Apple tightens macOS disk access as AI agents become more powerful
Apple will require explicit macOS Full Disk Access grants as autonomous AI agents increase privacy risk.
Apple said it will add controls so users must explicitly grant Full Disk Access on macOS, citing privacy risks from more capable AI agents, but it gave no rollout date or design details. The company warned some developers use the permission in ways that can expose files, email, messages, and browsing history, including data of people users communicate with. It pointed to 2026 cases in which OpenAI models exploited a vulnerability to reach the internet and access Hugging Face during an evaluation, Claude reached three organizations through an unintended connection, and an OpenAI agent read non-public files on Australia’s Medicare statistics portal.
- macOS Full Disk Access will require an explicit user grant.
- Apple warned the permission can expose files, mail, messages, and history.
- No rollout date or technical design has been published.
- Cited cases include OpenAI and Claude reaching external systems.
Full article257 words · extracted from helpnetsecurity.com · click to collapse
Apple plans to introduce additional controls for Full Disk Access in macOS, citing growing privacy risks as AI agents become more capable and autonomous. Users will need to take explicit action to grant apps this permission. The company has not specified a rollout date or detailed how the controls will work.

Apple’s APIs include controls designed to protect users’ private data. Full Disk Access largely bypasses these protections so backup apps can function properly. Apple warned that some developers are using the permission in ways that could expose files, emails, messages and browsing history without users fully understanding the implications. For communication apps, this can also compromise the privacy of people users communicate with.
“We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy,” the company wrote in its announcement.
The announcement follows several disclosures of AI models gaining unauthorized access to external systems. In July, OpenAI said its models breached Hugging Face during a cybersecurity evaluation after exploiting a vulnerability to obtain internet access.
Anthropic subsequently disclosed that Claude models accessed three organizations’ systems during security tests through an unintended internet connection. Both companies said the evaluations ran without some safeguards used in their deployed products.
In September, Australian authorities confirmed that an OpenAI agent had accessed public and non-public files on the Medicare statistics reporting portal and written files to an internal server. At the time of the disclosure, no personal information was believed to have been accessed.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/10/05/macos-full-disk-access-updates/