AI agents that can access files, control apps, and act on behalf of users are prompting operating system makers to rethink permissions. Apple plans additional controls for applications seeking full disk access on macOS, requiring more explicit user action before the permission is granted. The company linked the change to AI agents that can act with less user intervention and to risks that broad access can expose files, mail, messages, and browsing history. Full disk access was designed for cases such as backup software and cannot be obtained silently by an app. Once granted, however, an agent can use the same permission to read information and take further actions. Microsoft is developing agent accounts and agent workspaces on Windows 11 so an agent can run under a separate standard account with limited permissions and a separate environment. It is also working on contained Model Context Protocol servers that run under a separate agent account.
AI agents that can access files, control apps, and act on behalf of users are prompting operating system makers to rethink permissions. Apple plans additional controls for applications seeking full disk access on macOS, requiring more explicit user action before the permission is granted. The company linked the change to AI agents that can act with less user intervention and to risks that broad access can expose files, mail, messages, and browsing history. Full disk access was designed for cases such as backup software and cannot be obtained silently by an app. Once granted, however, an agent can use the same permission to read information and take further actions. Microsoft is developing agent accounts and agent workspaces on Windows 11 so an agent can run under a separate standard account with limited permissions and a separate environment. It is also working on contained Model Context Protocol servers that run under a separate agent account.