Apple to Limit Mac Disk Access as AI Agents Increase Security Risk

Apple to Limit Mac Disk Access as AI Agents Increase Security Risk

Apple's New Mac Disk Access Restriction

Apple is preparing to tighten how applications can reach the files stored on a Mac. Under the forthcoming change, apps will no longer be able to obtain full disk access quietly in the background. Instead, Apple will require what it describes as "very explicit user action" before an app is granted that level of access.

Full disk access is a powerful permission. An app holding it can read locations that are normally off limits, including Mail data, Messages history, Safari browsing records, and Time Machine backups. Today, users grant this through System Settings, but the new requirement raises the bar for how deliberately that consent must be given.

The restriction is not aimed at traditional utilities alone. It reflects a broader shift in what runs on the desktop, as autonomous AI agents increasingly request broad file-level permissions to complete tasks on a user's behalf. Apple's answer is to put the user directly in the loop at the moment access is requested.

For developers, the practical effect is that onboarding flows built around silent or bundled consent will need rethinking. For users, the change promises fewer surprises about which software can see their personal files.

Why AI Agents Are Driving the Change

Apple's justification for the new restriction centres on the growing presence of AI agents on the Mac. According to Apple, AI agents substantially increase risk, and that assessment is what prompted the new disk access requirement.

The concern is structural rather than incidental. An AI agent is designed to act on a user's behalf, often autonomously, which means it may attempt to read files the user never intended to expose. Under the previous model, an app could reach broad swaths of the disk once it had been granted access, and an agent operating inside that app could inherit the same reach.

By requiring "very explicit user action" before an app can access data from other apps, Apple aims to put a deliberate human decision between an agent and the files it wants to read. The change reflects a shift in threat modelling: the risk is no longer only a malicious app, but a legitimate one whose automated behaviour expands what it can touch.

What 'Very Explicit User Action' Means for Mac Apps

Apple's new requirement raises the bar for how Mac apps obtain full disk access. Under the change, an app must secure what Apple calls "very explicit user action" before it can reach the entire disk. In practice, that means the old model — where a user simply flipped a switch in System Settings — will no longer be enough on its own.

The distinction matters because full disk access is one of the most powerful permissions on macOS. Once granted, an app can read data far beyond its own sandbox, including files belonging to other applications.

For developers, the immediate consequence is that onboarding flows and permission prompts must be redesigned around a deliberate, unmistakable user gesture. Apps can no longer rely on a passive toggle to carry the consent.

For users, the friction is the point: Apple is trading convenience for a clearer, more intentional grant of trust. The exact mechanics remain to be seen, but the direction is unambiguous.

The Security Implications of AI Agents on Mac

The change responds to the substantially increased risk posed by AI agents on Mac. Unlike traditional apps, an AI agent can operate autonomously, making decisions and taking actions on the user's behalf without step-by-step confirmation. That autonomy is precisely what makes disk access so dangerous.

An agent with broad file access could read, modify, or exfiltrate sensitive data at machine speed, well beyond what a human could review in real time. A single compromised or misbehaving agent could therefore cause far greater harm than a conventional app.

The new restriction limits that exposure. By requiring very explicit user action before an app can access the disk, Apple ensures that AI agents cannot silently gain the broad permissions they would need to act at scale. The goal is not to block agents outright, but to keep a human decision point between an agent and the user's files.

APPLE  AI security 

Comment