Apple tightens macOS Full Disk Access, citing AI agent risks

Desktop AI is forcing the operating system's hand. Friday's news window pairs an Apple privacy-policy signal aimed straight at autonomous agents with Anthropic turning certification into a residency program — and a video-avatar startup claiming a Turing-test milestone on very thin evidence.
Apple says it will tighten macOS Full Disk Access controls because AI agents have raised "the risks associated with this level of access." The company's developer notice, published Friday, warns that "some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems — including files, mail, messages, and even browsing history — without users' full knowledge and understanding," and promises that granting the permission will soon require "very explicit user action." The trigger is easy to trace: within the last week, a journalist claimed Meta's Muse agent knew the content of his private messages without permission — a claim Meta disputed — and Wired reported a flaw in ChatGPT's Mac app that could have let hackers grab sensitive data. Apple disclosed no timeline, no macOS version, and no specifics of the coming controls, so this is a statement of intent rather than a shipped change — but it is the platform owner saying out loud that permissive OS-level grants were designed for backup software, not for agents that act on their own. We covered the Muse zero-day that set this whole week in motion — Meta's Muse assistant shipped with a local zero-day.
Anthropic is putting $100 million behind a training program meant to produce 10,000 "Frontier Deployed Engineers" by the end of 2027. The Claude Frontier Academy launches Friday with first cohorts drawn from Accenture, Bain, Capgemini, Commonwealth Bank of Australia, Deloitte, McKinsey, Morgan Stanley and Novo Nordisk; engineers are nominated by their employers, start with a multi-day in-person program run with Anthropic's own engineers, pass a graded practical, then lead a real Claude project at their own company during a 12-week residency before earning the credential — first badges expected in early 2027, with cohorts running now in San Francisco, New York and London. Read it as a distribution play wearing a training program's clothes: Anthropic already reports 175,000 Claude certifications across 46,000 firms, and the constraint Anthropic names in its own announcement is not model capacity but the handful of people inside each customer who can put the model into production. Certificates scale a brand; a residency scales a reference customer list — every graduated engineer returns to a named project with Anthropic's fingerprints on the architecture.
Tavus says its new Griffin model passed a "video Turing test," with 48% of live-chat participants believing it was a real human. The company frames Griffin as the first "Human Interaction Model": in its self-run study, 26 of 54 participants in one-minute video chats could not reliably tell Griffin apart from a person, versus a 1-in-41 miss rate for Tavus's previous system, and Nvidia's independent VideoFDB benchmark scores Griffin at 3.83 out of 5 against a human reference clip at 3.92. Treat the headline number carefully — the study is the company's own, the test is the company's own definition, 54 one-minute conversations is a small sample, and the product is not shipping: only a Griffin-Lite build goes to trusted testers, with disclosure tooling still in progress. The direction is what matters: when a synthetic face survives half of first impressions, the burden of proof in a video call flips from the machine to the viewer.
What to watch: whether Apple's Full Disk Access changes show up in the next macOS beta — and whether Google and Microsoft apply the same logic to their desktop agents.
Is a platform-level permission wall the only thing standing between your files and someone else's agent? Tell us in the comments.




