Apple Rethinks macOS Full Disk Access for Agents
Apple says it will add stronger consent controls around macOS Full Disk Access, which can expose files, mail, messages, and browsing history to apps and autonomous agents. Ben Thompson’s analysis connects the move to a compromised always-on Mac mini and Apple’s broader struggle with agent-native computing.
Apple is right about blanket access, but macOS still treats agents like human-operated apps. The better answer is agent-scoped, capability-based permissions with clear auditing—not unrestricted root access or invisible GUI prompts.
- –Full Disk Access has an enormous blast radius, so an explicit confirmation step is necessary but not sufficient.
- –macOS TCC prompts are poorly suited to headless agents, forcing developers into brittle remote-GUI workarounds.
- –Unix tooling, automation APIs, and Apple Silicon make Macs excellent agent hosts, while exposed screen sharing can create serious attack surfaces.
- –Developers should isolate agents, apply least privilege, and use VPN or SSH tunnels instead of exposing remote desktop services.
- –Apple’s next permission model must account for agents spawning code and tools, not just the top-level application.
DISCOVERED
1h ago
2026-10-05
PUBLISHED
3h ago
2026-10-05
RELEVANCE
AUTHOR
maguay