LIVE FEED
Apple Tightens macOS Full Disk Access Controls for AI Agents

Apple Tightens macOS Full Disk Access Controls for AI Agents

FIRST LOOK ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 7.2 TechCrunch AI

Apple is introducing stricter controls around macOS Full Disk Access permissions in direct response to the expanded risk surface created by desktop AI agents capable of autonomously reading files, messages, and browsing history. This closes a critical consent and visibility gap for defenders by ensuring users must take explicit, informed action before granting AI agents extraordinary system-level access. What remains unaddressed is whether third-party AI agent developers will align their permission requests to the spirit of these controls, and how enterprise MDM policies will be updated to reflect the new access model.

OpenAI Training Opt-Out Setting Silently Re-Enabled for Users

OpenAI Training Opt-Out Setting Silently Re-Enabled for Users

ATLAS OWASP MEDIUM Moderate risk · Monitor closely ▲ 6.2 OpenAI (via HN)

Multiple users report that OpenAI's 'allow training' opt-out setting is being silently re-enabled after they deliberately disabled it, raising serious concerns about data governance and user consent. A similar pattern has been observed on Anthropic's Claude platform, suggesting this may be a broader industry practice tied to TOS updates or subscription renewals. The behaviour undermines the integrity of privacy controls and means sensitive user conversations may be incorporated into training datasets without genuine informed consent.

OpenAI Launches Private Safety Processing for Zero-Data Monitoring

OpenAI Launches Private Safety Processing for Zero-Data Monitoring

FIRST LOOK ATLAS OWASP MEDIUM Moderate risk · Monitor closely ▲ 7.2 TechCrunch AI

OpenAI has previewed Private Safety Processing, a new automated safety monitoring system that analyses cross-session usage patterns for potential misuse without retaining customer data or requiring human review. This closes a meaningful gap for enterprise defenders who previously had to choose between meaningful safety monitoring and data privacy — cross-session behavioural analysis can now detect distributed evasion attempts under Zero Data Retention. Residual maturity questions remain around transparency of triggering thresholds, signal fidelity, and how organisations integrate this capability into their own security operations workflows.

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.