Apple Will Require More Explicit Consent for AI Agents’ Full Disk Access

01Apple to Tighten macOS Full Disk Access, Requiring “Very Explicit” User Action for AI Agents

Apple is tightening one of macOS’s most powerful permissions as AI agents gain broader access to personal data. Full Disk Access allows an app to reach files across a user’s system, including mail, messages and browsing history. Apple says the feature largely bypasses its usual privacy controls because it was originally intended to let backup software function properly.

The company now says some developers are using that permission in ways that may expose information without users fully understanding what they have authorized. As AI agents become more capable and autonomous, Apple said, the risks associated with such extensive access will “grow substantially.”

Apple plans to introduce new controls so an app can obtain Full Disk Access only through “very explicit user action.” The change targets the authorization step: users will have to take a clearer, more deliberate action before granting an app system-wide access. Apple has not described what that interaction will look like, when it will arrive or how it will affect apps that already have permission.

The announcement follows a dispute involving Muse, Meta’s desktop AI agent. Inc. columnist Jason Aten reported that Muse knew the contents of his private messages even though, he said, he had not explicitly authorized that access on his iPhone or Mac. Meta disputed that account.

Meta spokesperson Andy Stone said access to Messages is “entirely opt-in.” According to Stone, Muse can read message content only when a user enables both macOS Full Disk Access and the app’s Messages connector. The available sources do not establish whether Muse accessed Aten’s messages without authorization.

The episode nevertheless illustrated Apple’s wider concern: a user may activate a broad operating-system permission without appreciating everything an AI agent could subsequently reach. Unlike conventional software that uses access for a narrow task, an agent can act across files and applications, increasing the consequences of an unclear or insufficiently informed approval.

Apple has confirmed the system-level risk and its intention to require more explicit consent, but it did not answer media inquiries seeking further details about the change. The practical effect will remain unknown until Apple explains the new controls, their release date and their treatment of existing permissions.

Mac users should receive a clearer warning before exposing files, mail, messages and browsing history to an AI agentAI developers may face additional friction when requesting the broad permission their products usethe next test is whether Apple’s undisclosed authorization design meaningfully improves informed consent.

02Cloudflare Releases Open-Weight Clef Decision Models and Launches Reinforcement-Learning Fine-Tuning Platform

Cloudflare has released Clef and Clef-flash, two models designed to make bounded decisions inside automated workflows. Rather than generating open-ended text or choosing tools like a general-purpose large language model, a decision model answers predefined questions with typed results and probabilities, allowing software to route a request, escalate it or defer it to a person.

That division of labor could let an AI agent use Clef for fast, consistent classification while reserving a general model for reasoning and execution. In customer support, for example, Clef can assess whether a message is urgent, select the responsible team and score its severity. Cloudflare also introduced a reinforcement-learning product through which customers can fine-tune Clef for their own applications.

Developers can access both models through Cloudflare’s Workers AI service. Cloudflare says they are compatible with Typesafe AI’s Jev API, while their weights are available on Hugging Face under the Apache 2.0 license for local use and experimentation. The company says Clef currently leads its evaluation against the Jev Decision Index, although Cloudflare ran the cited performance and quality tests and the results have not been independently verified.

Clef adds a vision encoder that can classify images, whereas Cloudflare says Jev currently handles only text. It also supports a 64,000-token context window, compared with Jev’s 32,000 tokens. Cloudflare says its models beat other decision models on latency across 43 evaluation benchmarks, except for Laya, which was faster but traded off quality in the company’s tests. Hosting on Workers AI also lets the models use Cloudflare’s edge GPUs to reduce network latency.

The company demonstrated the intended use through its threat-intelligence team’s website-classification workflow. Given a domain and access to Browser Run, Clef fetched and rendered the site, then returned several probabilistic categories—such as fashion, ecommerce or phishing—in 2.2 seconds. Cloudflare’s gpt-oss-120b general model took 4.7 seconds in the same workflow and returned only two classifications. That roughly twofold latency difference applies to this internal test, not necessarily to other tasks or models.

Cloudflare has not disclosed the fine-tuning product’s price, availability or customer-data handling arrangements.

