It appears agentic AI is all the rage: OpenAI's new agents, "Dots," rolled out this week, while Meta's Muse just passed five million downloads. Rather than just chatting with or using them to generate images, AI companies want users to start asking their bots to do things on their behalf, from managing their inboxes to ordering dinner.
But agents aren't just the next logical step for AI as a technology. When implemented poorly, they can be wildly dangerous. AI agents are designed to run on their own, and, in order to do that, they often need near-total access to your devices and their data. Some people are now giving agents full use of their computers, including all of their messages, files, passwords, and accounts. That's a lot of trust, especially when it's not that difficult to "hack" one of these agents for malicious purposes with a poisoned prompt hidden on a website, which could lead your AI agent to hand hackers the keys to your bank accounts. That's no good.
Apple is making it much more difficult for you to put yourself in this situation #
How does Apple feel about this? The company is famously behind on the software side of AI—it only rolled out its AI-powered version of Siri in September—but its AI hardware business is booming. When the AI agent craze first took off with projects like Moltbot, customers bought Mac minis in droves in order to run those programs. Now, Apple advertises its various Macs with AI at the forefront: It doesn't offer its own models like OpenAI or Anthropic, but it's making plenty of money selling you the hardware to run those models.
Perhaps that's why Apple seems quite concerned about the AI agent trend, particularly when it comes to the data users are exposing to run these programs. Apple is all about privacy and security, and as such, I can only imagine the company watching in horror as so many users willingly hand their Macs (and all of their data) over to automated AI bots.
Against that backdrop, the company posted an update on its developer forum entitled "Updates to Full Disk Access in macOS." In it, the company highlights the dangers of developers asking users to grant "Full Disk Access" permissions to an app. Apple says this function has been traditionally reserved for backup apps that need to access the entire disk to function. (After all, if your backup app can't access your entire Mac, how can it back up your entire Mac?) But now, Apple says developers are asking users to expose everything on their Macs, including messages, mail, browsing history, and more, without those users fully understanding the consequences. Apple even argues the privacy implications extend beyond the user, as communication apps that demand Full Disk Access compromise the people the user is chatting with, too.
And Apple appears to be doing something about it: While details are slim, the company says it will introduce "additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action." I'm guessing this means that in the future, once you download an agent to your Mac, you'll have to click through a series of warnings and settings to "prove" to macOS that you really want to expose your entire Mac to the app and its AI. The company says it's doing this now, as the threat will only grow as AI agents improve and become more autonomous.
The risks of AI are increasing across the board #
I'm all for additional safeguards when it comes to AI. In the past, you needed some level of technical expertise to install an AI agent on your Mac. As such, you likely understood the risks involved, or willfully ignored all the warnings in order to do so. Now that running agents is as easy as installing Muse on your Mac, the barrier to entry is minimal. Anyone can do it, even if they don't fully understand what they are actually doing. As the AI industry reckons with the risks its technology poses to humanity, companies like Apple should indeed be figuring out how to protect their users from AI's current dangers—even if users can still choose to ignore those warnings.