The Signal — October 3, 2026
Apple plans to require much more explicit permission before Mac apps can read nearly everything on a machine, warning that more capable AI agents make that access riskier. Two researchers launched a nonprofit to publish the post-training methods that frontier labs now keep private, and the Army set up a command to buy and field autonomous systems, with targets running to fiscal 2028.
Apple plans tighter Full Disk Access controls on the Mac, citing AI agents
Apple told developers on October 2 that it plans to add controls to Full Disk Access, the macOS permission that lets an app read nearly everything on a Mac. Apple says the permission "largely sidesteps" the system's privacy controls so that backup apps can work, and that some developers are using it in ways that expose files, mail, messages and browsing history without users fully understanding what they have granted. For messaging apps, Apple notes, that exposure extends to the people users are talking to. Going forward, users who want to grant this access will be able to do so only "with very explicit user action." Apple tied the change directly to agents, writing that "as AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially." It did not say when the new controls will ship or what they will look like.
Apple's post does not name any company, but The Verge connects it to a recent dispute over Meta's Muse agent. Inc columnist Jason Aten wrote that Muse somehow knew the contents of his messages although he had not given it permission to read them. Meta spokesperson Andy Stone responded that Muse can read Messages only if a user enables both Full Disk Access and Muse's Messages connector, and that the access can be revoked at any time. Neither account has been independently confirmed. On the iPhone and iPad, apps are walled off from each other's data by default. The Mac's Full Disk Access is the deliberate exception, and by Meta's own account it is the permission Muse needs to read a user's messages.
Sources: Apple Developer · TechCrunch · The Verge
Nathan Lambert and Tom Zick start Trillium Labs to publish open post-training recipes
Nathan Lambert and Tom Zick have founded Trillium Labs, a nonprofit that plans to do frontier AI research in public. Lambert previously worked at Ai2 and Hugging Face and runs a popular technical blog; Zick worked at Harvard and on responsible-AI policy at Charles Schwab. Trillium will begin with post-training, the stage after a model's initial training when it is tuned, often with reinforcement learning, into a usable assistant or agent. The founders' announcement argues that this is where much of the consequential work now happens and where labs publish least. They say outside researchers can see the results of training decisions but lack the compute to study how those decisions were made. Trillium says it will release complete recipes, including data, code, evaluations and intermediate checkpoints, and will document failed runs alongside successful ones.
WIRED reports that the lab will also study how reinforcement learning shapes a model's character, including tendencies such as sycophancy, and will research recursive self-improvement, in which AI systems help build their successors. Schmidt Sciences and Halcyon Futures provided initial funding in an undisclosed amount. The founders told WIRED they aim to raise $40 million to $100 million in total and plan to spend $30 million on training over the next 18 months. The lab has not yet released a model or a recipe, so the open releases are still commitments. Its announcement credits the fully open work already coming from Ai2, EleutherAI, Nvidia and Hugging Face, and it arrives while the most capable models from companies like OpenAI and Anthropic are available only through apps and APIs.
Sources: Trillium Labs · WIRED
The Army set up a command for autonomous systems, with fielding targets in 2028
Acting Army Secretary Adam Telle signed a memo this week establishing the U.S. Army Futures and Autonomous Systems Command, or FASCOM. The Army announced it on October 2, two days after Defense Secretary Pete Hegseth used his State of the Force address to announce a department-wide Autonomous Warfare Command and told the military services to build their own organizations, acquisition programs and career fields for autonomy. According to the memo as described by Breaking Defense and InsideDefense, the Army will build autonomous capabilities into at least six kinds of formations, including aviation, armor, fires, sustainment, engineer and training units. It will also name a single portfolio acquisition executive for autonomy and prioritize buying and fielding autonomous fires, combat vehicles, watercraft resupply, breaching, reconnaissance and targeting systems, along with teams of crewed and uncrewed platforms, by fiscal 2028.
The memo also adds positions for drone specialists and robotics technicians in units across the Army. Telle described the effort as being about "combat readiness to destroy the enemy and ensure our Army never enters a fair fight." The memo reorganizes how the Army buys, staffs and trains for autonomous systems; it does not deploy any. The public announcement does not say how much authority over targeting or the use of force these systems will have, or what human oversight will apply to them.
Sources: Breaking Defense · InsideDefense
On the Editor's Desk
We held Anthropic's study estimating how much work today's robots can already do. It came out September 30, so it was already a few days old, and we have run several Anthropic stories this week. We also left out a federal indictment accusing a California business owner of smuggling more than $300 million in GPU servers to China, since the charges are allegations at this stage and the story's connection to AI is narrower than today's three. A federal judge's ruling that one police search of Flock's license-plate database was unconstitutional applies to a single case and is mostly a surveillance-law story, so we did not include it here.