Illustration for: Apple to Tighten Mac Disk Access Over AI Agent Risk

Apple to Tighten Mac Disk Access Over AI Agent Risk

Apple said it will add new controls around macOS's Full Disk Access permission, warning that AI agents' growing autonomy makes that level of system access substantially riskier than when the setting was designed.

By the Numbers

Full Disk Access
Setting affected
macOS
OS
Autonomous AI agents
Cited risk driver
ChatGPT Mac app flaw
Related incident
TechCrunch, Bloomberg
Reported by
TC
Early-stage VC & angel · Founder, New York Venture Partners · Value Add Pulse Markets Desk
2 min read
ShareXLinkedInEmail

THE RUNDOWN

1

Apple singling out AI agents as the reason for tightening a macOS permission that's existed for years shows the company sees agentic AI software, not just malware, as a new category of security risk on its own platforms.

2

The move follows a Wired report that a flaw in ChatGPT's Mac app could have let hackers access sensitive data, giving Apple's warning a concrete recent incident rather than a hypothetical one.

3

Always-on AI agents like Meta's Muse and OpenAI's Dots, which run with broad system permissions to complete tasks, are the exact use case Apple's new controls target -- a preview of how platform owners may gate agent permissions generally.

4

For AI-agent startups building Mac-native products, tighter Full Disk Access rules mean more explicit user consent flows standing between their agent and the data it needs to act on a user's behalf.

TC

The VC Read · Trace's Take

Trace Cohen

Apple restricting Full Disk Access isn't really about one ChatGPT bug -- it's Apple asserting itself as the permissions gatekeeper for every AI agent that wants deep access to a Mac, the same role it plays for App Store apps generally. Any startup building an agent that needs broad file-system access should treat this as the first of several platform-level gates, not the last; the diligence question for agent-infrastructure investors is how much of a product's value depends on access Apple, Microsoft or Google can restrict unilaterally.

Analysis

Apple said it's adding new controls around macOS's "Full Disk Access" permission, warning that the risks of granting that level of system access "will grow substantially" as AI agents become more capable and autonomous, TechCrunch reported. Full Disk Access -- originally built so backup software could function properly -- lets an app read files, mail, messages and browsing history; Apple said "some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems... without users' full knowledge and understanding," per Bloomberg.

A Specific Incident Behind a General Warning

Apple's announcement comes shortly after a Wired report that a flaw in ChatGPT's Mac app could have let hackers access sensitive user data, and amid the broader rise of always-on AI agents -- Meta's Muse and OpenAI's Dots among them -- designed to act autonomously across a user's files and apps rather than respond to a single prompt. Pulse tracks OpenAI's agent products on its company hub. Both products are the kind of software Apple's new controls are aimed squarely at: agents that need standing, broad access to do their job rather than one-off permission grants.

“Pulse tracks OpenAI's agent products on its company hub.”

Why This Is a Platform Story, Not Just a Privacy Patch

Apple controlling how much system access any app -- AI agent or otherwise -- can get is the same gatekeeping role it has long played with App Store review and iOS permissions, now extended explicitly to agentic AI on the Mac. Going forward, Apple says only users who "genuinely wish to grant an app this extraordinary level of access" will be able to, through "very explicit user action," rather than a single click-through dialog. That's a meaningful friction point for any AI agent startup whose product depends on broad file access to be useful.

What the Headline Misses

Apple's framing puts the responsibility on "some developers" misusing Full Disk Access, not on any single named company, and the company hasn't announced specifics on what the new consent flow will look like or when it ships. The risk for AI-agent developers isn't just Apple's rule change itself -- it's the precedent: if Microsoft and Google follow with their own agent-specific permission gates on Windows and Android, every agent product leaning on deep system access faces a wave of new consent friction roughly at the same time, independent of its own user growth strategy.

ShareXLinkedInEmail

Key Sources

2 sources

Reported by TechCrunch · Analysis by Value Add Pulse.

← Back to Pulse

THE WIRE in your inbox— Tech, startup & VC news with Trace's take, a few times a week. Free to subscribe, no spam.