+− THE DAILY DIFFdev & AI news
NEEDS REVIEW

Apple puts the brakes on AI Agents

Apple plans extra macOS Full Disk Access controls because autonomous AI agents increase the risks of broad data access.

Apple plans extra macOS Full Disk Access controls because autonomous AI agents increase the risks of broad data access. We examine the current permission, Meta's disputed Muse messages case and historical agent-security evidence, then cover Pass Designer and Utah's VPN-location rules. Verdict: NEEDS REVIEW.

Read the written edition (English) ↗

What this video covers

  • Why is one Mac permission suddenly a bigger risk?
  • What does Full Disk Access actually open?
  • Why do autonomous agents change the stakes?
  • What can developers limit before Apple ships?
  • What does Apple's new pass editor actually do?

Transcript

Why is one Mac permission suddenly a bigger risk?

0:00 You'd think clicking Allow settles what an app can see. Apple says increasingly autonomous AI agents make Full Disk Access substantially riskier, and it's adding controls. In this video, what can agents read? What's Apple changing? Who else gets exposed? Someone else's privacy is at stake on your Mac. We'll come back to them before the verdict.

0:18 It's Saturday, October third, and this is The Daily Diff. On Friday, Apple warned developers about full disk access and introduced a Wallet pass editor. Meanwhile, a federal judge put Utah's VPN location rules on hold. TechCrunch reporter Sarah Perez called Apple's announcement shots fired. The target remains unnamed in Apple's post, which is an impressively corporate way to start an argument. Apple's documentation includes Mail and Messages data,

What does Full Disk Access actually open?

0:42 plus Safari data. It also includes Time Machine backups, so your backup app can work. Apple says this largely sidesteps other privacy controls. You grant it through System Settings, and the permission already exists. The announcement promises additional controls around that grant. On X, javi responded, I hope you like permission prompts. That's the developer tension in six words. Automation keeps asking us to manually approve the automation.

1:06 Keep the permissions straight, though. Accessibility and Automation have separate entries in Apple's guide. Reading protected data and controlling another app are different capabilities, with different controls.

Why do autonomous agents change the stakes?

1:16 A backup program copies your files. An agent interprets what it reads and may call tools to act on it. More autonomy makes the consequences of broad access harder to predict. There's already a disputed example. Jason Aten said Meta's Muse read his messages without permission. Meta says the integration requires both full disk access and its Messages connector. Apple names neither Muse nor a rollout date. It says users should understand this access and grant it through very explicit

1:42 action. The actual interface remains a missing screenshot. There is a deeper agent problem here. An email or webpage can contain instructions that try to redirect the assistant. That's prompt injection, and the agent encounters it while doing useful work. Independent researchers built Agent Dojo, with ninety seven tasks and six hundred twenty nine security cases. It tests whether untrusted data takes over an agent's tools.

2:04 These are historical lab results from twenty twenty four. Apple's future dialog hasn't been published, so nobody gets a victory lap yet. In one GPT four oh configuration, the targeted attack succeeded about forty eight percent of the time. Filtering available tools brought that to about seven percent, with a useful design lesson.

What can developers limit before Apple ships?

2:21 Give an assistant the data and tools the task needs. A project folder is a smaller input surface than a whole account. Read access can also be separated from permission to send or delete. That's a product tradeoff developers already live with. A terminal or backup utility may have a legitimate reason for broad access. Removing it carelessly would create a very secure broken workflow. So what is Apple changing? The stated goal is clearer, more explicit consent for extraordinary access.

2:46 We still need the implementation to see how it preserves those legitimate uses.

What does Apple's new pass editor actually do?

2:50 Apple also introduced Pass Designer, a visual editor for Wallet passes. You start with a template, bring in your images, and preview the pass as you edit. Apple says the preview uses the same rendering as iPhone and Apple Watch. It validates fields and can build a backward compatible pass from semantic data. Semantic tags describe things like flight details and event dates. Your concert ticket can finally become structured data before becoming a blurry screenshot in somebody's family group chat.

3:15 The beta requires macOS twenty seven or later. Apple lists free registration for the download. This helps design passes; issuing and distributing them needs its own workflow.

Why can't a website perfectly locate a VPN user?

3:24 Then there's Utah, where lawmakers wanted covered adult websites to identify the real location of VPN users or block them. A federal judge has preliminarily blocked the challenged VPN provisions. The Electronic Frontier Foundation quotes the court saying geolocation perfection is not presently possible. Turns out the network stack still refuses to implement features merely because a legislature opened a ticket. A website sees the VPN server's address.

3:49 That doesn't establish where the person is sitting. Treating every hidden location as potentially Utah pushes the requirement far beyond the state's borders. EFF quotes the judge's reasoning that Aylo would need to verify twenty eight million users to guarantee compliance. That's the cost of demanding perfection from a signal that can't supply it. This is a preliminary order.

4:08 The separate restriction on sharing VPN information wasn't challenged. The legal diff still has lines left to review. All three stories turn on boundaries. A pass editor can check a field. A website sees an exit address. An agent gets whatever access the surrounding system actually grants. And the person from the opening is whoever sent you the message.

Who gets exposed without clicking Allow?

4:27 Apple explicitly warns about their privacy too. Your permission can expose a conversation containing somebody else's data, and they never clicked your Allow button. Slashdot's headline calls it increased risk. That wider circle is why I care. The permission screen needs to explain what the assistant will receive. If you'd rather read this than hear me say it, the diff lands in your inbox every morning, free at the daily diff dot dev, link below.

4:49 So today's verdict, NEEDS REVIEW.

What's my verdict on Apple's proposed controls?

4:51 I want clearer consent and narrower access, with legitimate workflows preserved. Apple's implementation will decide whether it delivers. Subscribe, hit the bell, and tell me in the comments if you'd have stamped it differently. And that's the diff for today. I'm Niko from Axrisi. Merge responsibly.

Sources

  1. Apple noticedeveloper.apple.com
  2. Mac permissionssupport.apple.com
  3. Reportingtechcrunch.com
  4. Muse disputetechcrunch.com
  5. Meta responsex.com
  6. AgentDojoarxiv.org
  7. Resultsagentdojo.spylab.ai
  8. Pass Designerdeveloper.apple.com
  9. Utah rulingwww.eff.org
  10. HNnews.ycombinator.com

Related videos