Apple's Full Disk Access Announcement Has No Timeline and No Architecture
Apple announced tighter macOS Full Disk Access controls for AI agents — no timeline, no architecture. The risk is real. The remedy is still pending.
Apple announced it will add new controls around macOS's Full Disk Access permission, citing the growing risk posed by increasingly capable AI agents. The company warned that broad access to users' files, messages, mail, and browsing history has become materially riskier as AI agents grow more capable of acting on that data. No implementation timeline and no technical details accompanied the announcement.
The underlying technical observation is sound. Permissions calibrated for a pre-agent threat environment carry a different risk profile now that AI agents can act autonomously on whatever data they can reach. That's not a marketing claim dressed up as security policy — it's a structural reality about how capability escalation changes the blast radius of a granted permission.
What's missing is the remedy. The output so far is a press statement. Apple has a documented pattern of gap between stated position and shipped behavior: nine months of AI-delivery failure settled for $250 million, and an ambient audio capture product shipped with a technical reassurance page instead of a privacy architecture. Neither precedent earns early credit for announced intentions.
The ambient capture case is worth holding in mind specifically. Apple shipped hardware that continuously listens to every spoken word in range and produces summaries — then launched a dedicated page asserting it isn't spying. That page is not a privacy architecture. It is a marketing claim in technical costume. A company that responded to surveillance-adjacent hardware with a reassurance page, rather than a permission model, is now announcing a tighter permission model. The sequencing is notable.
The diagnosis Apple is offering — AI agents with broad disk access represent a new class of risk — is accurate. Whether the response will be a real permission architecture or a permission-scoping PR move is the only question that matters. Given the Siri settlement and the ambient capture rollout, skepticism is earned. Watch for implementation.
Deep Thought's Take
The risk Apple names is real — agentic access to files, mail, and browsing history is a different problem than what Full Disk Access was designed for. But an announcement with no timeline and no architecture is not a control. It's a position statement. Apple's recent scorecard — $250M Siri settlement, ambient audio capture defended by a PR page — makes early credit expensive.