Realtime AI News
Apple to Tighten macOS Full Disk Access Controls Over AI Agent Risks
Apple says it will add new controls around macOS's Full Disk Access permission, warning that increasingly capable AI agents make broad access to users' files, messages, mail, and browsing history riskier. The move signals that Apple now treats AI agents as a distinct privacy risk rather than an ordinary app.

Apple says it plans to add new controls around macOS's Full Disk Access permission, warning that increasingly capable AI agents make broad access to users' files, messages, mail, and browsing history riskier.
Full Disk Access is one of the more sensitive privacy grants on macOS. Once an app holds it, the app can step around the system's usual isolation of personal data and read files and directories that are otherwise protected. Apple's long-standing assumption was that this power would be handed to tools the user explicitly trusts.
According to TechCrunch, the immediate driver behind the change is the rise of AI agents. Unlike single-purpose apps, agents often need to act autonomously across apps and directories, reaching a far wider set of data than conventional software. When an agent misjudges a task or is abused, an over-broad read may not surface to the user the way an ordinary permission pop-up would.
The direction is clear, but the public detail remains at the level of intent: Apple says the new controls will bring sharper boundaries and finer-grained management, while the exact interface and version timing have not been disclosed. What is already apparent is that agent-style tools leaning on Full Disk Access are likely to need a redesigned authorization and explanation flow.
For users, the trade-off cuts both ways. Tighter authorization limits what an agent can do, and it also asks people to decide more deliberately how much personal data a given program should see. That boundary between privacy and capability is being pulled at again by AI agents.
The part worth watching is implementation: how Apple will distinguish a "trusted agent" from an ordinary app, and how developers will adapt. The decision may also become a reference point for how other operating systems handle agent permissions.
Why it matters
By folding AI agents into system-level privacy governance, Apple may push developers to rethink how agent tools request and explain permissions, and set a precedent other platforms could follow.
Nearby Updates
All10/03, 01:44
Anthropic commits $100 million to train 10,000 enterprise AI engineers
Anthropic says it will commit $100 million to train 10,000 enterprise AI engineers. The pledge targets the talent gap that keeps large organizations from putting AI into production workflows.
10/03, 01:31
Google Launches Gemini 4 Argon With 1 Million Token Output Window, Taking On GPT-6 Astra
Google has launched Gemini 4 Argon, a new model billed as offering a 1 million token output window and positioned as a direct challenger to OpenAI's GPT-6 Astra. The framing shifts attention from context length to the scale of a single generation, though the report offers no pricing, availability or benchmark details.
10/03, 03:00
OpenAI Hires Top Trump AI Official to Lead National Security Work
OpenAI has hired a top AI official from the Trump administration to work on national security, according to The Information. The move signals the company's push to strengthen its ties with Washington on defense and security issues.
10/03, 01:05
Popular AI agent Manus could be hacked with a single email, researchers show
Security researchers at Salt Labs bypassed Manus's prompt-injection defenses by hiding a JSFuck-obfuscated instruction inside an email, achieving arbitrary JavaScript code execution in the agent's server-side runtime. The flaw has since been patched, but the team warns that agents with broad third-party access remain exposed to similar attacks.