Apple Restricts AI Agents’ Access to Mac Data: Can India’s DPDP Act Prevent Similar Privacy Risks?

Apple Acts to Improve Privacy Handling of Agents in Macs

Apple unveils new privacy settings for macOS Full Disk Access After people became more concerned about the extent of data that AI agents could access on a Mac, Apple is providing further controls. The system company explained that some developers were using the access permission in ways that risk revealing your files, emails, messages and browsing history.

Apple has stated that next-generation permissions will be much more explicit before apps get this kind of access. Apple has associated the change with the growing power and independence of AI agents, which can run across a computer rather than simply wait for a question.

The invention has reopened a significant privacy concern in India. If a computer user’s files, messages, and other data can be accessed by an AI agent working on his or her behalf, can India’s Digital Personal Data Protection Act, 2023 protect that data?

📢 Get Legal Updates & Competitive Exam Notes
Join our WhatsApp and Telegram communities for legal updates, exam notes, opportunities, judgments and important legal news.
Join WhatsApp Join Telegram

Why Is Full Disk Access a Privacy Issue

This is a macOS permission that allows an app to have access to data stored on your entire Mac. Apple created this feature so backup apps could work with full disk access, but if the app is not a backup app it could give a third-party an extremely personal amount of data.

It gets even more complicated with AI agents, because they are built to act on behalf of a user. Rather than just responding to a query, an agent might have to read through a document, scan your messages, open apps and look up data stored on your device.

That debate was raised publicly last week when a reporter for a tech publication claimed the Meta Muse AI agent read his messages. Meta denied the report and explained that its Messages integration, if turned on, is completely opt-in and needs Full Disk Access and the Messages connector to be enabled.

However, this specific debate does not mean that the larger privacy issue isn’t also still valid. Simply, the more data an AI system is able to use, the larger potential impact it will have if it is mishandled, whether collected, used, disclosed or stolen.

How the DPDP Act Applies to AI Systems

Digital Personal Data Protection Act, 2023 The Digital Personal Data Protection Act, 2023 defines the processing of digital personal data and imposes duties on those parties that specify the purpose and manner of processing of personal data, as Data Fiduciaries. The Digital Personal Data Protection Rules, 2025 were notified by the Government on 14th November, 2025.

The relevant legal questions for a AI agent handling Indian user data would include what personal data it is collecting, for what purpose is it processing it, is there any legitimate basis for it to do so, how has it informed the user and what security safeguards has it taken.

The principles underlying the DPDP framework that come into play when an AI agent is granted access to far more data than what is arguably needed for a specific task are these: consent and transparency, purpose restriction, data minimisation, data retention limitation, security safeguards and accountability.

Could Consent Alone Protect Users?

Consent Data is a critical part of the DPDP framework, but a permission-button is not the magic cure for every privacy problem. Under the 2025 Rules notices must also be conspicuous, standalone and intelligible and must disclose what personal data will be obtained and for what purpose.

This is particularly important for AI agents because it is conceivable that a user may give the app permission to do something, but not realize that the app may be able to learn significantly more than the user has intended.

For example, a user-suggested AI assistant to help the user organise their documents might need access to the relevant files. Providing the same AI assistant with free access to the user’s emails, private chats, browser history or unrelated personal files might lead people to wonder if processing is limited to that purpose.

Thus the framework of DPDP alone already seems to paves the way for some implications on the question of what is the more-than-necessary collection and use of personal data.

Security Measures May Be Critical

In addition to the aforementioned obligations, the DPDP Act extends obligations in the related to reasonable security safeguards. The legislation prescribes large pecuniary penalties for shortcomings with respect to protecting personal data with the maximum prescribed fine being 250 crore for failure to take reasonable security safeguards to prevent a breach of personal data.

This may be especially relevant to agents driven by AI, because giving an agent access to a computer introduces a security vulnerability that may persist beyond that which is explicitly displayed to the user.

If an AI system is exploited, edited or mis-configured, the result may involve a vast amount of personal information being accessed. The legal responsibility for any breaches may depend on the facts and circumstances of the situation including who was handling the information, if the safeguards were in place and the capacity in which everyone was acting.

Can India Avoid the Apple-Style Privacy Danger?

The DPDP Act is capable of dealing with some of the issues plaguing the problem, but it does not function in the same manner as an Apple operating system restriction. The alteration suggested by Apple is a technical and UI lockout that intends to notify the user more explicitly prior to granting the extremely broad access.

The DPDP Act is a data processing law that places legal duties on organisations that process personal data. It may direct organisations to be transparent, use the right kinds of processing, and apply the right kinds of security protections, but it does not necessarily bar an AI application from asking for or obtaining a specific OS permission.

There’s a distinction here. Good privacy protection may involve both technical safeguards and legal obligations. An OS can prevent the access to personal data prior to its exposure; data protection law can specify what an organisation does with personal data once it has been collected or processed.

As AI agents can perform on applications and taps into data at a scale never before seen, the Indian privacy regime will thus be tested on questions which extend beyond app based data collection. The main question being whether a consumer really understands what they are agreeing to and whether organisations restrict AI systems to the minimum amount of personal data needed to accomplish the purpose for which access was provided.

Author

Leave a Reply

Your email address will not be published. Required fields are marked *