The company says it will add new privacy protections in macOS to combat new dangers posed by artificial intelligence agents. Apple has pointed out the dangers posed by applications with a “Full Disk Access” permission, which could give them access to sensitive data stored on a Mac such as files, e-mails, messages and browsing data.
Apple said others are utilizing Full Disk Access in a manner that may potentially reveal customer data without users’ full awareness of the scope of permission granted. The company said the controls it will roll out in the future will demand an additional step from users before providing such extensive access. Apple has tied the change directly to how advanced and autonomous AI agents have become.
The conundrum is a noteworthy legal question in India – if the AI agent is permitted to fetch from the computer the information stored there, what are the responsibilities of the companies that maintain the AI agent under Indian data protection law?
Why Is Full Disk Access Important?
Full Disk Access to macOS in a way that grants an app access to information that is typically shielded by others privacy restrictions. Apple created this permission so the source for information to be moved by apps like back-up applications; yet, with AI representatives, this has become a privacy complication as these offices make it simple for using information or a different program.
A more capable AI agent might be able to access files, emails, messages, calendars, and more. While a conventional app is designed to do one thing, an autonomous agent might be able to act on information it’s discovered on the user’s device.
This operationalises a legal differentiation between having the information stored on a device, and allowing another party to access, view, analyse or otherwise process the information.
What Does Indian Data Protection Law Say?
What are the legislative requirements in India? The primary law on this subject in India is the Digital Personal Data Protection Act, 2023. The Rules are the Digital Personal Data Protection Rules, 2025, and set out the Rules for implementing the Act. Data Fiduciaries are the bodies that decide the purpose and means of processing of personal data.
It builds on fundamental principles of consent and transparency, purpose limitation, data minimisation, accuracy, storage limitation, security safeguards and accountability. These principles become critical when an AI system is granted access to vast amounts of information.
The crux of the matter is thus not just whether a user pressed “Allow” in a Mac question. The legal issue may extend to what is then processed, on what grounds, to what extent, and under what protection.
Consent Must Be Meaningful
The DPDP framework is heavily focused on consent. Consent in the context of the processing of personal data should be specific to the purpose of processing, informed and revocable.
This is especially relevant with AI agents. A user may know that an app needs to be granted access to do something but may not realize that granting access to that one thing will also grant access to everything else, all of the other emails, messages, documents or browsing history.
Apple’s move to make them take more deliberate action before Full Disk Access is a matter of privacy, too. “Users should make informed decisions before providing such extraordinary access,” Apple said.
One thing to keep in mind, though, is that Apple’s technical permission system and India’s legal permission law are not the same. A one-time system permission from a user in itself doesn’t necessarily have all the answers to Indian data protection law.
Data Minimisation and Purpose Limitation
Processing personal data for a lawful purpose and limitation on processing to the extent necessary for that purpose is given due weightage in Indian data protection law.
For instance, if an AI system is to be used to summarise documents that a user has selected, then having access to their entire computer could be questioned as being necessary for that particular purpose.
As the AI agent’s power increases, this distinction may become even more crucial. There is a difference between an application that has the technical ability to process and access vast amounts of information, and one that is legally required to do so.
Apple’s developer guidance also recommends that applications access only the protected resources they need.
Security and AI Agents
Another concern is data security. AI agents have the ability to interact with external content, websites, emails and documents. Apple has warned developers of potential dangers like Indirect prompt injection whereby instructions lurking in content can lead to an AI system being influenced and taking unwarranted actions.
Specifically, Apple’s developer documentation describes situations in which an attacker might try to trick an AI agent into leaking data, handing over data, or executing an undesirable action.
Data Fiduciaries will have to put in place ‘such reasonable security safeguards’ to safeguard personal data under the DPDP regulations. Personal data breach notifications and security safeguards are also mentioned as provisions in the Rules subject to the notified date of commencement.
Hence, while organisations utilising AI agents in India might have obtained consent, they would also have to ensure that their systems are not exposed to unauthorised access, misuse and breaches.
Who Could Be Responsible?
There are other important legal issues to consider, such as Who is liable for processing this data? The AI agent might have a number of persons involved, such as the software developer, the software provider, the developer of the application and third-party service providers.
In India, the liability is based on the role that a particular entity plays as well as the context in which the personal data is processed. Therefore, a company, for example, cannot escape its obligations by having an automated AI system to perform the processing.
This is even more relevant as AI agents evolve from giving answers to taking actions for users. As an agent can both read private data and act on other tools without human intervention, the repercussions of too much access can be vastly worse.
What Apple’s Move Means for India
Apple’s rationale is driven by a concern for the privacy and security of the user’s machine and not by the implementation of Indian law. However, there are a number of related concerns that have implications for Indian law.
Basic idea: access to data should be linked to a valid purpose, made aware to the individual and safeguarded against abuse (through good security). Wide technical access does not necessarily mean unfettered processing of anything that can be accessed on the device.
In the future, when AI agents are given more freedom, the legal debate could shift away from the application actually gathering data. The regulators and courts may have to focus more on the question of what an AI agent can reach, decide, do, and whether the person really understood the implications of giving it access.
Apple has not said when the new Full Disk Access controls will be available or how they will work. But the company’s statement shows the dilemma facing the tech industry: how to provide AI agents with sufficient access to be useful, but still keep user data available to the user for control and law enforcement.



