Safety#Runtime#AI safety

Apple will gate Mac disk access behind explicit user action, citing AI agents

Apple told developers macOS Full Disk Access will require "very explicit user action" — no date given — naming AI-agent risk directly.

A Mac mini on a blue background

Apple updated developers on October 2: macOS Full Disk Access (FDA) will only be grantable through “very explicit user action” going forward. No OS version or timeline accompanied the note — but the reasoning was explicit, and it names the new tenant of every Mac: agents.

The facts

  • The change: FDA grants will require explicit user action; no version or date announced.
  • Apple’s framing: FDA was designed “to allow backup apps to function properly” but “largely sidesteps” privacy controls, exposing “files, mail, messages, and even browsing history” — and “as AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.”
  • The backdrop: Meta Muse was accused of surfacing Messages content on Mac (Meta denies), and the ChatGPT Mac app took a process-injection flaw report the same week.
  • Sourcing note: TechCrunch broke the story, The Verge followed; Apple’s developer documentation is the final word.

A model turning for agents

FDA is the bluntest instrument in macOS’s permission system — one grant, everything visible. The agent-era granularity is per-task, per-path, per-time narrow grants, and Apple’s statement commits the system to building them. Backup and sync apps will have to redesign their elevation flows around it.

What builders should do

Three changes to make early: write installation copy that explains “why disk access” in user terms (the system will force the conversation); move bulk reads onto controlled channels like AppleScript and QuickLook; and prepare a least-privilege manifest for review. CLI agents like Claude Code and Codex are not named, but all sit inside FDA’s blast radius.

Editorial take

This is the platform’s first tightening for agents, arriving the same month as its openings — the strategy is now legible: agents may enter, but they live inside the permission house the system draws. Manus’s email-injection flaw supplies the footnote for why.

The policy context around the change

Apple’s note lands alongside a crowded field: OpenClaw Enterprise selling governance planes to enterprises, Nvidia’s agent-safety platform selling containment, and regulators now subpoenaing labs over agent incidents. Platform-level permission redesign is the consumer-side of the same wave — the desktop was the last unguarded surface. The absence of a version target suggests Apple is building the mechanism now and shipping it with the next macOS cycle; agent apps should not wait for the enforcement date.

Apple’s backup-app problem

FDA exists because backup, sync and security tools genuinely need whole-disk reads — Spotlight indexes, Time Machine, malware scanners. The tightening will hit exactly those vendors first, and Apple’s own statement concedes the grant was “meant to allow backup apps to function properly.” Expect a transition API (scoped snapshots? per-path grants?) to accompany the enforcement; without one, the honest backup apps break while malicious ones move to other channels.

The deeper design question is what “explicit user action” means in practice — a one-time consent dialog will be clicked through, so the likely mechanism is per-action confirmations with context (which file, which app, why now), closer to UAC than to App Store permissions. Agent UX will have to absorb a permission prompt into its task flow, or users will train themselves to approve blindly — which recreates the original problem one click deeper. Watch for the developer-forum thread that always follows these notes; the mechanism details will surface there first.

The explicit-action requirement also creates an audit trail the previous dialog lacked: if the system records each grant with its context, enterprise admins finally get an answer to “which app read what” — a capability the Muse dispute showed nobody currently has.

For the standards-minded, the developer note is also a rare explicit statement of threat model from Apple: it treats agents as autonomous actors rather than tools, which is the vocabulary of agent-security engineering entering mainstream platform documentation. Expect the same framing to migrate to iOS’s permission dialogs before long, since Siri-class agents share the same architecture. The note’s language about agents is the first time a platform has named them as a risk class in a permission change.