• Home
  • Apple tightens Mac security controls…

Apple tightens Mac security controls over AI access risks

Apple is introducing additional controls around its macOS “Full Disk Access” setting following growing concerns over the security risks posed by desktop-based artificial intelligence agents.

The technology company said the feature, which was originally designed to allow applications such as backup tools to function properly, now presents greater risks as AI agents gain the ability to access and interact with files and other sensitive content on users’ computers.

Apple’s move comes days after Inc. columnist Jason Aten reported that Meta’s Muse AI app on Mac appeared to know the contents of his private messages despite his claim that he had not authorised the application to access them.

Meta disputed the claim.

The report renewed concerns about the level of security and privacy offered by desktop AI applications, particularly those capable of controlling functions on a computer and accessing personal files, messages and other data.

Apple’s decision also follows a Wired report that identified a flaw in the Mac version of OpenAI’s ChatGPT app that could potentially have allowed hackers to access sensitive user data.

Desktop-based AI agents often require users to grant them broader system permissions to perform tasks on their behalf. On macOS, users can enable Full Disk Access to give applications permission to access files, emails, messages and browsing history.

In Muse’s case, Full Disk Access is an optional permission that users can enable to give the AI agent broader access to content stored on their Macs.

“Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems…without users’ full knowledge and understanding,” Apple said in a new blog post aimed at developers.

Apple said it would introduce new controls requiring users who “genuinely wish to grant an app this extraordinary level of access” to take “very explicit” action before granting the permission.

“Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy,” Apple wrote.