Apple Wants to Make It Harder to Run Agentic AI on Your Mac.

Agent-based AI seems to be all the rage these days: OpenAI’s new agents, called ” Dots ,” were released this week, and Meta’s Muse surpassed five million downloads . Instead of simply chatting with bots or using them to generate images, AI companies want users to start asking their bots to do things on their behalf, from managing emails to ordering dinner.
But agents aren’t just the next logical step in AI technology. If implemented incorrectly, they can be extremely dangerous. AI agents are designed to operate autonomously, and to do so, they often require near-total access to your devices and their data. Some people now grant agents full access to their computers, including all messages, files, passwords, and accounts. This requires a tremendous amount of trust, especially considering that it’s not that difficult to “hack” one of these agents for malicious purposes using a malicious prompt hidden on a website , which could lead your AI agent to hand over the keys to your bank accounts to hackers. This is unacceptable.
Apple makes it much more difficult for you to create such a situation.
How does Apple feel about this? The company is notoriously lagging behind in AI software development—it only released its AI-enabled version of Siri in September—but its AI hardware business is thriving. When the AI agent craze first took off with projects like Moltbot , customers were buying up Mac minis in droves to run these programs. Now, Apple is marketing its various AI-enabled Mac models as essential tools: it doesn’t offer its own models like OpenAI or Anthropic, but it makes a lot of money selling you the hardware to run them.
Perhaps this is why Apple is so concerned about the trend of using AI agents, especially when it comes to the data users provide to run these programs. Apple prioritizes privacy and security, and so I can only imagine the company watching in horror as so many users voluntarily hand over their Macs (and all their data) to automated AI bots.
Against this backdrop, the company published an update on its developer forum titled ” Updates for Full Disk Access in macOS .” In it, the company highlights the dangers of developers asking users to grant apps “Full Disk Access” permission. Apple states that this feature was traditionally intended for backup apps, which require access to the entire disk to function. (After all, if your backup app can’t access your entire Mac, how can it back up your entire Mac?) But now, Apple says, developers are asking users to expose all the data on their Macs, including messages, mail, browsing history, and more, without users fully understanding the consequences. Apple even argues that the privacy implications extend beyond the user, as communication apps that require full disk access also put the people with whom the user communicates at risk.
And it looks like Apple is doing something about it: while details are scarce, the company says it will implement “additional controls to ensure that users who genuinely want to grant an app this unusually high level of access can only do so through very explicit user action.” I assume this means that in the future, after downloading an agent to your Mac, you’ll have to go through a series of warnings and settings to “prove” to macOS that you truly want to grant access to the app and its AI to your entire Mac. The company says it’s doing this now, as the threat will only grow as AI agents become more sophisticated and autonomous.
The risks associated with artificial intelligence are growing everywhere.
I fully support additional security measures when it comes to AI. Previously, installing an AI agent on a Mac required a certain level of technical expertise. Consequently, you likely understood the risks involved or intentionally ignored all the warnings. Now that running agents is as simple as installing Muse on a Mac, the barrier to entry is minimal. Anyone can do it, even if they don’t fully understand what they ‘re doing . As the AI industry acknowledges the risks its technologies pose to humanity , companies like Apple really should be thinking about how to protect their users from the current dangers of AI—even if users may still ignore these warnings.