Developers can put cheaper, bounded classification decisions in the critical path of agent workflows while retaining general models for reasoning and actionteams can run the Apache-licensed models locally or use Cloudflare’s hosted servicecustomers still need details about fine-tuning access, cost and data treatment.

03Ataraxos Beats a Top Stratego Player 15-1 After Training on Just 16 GPUs

An AI system called Ataraxos defeated top Stratego player Pim Niemeijer 15 games to one, with four draws, overcoming a classic game that had resisted systems capable of mastering chess, Go, and poker. Researchers from Carnegie Mellon University, MIT, New York University, and Stanford University trained Ataraxos using just 16 GPUs and a few thousand dollars.

Stratego gives each player 40 pieces representing military ranks, as well as bombs and a flag. The objective is to capture the opponent’s flag. Each player can see where the opposing pieces are, but their identities remain hidden until pieces meet in battle. The weaker piece is then removed, while the winner’s identity is revealed.

That hidden information makes Stratego unusually difficult for AI. In Texas Hold’em poker, a player has two hidden cards, producing 1,326 possible hands. Stratego’s 40 pieces can begin in more than a decillion possible arrangements, leaving a system to reason about far more uncertainty.

The uncertainty also unfolds slowly. A chess game typically lasts about 40 moves, while a Stratego game can run for roughly 2,000. An AI must therefore track clues and revise its view of the opposing army across a much longer sequence of decisions.

Bluffing adds another complication. A player can move a weak piece as though it were a powerful marshal to frighten an opponent away. Bluff too frequently and threats lose credibility; never bluff and play becomes predictable. The researchers identified this balance, together with Stratego’s volume of hidden information and long games, as a reason earlier systems struggled. DeepMind’s DeepNash, introduced in 2022, did not reliably defeat the strongest human players.

Niemeijer was described by the source as arguably the best Stratego player of all time, but the reported result does not establish that Ataraxos has solved every version of the game. The available account also does not specify the system’s algorithm, match conditions, opponent-selection process, or whether the result has been independently reproduced.

Stratego researchers now have evidence that an AI can handle extensive hidden information, long-term inference, and bluffing against an elite human opponentthe use of 16 GPUs and a few thousand dollars suggests such experiments may not require a DeepMind-scale training budgetindependent reproduction and fuller match details remain the next tests.
04

Anthropic Commits $100 Million to Train 10,000 Enterprise AI Engineers Anthropic launched Claude Frontier Academy, aiming to train 10,000 “Frontier Deployed Engineers” by the end of 2027. Initial cohorts include engineers from Accenture, Deloitte, Morgan Stanley and other large organizations. anthropic.com

05

DeepSeek Releases an Open-Source Desktop Agent Harness DeepSeek Harness, now in preview for macOS and Windows, lets users install or create plugins for tasks including document organization, spreadsheet analysis, coding and scheduled work. Developers can inspect execution traces, run its web interface through Node.js or clone the source from GitHub. deepseek.com

06

OpenAI Publishes a Developer Guide to the GPT-6 Model Family OpenAI released guidance for startups on selecting GPT-6 models, configuring reasoning effort, improving prompts and skills, coordinating tools and preparing workflows for production. openai.com

07

Chatham Financial Cuts Trade Validation From 30 Minutes to Under Four Chatham Financial, a capital-markets advisory and technology firm, is using Codex and GPT-5.6 to build software and redesign workflows. OpenAI says the work reduced trade-validation time from 30 minutes to less than four. openai.com

08

Explicit Belief States Improve Long-Horizon Agent Performance in Tests Researchers introduced Progression of States, an inference-time framework that maintains an agent’s current-world beliefs, detects stalled progress and applies targeted recovery without additional training. The authors report the best overall performance across four benchmarks and all three tested LLM backbones. huggingface.co

09

OneStreamer Gives a 4B Video Model Persistent Memory and Proactive Responses Researchers introduced OneStreamer, which records timestamped captions and event summaries from live video so it can answer later questions without revisiting older visual features. Its authors report the strongest results among compared methods across eight streaming-video benchmarks and released the OneStreamer-1M dataset with more than one million records. huggingface.co