Apple says AI agents make Full Disk Access riskier. Your own agent workflows have the same problem.

by•

On 2 October Apple said it will make granting Full Disk Access on macOS require more explicit user action, and it named AI agents as the reason. If you let agents touch your files, that's a prompt to audit what you've already handed over.

On 2 October Apple posted a short developer news item titled "Updates to Full Disk Access in macOS." It says Apple will add controls that require more explicit user action when Full Disk Access is granted, because some developers misuse it to reach sensitive data such as files, mail, messages and browsing history without the user fully understanding. The sentence I keep coming back to is this one: "As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially."

The post is short. It doesn't say which macOS version gets the change, when it lands, or what developers need to do about it, so I'm not going to pretend to know. What it does tell you is where Apple thinks the risk is heading.

Here is why I think this matters to a small team even if you never ship a Mac app. Most of us now run agents in our own workflows: a coding agent on a laptop, something that triages email, a script that reads a folder of customer notes and summarises it. The easy way to set these up is to grant broad access once so that nothing ever prompts you again. That's the same trade Apple is describing, and we're making it on ourselves.

The failure mode isn't dramatic. It's that an agent with access to everything will eventually read something it shouldn't, and the instruction that makes it do something with it can arrive inside a file, a web page or an email, not from you. Whatever the agent can read, text inside that content can try to steer it. The narrower the access, the smaller the damage.

So here is the audit I'm doing this week, and I'd suggest it to anyone running agents:

First, list every agent or automation you run and write down what it can read and what it can change. Most people discover at least one that has access to far more than its job needs.

Second, separate reading from acting. Anything that can read untrusted content (email, web pages, support tickets) shouldn't also be able to send, delete or publish without a person approving it.

Third, keep sensitive data out of reach by default. For an app like Murror, where people write things in a journal they wouldn't say out loud, the rule I'd apply is that nothing in your own tooling gets a standing grant to that kind of data. If you need to look at something, look at a specific item for a specific reason.

The source is Apple's own developer news post from 2 October. It's brief, so read it directly instead of relying on my summary.

What's the broadest access you've given an agent so far, and would you give it again today?

15 views

Add a comment

Replies

Best

the broadest I've given is a daily claude code loop that has standing access to my gmail, calendar, drive, and a browser it can click around in on its own. would I give it again today - yes, but only because the actual guardrail I built wasn't on the data access, it was on specific actions: it can read anything but it can't send an email, buy anything, or post publicly without me confirming first. your "separate reading from acting" point is exactly right and it's the part I backed into after almost sending something I didn't mean to, not something I designed up front. the uncomfortable part is the read side is still basically unbounded - it can read years of email to answer one question, and I've never actually audited whether it needed that much just to do today's task vs what it technically could reach

When you did your audit, what was the most surprising thing you found? Was there one agent that could reach way more than it needed?