Apple Says It Will Further Lock Down MacOS in Response to Third-Party A.I. Agents

Apple, in a Developer News post I am reproducing in its entirety, segment-by-segment:

We give developers powerful APIs to build incredible capabilities into their apps for Apple products, backed by a set of controls designed to protect users’ private data. Full Disk Access largely sidesteps these controls in order to allow backup apps to function properly on the Mac.

As John Voorhees writes, the uses of Full Disk Access go well beyond the category of backup apps, and it is worrisome to see Apple give it such a limited frame. I have given that permission to disk management utilities, Sketch, Terminal, and other apps I do not want to be throwing permissions requests as I move around my drives. Is Apple suggesting this capability could be limited in the future to backup applications alone? I do not like that.

Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems — including files, mail, messages, and even browsing history — without users’ full knowledge and understanding.

This seems very clearly a response to Jason Aten claim, in Inc, that Meta’s Muse accessed and uploaded his Messages database without permission. This story is, as of writing, still confusing to me because Aten does not clearly describe the circumstances.

Full Disk Access is required because the Messages database is protected by MacOS. Giving Muse this permission is one of two prerequisites. The other, according to Meta’s Andy Stone, is something called the Messages Connector. Aten says he “had explicitly declined to connect Messages” but when he “looked at Muse’s settings afterward, Messages was enabled” anyway. In a follow-up article, Aten suggests he turned on Full Disk Access, then turned it off — though he does not say this explicitly — after which Muse was still able to read Messages data. If so, it indicates a possible MacOS security problem. But I must stress that I am confused by Aten’s description of the chain of events. As I was (slowly) putting this article together, Jeff Johnson attempted to reproduce the circumstances of Aten’s articles as he, like me, found the description confusing. As Johnson writes, “if Muse uploaded Aten’s Messages database, as he claims, then Aten granted Full Disk Access to Muse at some point. There’s no other plausible explanation”.

Regardless, we now have a wave of poorly regulated and frequently misconfigured software that scoop up user data with barely any notice, so Apple says — as you will read later — that it is stepping in to curb a likely vector for unintended consequences in Full Disk Access. However, it provides no details on what these additional restrictions will look like for users. It could be something as minor as a sterner dialog box, but I do not see a reason why Apple would issue a warning about a change like that.

Because of the lack of information available at present, I do not want to get too far ahead of myself, but I am concerned that it could be a significant curtailing of application permissions. It has the potential for further self-preferencing, as Apple will surely exempt Siri from the kinds of permissions requests it requires of third-party apps, even as it is updated with additional capabilities. In MacOS Golden Gate, for example, apps must be excluded if you do not want Apple Intelligence or Siri to have access. This makes sense inasmuch as Apple trusts itself, and users have agreed to its software license agreement and privacy policy. But an aggressive policy against broad access also means third-party software will be further disadvantaged on MacOS. Meta is, thanks to feeble government regulations and a seemingly skeezy management culture, the last company whose agent I would trust to run rampant across my system. But suppose there was an agent I felt comfortable using and felt like there was a reason to do so. No matter its potential capabilities, it would struggle to compete with Siri because of how privileged and integrated the latter already is — and now consider how much more difficult it would be if Full Disk Access were kneecapped.

One might argue that it is hardly a surprise since Apple has been promoting its unique “personal context” advantage since it began marketing Apple Intelligence in 2024. And Siri has always been privileged: since Apple integrated it with the iPhone 4S, it has been able to send and read text messages, emails, and more. Apple Intelligence and Siri are just another part of the system — part of the whole widget. And that “whole widget” stance cuts both ways. Not only does it affect users on Apple’s hardware, it also means Apple does not treat Apple Intelligence or Siri as software it will bring to other platforms. Apple is only competing in this market on its own products, which means its virtual assistant has a platform-level market share of basically 100%, and not because it has outcompeted any rivals.

Call me a naïve little baby if you want, but I do not think preserving Siri’s dominance on Apple’s devices is the company’s reason for locking down Full Disk Access. But Apple’s existing restrictions are part of the reason Siri was awful for a decade. If it had the opportunity to compete with third-party replacements, I doubt it would have languished in a miserable state for as long as it did. I cannot imagine people have been choosing Apple’s products to get Siri. Perhaps virtual assistants and agents will become important enough to people that they will become a factor in hardware purchasing decisions. Maybe that could even mean newer platforms to compete at a higher level. But I worry about the likelihood of incumbent platform owners — the kind the European Commission has called “gatekeepers” — using privacy and security arguments to curtail possible competition.

Back to Apple:

For communication apps, this can also compromise the privacy of the people users are communicating with.

You know what else could compromise communications privacy? iCloud. By default, device backups include a user’s Messages conversation history in a format Apple can decrypt. Users must turn on Advanced Data Protection, enabling true end-to-end encrypted backups, but their conversation partners may not, undermining its effectiveness.

Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action. Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.

This is an issue of platform owners playing a regulatory role that should be occupied by actual lawmaking. People should not need to worry that granting Full Disk Access to software made by a well-known company will produce a result indistinguishable from malware. We have been through this before. In 2012, the iOS app Path was caught uploading users’ contacts without explicit permission for its friend finding feature. There was theoretically nothing to prevent other iOS apps from abusing their access to the Photos library, either. All of these things are now gated behind App Store moderation on iOS, Full Disk Access on MacOS, and permission request sheets on both platforms.

It worries me that this nascent and seemingly niche world of agents is going to be another thing for users to understand and platforms to control. But, then again, I also have to wonder if the reasons I use Full Disk Access are perhaps a smaller niche. I just hope Apple’s response to this does not spoil my personal use, nor should it be a further gate to keep.