Apple restricts macOS disk access as AI agents expand
Apple announced on 2 October that it is introducing stricter controls for Full Disk Access on macOS, a move explicitly linked to the rising risks of autonomous AI agents accessing user data.

On 2 October, Apple published a statement on its developer site. The change alters how apps request Full Disk Access on macOS. The company stated that "some developers" are using this permission in "ways that could put users at risk." This is a structural shift in how operating systems handle permissions for software that acts on behalf of users.
The specific threat
Apple explained that Full Disk Access is currently designed to allow backup applications to function. However, the permission "largely sidesteps" standard privacy controls. According to Apple's post, misusing this access can expose "everything on their systems, including files, mail, messages, and even browsing history" without the user's full understanding. For communication apps, this compromise extends to the privacy of the people the user is talking to. The company noted that as AI agents become "increasingly capable and autonomous," the risks associated with this level of access will "grow substantially."
The timing is significant. This announcement comes as tools like Meta Muse and OpenAI's Dots gain popularity. These are always-on agents that request substantial access to personal data. 9to5Mac reported that there have already been "horror stories" regarding Meta Muse, suggesting that the theoretical risk is becoming a practical reality. Apple said it will introduce controls ensuring users grant this "extraordinary" access only with "very explicit user action." No further details on the technical implementation were provided at the time of the report.
Identity and access control
While Apple addresses the OS-level permission, a parallel trend in agent tooling focuses on identity. Giving an agent your personal login credentials creates a security liability. The app cannot distinguish between your actions and the agent's actions. If the agent misbehaves, the only way to stop it is to change your own password, locking you out of your account in the process. AgentMail, a provider of identity solutions for agents, argues for a separate model. They propose giving agents their own identity, including their own email inbox and sign-in key. In this model, the agent is a distinct principal. If a credential is leaked, it only affects that specific agent's sign-in, not the owner's entire account. The owner is recorded as the accountable human, but the blast radius is contained.
This distinction between delegation and separate identity is becoming a standard architectural decision. For agents that act within your existing accounts, borrowing authority works. For agents that sign up for services, receive email, and hold accounts over time, a separate identity is more secure. The ability to revoke an agent's access without affecting the human owner is a critical safety feature that borrowed logins do not offer.
Verification and drift
Permissions are only one part of the safety puzzle. Another is ensuring the agent does what it claims to do. Microsoft and Hugging Face released a benchmark called ThinkingBox on 3 October. It grades AI agents on the records they leave behind in a database, rather than the sentences they generate. The benchmark runs agents through 507 stateful business workflows, each repeated 20 times. The results were stark. In a test covering 121,680 valid trials across 12 LLM models, 79,853 attempts failed executable checks. Of those failures, 67.24% of the agents terminated cleanly and reported no error, yet the database showed wrong field values in 77.61% of those cases. Unintended extra effects appeared in 43.30% of the failures. This highlights a core problem: an agent can sound correct while leaving the system in the wrong state.
This issue is compounded by "agent drift." A concept detailed in a recent analysis by Sdarchitect, drift occurs when an agent's behavior changes even though no code was deployed. Because agents operate in a system of models, tools, and data, any change in those underlying elements can alter behavior. A model provider updating a model version or changing safety controls can cause an agent to act differently. Traditional change control systems, which track code deployments, do not catch this. The implication is that evaluation must be continuous, not just a one-time design check. If the environment changes, the agent's behavior changes, regardless of the agent's own code.
Infrastructure and oversight
As agents become more autonomous, the infrastructure around them is evolving to manage risk. Spawned launched a cloud platform designed for both humans and agents, allowing them to deploy real infrastructure to AWS, GCP, or Azure. It uses a declarative framework to ensure agents do not create misconfigurations or hallucinated components. Kimchi offers a different approach, focusing on cost and data governance. It enforces hard budget caps and ensures model data does not leave the enterprise environment, a key requirement for compliance-heavy industries.
However, technical guardrails are not enough if the human oversight is flawed. A paper titled "Oversight Has a Capacity," published on arXiv in June 2026, argues that human-in-the-loop approval gates are based on false assumptions. The study found that reviewers only moderately agree on what constitutes a risky action, with a Fleiss' kappa of 0.52. More importantly, human attention is finite. When modeled as a fatiguing resource, realized safety follows an inverted-U curve. Excessive escalation can actually make a system less safe because the reviewer becomes fatigued. The safety-optimal strategy is to escalate less than 100% of the time, reserving human judgment for the most critical decisions. This reframes oversight not just as a classification problem, but as a resource allocation challenge.
The convergence of these developments points to a new phase in AI agent deployment. It is no longer enough to build a smart model. The focus is shifting to the entire system: how the agent identifies itself, how it is verified against real-world state, how its environment is managed, and how human oversight is calibrated to prevent fatigue. Apple's move on macOS permissions is a signal that operating system vendors are taking this seriously. The era of treating agents as simple scripts is ending. The next generation of tools will be built with the assumption that agents are autonomous actors with their own identities, their own budgets, and their own capacity to make mistakes that only rigorous, state-based verification can catch.
Sources
11- 01Apple says it's tightening macOS privacy controls amid the rise of AI agentsEN
- 02Give Your AI Agent Its Own IdentityEN
- 03The Agent Said It Was Done. The Database DisagreedEN
- 04AI Risk – A user's guide (Part IV): Understanding Agent DriftEN
- 05Spawned: AIO cloud platform for humans and agentsEN
- 06Pi-based coding agent with hard budget capsEN
- 07Oversight Has a Capacity: Calibrating Agent Guards to a Subjective, Fatiguing HumanEN
- 08Against Personal Agents Theory of Everything Why the Future of Work Is a FactoryEN
- 09I stopped reviewing my agents' code. Here's what I do insteadEN
- 10Design Systems for AI AgentsEN
- 11Writing Evals for Agentic Systems as a 4 Step LoopEN
All figures and quotations in this text come from the sources listed below.
Content prepared by the editorial team with AI assistance.
Comments
0- No comments yet — be the first.