# Apple Just Admitted the Permission Model Was Never Built for Agents That Read Everything

> Source: <https://dev.to/coridev/apple-just-admitted-the-permission-model-was-never-built-for-agents-that-read-everything-3afp>
> Published: 2026-10-06 10:37:38+00:00

Full Disk Access on macOS has been a binary switch for a decade: an app either gets to see your whole filesystem or it doesn't. That design assumption just quietly broke, and Apple's response tells you more than the incidents that caused it.

This isn't a new vulnerability class. It's an old one wearing a new badge. Overly broad OS permissions have been a known weak point since the earliest days of mobile app sandboxing, back when flashlight apps asked for your contacts list and nobody blinked. What's different here is the actor requesting access. A human-driven app asking for Full Disk Access is a one-time grant with a predictable, bounded blast radius: the app does what it was coded to do. An AI agent with the same grant is a different animal. It can read your Messages, your browser session tokens, your chat logs, and *decide on its own* what's relevant to whatever task it's running. The permission model assumed a fixed program with fixed behavior. Agents break that assumption by design. That's the actual news here, not that Apple shipped a settings update.

Calling this "the first OS-level move specifically targeting AI agent risk" is doing a lot of work in that headline, and I get why, it's a good hook. But let's be honest about what's actually overstated and what's underappreciated.

Overstated: that this is some novel security frontier requiring entirely new primitives. It isn't. It's the principle of least privilege, applied late, to a category of software that should have triggered it from day one. Apple tightening Full Disk Access because agents were caught reading everything they were given access to is Apple doing security 101, not innovating.

Understated: how badly the entire industry's permission scoping has lagged behind what these agents can actually *do*. Meta's Muse and the ChatGPT Mac app weren't doing anything clever or adversarial, they were just using the access they were granted, the same way any app would. The fact that "the way any app would" now means trawling private chat history and browser sessions for context is the real story, and it's an industry-wide problem, not an Apple-specific one.

Who benefits from the current framing? Apple gets to look proactive and user-protective with a relatively modest permissions tweak. AI vendors get to point at the OS vendor fixing the "root cause" rather than confronting the deeper question of why their agents default to requesting broad access instead of scoped, task-specific access in the first place. Everybody gets a tidy narrative. Nobody has to admit the agent design pattern itself (grab broad context, figure out what matters later) is the thing that needs rethinking.

For developers building on top of these platforms, this should be a wake-up call about scope creep in your own permission requests, not just a note that Apple changed a setting. If your agent needs to read Messages to do X, it probably doesn't need standing access to the entire disk to do it. The lazy path, request everything up front, is going to get harder on macOS and should get harder on every platform.

For security teams, this is a reminder that your threat model for "installed application" and "autonomous agent with filesystem access" cannot be the same model. Review processes built around static app behavior don't capture what an agent might decide to read at runtime based on a prompt you didn't write and can't predict.

For the broader industry, I'd watch whether other OS vendors follow with their own agent-specific scoping, or whether this stays an Apple-only move while everyone else waits for an incident bad enough to force their hand. History suggests the latter.

If the real fix is agents requesting narrowly scoped, task-specific permissions instead of broad filesystem access, why hasn't that become the default design pattern already, and is it the OS vendors' job to force it, or the AI vendors' job to build it that way from the start?

— Cor, Skyblue Soft

*AI-assisted draft or imaging, human-curated, reviewed and edited.*
