As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially,” the post states.

What Full Disk Access Grants Today

According to Apple’s Mac User Guide, Full Disk Access allows apps to access all files on the computer, including data from other apps such as Mail, Messages, Safari, and Home, data from Time Machine backups, and certain administrative settings for all users on the Mac. The setting sits in System Settings under Privacy & Security, and adding an app requires the user to click the Add button, select the app in the list, and click Open. A separate Files & Folders category lists apps that have requested access to files and folders in different locations on the Mac.

Apple’s Platform Security guide describes the consent model surrounding that setting. Apple states in the guide that users should have full transparency, consent, and control over what apps do with their data, and that in macOS 10.15 or later the system enforces the model by helping ensure apps obtain user consent before accessing files in Documents, Downloads, Desktop, iCloud Drive, and network volumes. Since macOS 10.13, apps that require access to the full storage device have had to be explicitly added in System Settings on macOS 13 or later, or System Preferences on macOS 12 or earlier.

The guide also distinguishes how access is granted. Requests for files and folders, covering Desktop, Documents, Downloads, network volumes, and removable volumes, are handled through a prompt from the app, while full internal storage access requires the user to edit system privacy settings. Accessibility and automation capabilities likewise require user permission to help ensure they do not circumvent other protections.

How Managed Macs Handle the Permission

For Macs enrolled in a device management service, Apple’s Platform Deployment guide documents the Privacy Preferences Policy Control payload, which organizations use to manage the settings in the Privacy pane of Security & Privacy preferences and which carries the identifier com.apple.TCC.configuration-profile-policy. The payload requires user approval, must be installed through a device management service, supports Device Enrollment and Automated Device Enrollment, and requires supervision when applied through such a service. When more than one payload of this type is delivered to a device, the operating system applies the more restrictive settings.

One service within the payload, System Policy All Files, allows specified apps access to data like Mail, Messages, Safari, Home, Time Machine backups, and certain administrative settings for all users of the Mac. Organizations building a custom payload must specify a bundle ID or file path, whether the app is allowed or denied access, and the code-signing requirement, which the guide says can be obtained by running codesign -dr - on the app or binary. The guide notes that each device management service developer implements these settings differently and directs administrators to their service’s documentation.



Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here