Yeah, "very". They're going to make it like sudo where when you give permission to a program to write protected files once it has it forever after.
No, wait, that isn't how it works, is it?
That's how it already works. But you can request the permission from the user with a pop-up. Presumably a "very explicit action" means going into the Settings app and turning it on by hand.
But that's going to do exactly nothing. The app will tell them that they have to do this, and the users, having no idea how dangerous it is to give an AI unrestricted access to their device, will do it anyway, and we'll be right back to where we are now. And the next step will be "See, we can't allow full disk access." And then macOS will cease to be usable.
The only reasonable choice is to flag Meta's software as malware for extending their full disk access to agents. Force them to implement a proper sandbox. Apple already gives them all the tools they need to do it right.
- The main host app asks for full disk access, but functions without it, triggering an open file dialog to work around missing access when necessary. Most users will end up granting full disk access out of frustration, but that's okay because the agents themselves don't have that access. If possible, make it start out with a read-only full-disk entitlement, because otherwise, using it will be much harder.
- Each agent runs in a separate agent runner process with a stricter sandbox.
- The agent sandbox has an entitlement that grants read-only access to the entire disk (or, if the main host app's sandbox doesn't allow that, to every resource that the main host app has access to), and bans the use of the socket() system call.
- AI agents can request read-write access to specific files or directories by asking the host app. The agent is encouraged to ask for access to an entire directory at once if it needs to write to multiple files in that directory.
- The host app can pass in a security-scoped bookmark/URL to grant permission, but asks the user first unless the URL is part of an explicit list of allowlisted URLs that the user provided before beginning the task. Doing this expands the sandbox to allow writing to that file or to files in that directory. The SSB can be created programmatically or, if the main app also doesn't have access, through showing an Open File dialog.
- One tool provides network access to specific hosts with no POST, all GET parameters filtered, and a low limit on URL length to mitigate exfiltration risk. This tool has an entitlement that allow socket access inside an environment where opening sockets is otherwise banned, and thus can be run directly by AI agents.
- One tool provides broader network access with full upload capabilities. This tool lives outside the sandbox so that the AI agents cannot run it themselves — only ask the main host app to run it for them. Then:
- The main host app requires the user to give permission to access a single hostname for either a single request (allow once) or a single task (always allow for this task).
- If the user clicks the "Always allow sending data to example.com" button, the user is asked "Trust example.com for similar request parameters only" or "Trust fully".
- If the user choose to trust similar request parameters only, then any additional GET parameters must be explicitly allowed each time.
- The main host app passes each AI agent runner a new open socket connected to the AI service's server.
- The AI service's server is configured to provide minimal or no network access from the server side.
This is how you protect privacy in an agentic environment.