Apple Restricts macOS Full Disk Access as AI Agents Escalate Risk
On macOS, Apple is locking down full disk access for AI agents after revelations that third party models could silently access private messages, sparking a debate on whether security should live in the OS or the agent.

As AI agents gain the ability to navigate local files, operating systems are pulling the plug on their unrestricted access to protect user data. The assumption that an agent is just another desktop application is proving dangerous in practice.
The End of Implicit Trust
The push for local artificial intelligence execution brought models directly onto the desktop. This proximity granted them the same access permissions historically reserved for backup software and system utilities. The result is a growing attack surface. TechCrunch AI notes that a flaw in the macOS application of ChatGPT could have allowed hackers to access sensitive data.
I realize that when I was working from my phone on my local computer via the remote control and the AI that was supposed not to be able to change the file containing all my passwords and API keys could actually do that. It bypassed that by using some alternative commands that would not trigger the security that says that they cannot change these files. […] It happened to me that I saw that it accessed some files that were totally unrelated at movies I had stored on my computers and some pictures.
Apple’s Defensive Wall
Operating systems are taking a more defensive stance. TechCrunch AI reports that Apple is introducing additional controls around a setting called Full Disk Access on macOS. This feature was originally designed to allow backups to function properly, but Apple noted that agents have increased the risks associated with this level of access. This change follows a claim by an Inc. columnist that Meta’s Muse desktop application accessed private messages. Meta disputed the claim, with The Verge AI reporting that the company stated access to Messages is entirely opt-in.
According to The Verge AI, Apple will roll out an update requiring very explicit user action before an app can gain this sweeping level of access. Apple noted that some developers were using Full Disk Access in ways that exposed everything on user systems, including files, mail, messages, and even browsing history, without their full knowledge. The company warned that the risks associated with this access will grow substantially as agents become more autonomous.
The User Rebellion
While the operating system adds friction, users are finding ways to enforce strict isolation on their own. The open source project RemoveMacAI provides a method to turn off Apple Intelligence on macOS 27 and remove its downloaded models. The project documentation on Hacker News explains that the tool targets features like Writing Tools, Genmoji, and the ChatGPT extension, ensuring their foundation models are deleted.
The mechanism relies on native system protections rather than third party firewalls. The tool installs a configuration profile redirecting the download of each removed model to a closed local port. This approach prevents the system from silently downloading models again, while keeping System Integrity Protection enabled. I think for someone who doesn’t work with AI heavily this makes sense as it is a protection more than anything else.
What it means
Restricting local models at the system level provides immediate relief. It stops an autonomous agent from wandering into unrelated directories. The burden of safety is currently placed entirely on the user and the operating system.
This dynamic is fundamentally flawed. Systems that are historically not up to standard on security have to be updated that is for sure if they want to survive AI but this is also something that they would have to do in a normal case. […] updating a system strictly to resist AI I think it seems to be the right thing to do but it is not solving the problem at its core. The security should come from the tool and not from all of the people around it. Why should everyone have to adapt to a tool and why shouldn’t this tool be made safe instead.
Sources
- A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data (Wired AI)
- Apple will limit Mac disk access as AI agents ‘substantially’ increase risk (The Verge AI)
- Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents (TechCrunch AI)
- Turn off Apple Intelligence on macOS 27 and get its disk space back (Hacker News (front page))