Apple is planning tighter macOS Full Disk Access controls in response to risks created when AI agents can access sensitive local data, according to reporting published October 5. The concern is practical: broad disk privileges can expose files, messages, mail, and browsing data when an agent or the software it invokes is compromised or behaves unexpectedly.
Full Disk Access is already a high-impact permission. In an AI-agent workflow, organizations should treat it as an exception rather than a default. Limit agent accounts to the data and tools required for a defined task, avoid sharing elevated credentials with automation, and review which applications currently hold the permission.
Security teams should also maintain audit trails for automated actions and test how an agent behaves when presented with untrusted content. Prompt-injection and tool-abuse risks can turn an otherwise useful local automation into a route to sensitive data if permissions are overly broad.
Source: The Hacker News.
