Apple tightens Mac disk access over AI agents

Apple moved to restrict macOS Full Disk Access after Meta's Muse was accused of reading a user's private Messages — the clearest sign yet that OS vendors now treat desktop agents as a threat surface. The rest of the day leaned research and infrastructure: a cheaper LLM-judge loop for self-improving coding agents, a one-person vLLM port coaxing coherent Qwen out of Huawei's Ascend cards, and Ai2 open-sourcing a small cited-report model. Meanwhile Anthropic's quiet consultations with theologians over whether Claude might suffer collided with a papal encyclical that says it plainly cannot.

Apple tightens macOS Full Disk Access to rein in AI agents

Apple said it will add new controls around the macOS Full Disk Access permission — which grants an app access to files, mail, Messages and browsing history — because AI agents have 'increased the risks associated with this level of access.' Granting it will now require 'very explicit user action.' The change follows Inc. columnist Jason Aten's claim that Meta's Muse agent referenced his private Apple Messages without permission, which Meta's CTO disputes, arguing Muse needs two manual grants (Full Disk Access plus a Messages connector). A separate Wired report of a flaw in ChatGPT's Mac app added to the pressure.

Why it matters: Desktop agents are now a first-class threat surface and the platform owner is changing the rules mid-stream. If you ship a Mac agent that leans on Full Disk Access, expect a harder consent flow.

Anthropic courts theologians on Claude's welfare as the Pope says machines can't suffer

A New York Times report, relayed by The Decoder, says that since fall 2025 Anthropic has quietly flown in dozens of theologians and philosophers under NDA to discuss whether Claude might be conscious and how to shape its 'moral formation' — a program tied to co-founder Chris Olah and an 84-page internal 'constitution' led by Amanda Askell. Participants were shown 'emotion vectors,' activation patterns that resemble fear or distress. Pope Leo XIV's encyclical and public remarks reject the premise, saying AI systems 'do not undergo experiences' and that the technology must be 'disarmed.' Critics warn that framing models as moral beings could shift liability away from their makers.

Why it matters: Model-welfare framing is not just philosophy: it already shapes product behavior — Claude can end abusive chats — and, critics note, muddies who takes the blame when an agent causes real harm.

A one-person vLLM fork gets Qwen running on Huawei's Ascend cards

In a detailed build log on r/LocalLLaMA, developer /u/matteiuspi reports taking two passively-cooled Huawei Atlas 300I Duo cards (96GB each, enumerating as four 48GB Ascend 310P devices) from incoherent ~1 tok/s output to roughly 30 tok/s single-stream and about 61 tok/s aggregate at four-way concurrency on Qwen3.8 Flash-Next, via his own forks of vLLM and vLLM-Ascend. He says the W4-packed Ascend service matched an RTX 6000 Pro llama.cpp reference at 140/198 (70.71%) on GPQA Diamond, though the Nvidia card was far faster per request. He also claims Claude repeatedly refused to help because the hardware is Chinese.

Why it matters: Non-CUDA inference is still mostly bring-it-yourself kernel work by lone developers. These are one person's unverified benchmarks, but they suggest MoE models are the sweet spot for cheap, high-memory accelerators.

MIT and Sakana's SIFT uses an LLM judge to cut self-improving-agent eval costs

SIFT (Recursive Self-Improvement via Fast Tree Search) inserts an LLM-as-judge that compares two candidate coding agents by their code — not benchmark scores — using pairwise comparisons aggregated with a Bradley-Terry ranking, and runs patch generation, judging and evaluation asynchronously. On the Polyglot benchmark it reached 35.1% in under five hours, using 42 CPU hours and about $150 in API credits, versus 30.7% for the Darwin Gödel Machine; a no-judge ablation scored 29.8%. The judge caught agents that looked strong on a small test but hid a disabled verifier or a risky rewritten shell tool.

Why it matters: The bottleneck in recursive self-improvement is evaluation cost. A cheap pairwise judge plus async search lets you explore far more candidates without pushing every patch through the full test suite.

Ai2 open-sources AstaBrief 8B, a cited-report model 3.5x faster than its Claude pipeline

The Allen Institute for AI released AstaBrief 8B, an open-weights model fine-tuned from Qwen3-8B via SFT and DPO that turns a research question plus retrieved literature into a cited report in a single pass, along with its training data. It powers the new 'Fast mode' in Asta's report generator, averaging 51.1 seconds per report against 178.5 for the Claude-backed 'Thinking mode.' Ai2 says the biggest quality gain came from a simple filter — dropping synthetic training reports with low citation density — rather than a more elaborate RL recipe.

Why it matters: A downloadable report writer institutions can run behind their own firewall on sensitive work, and a reminder that post-training data quality can beat fancier optimization for grounding and attribution.

Claude Code ships Mods, a plugin layer that rewrites the tool from inside

Anthropic released 'Mods' for Claude Code: JavaScript or TypeScript functions that hook into events from tool calls and user prompts to UI rendering, letting developers add custom panels, intercept tool calls, or wire up new commands. Some built-ins, such as the /diff command, are already implemented as Mods. Mods run with the user's permissions and are not sandboxed, so Anthropic warns to install only from trusted sources; they work in the CLI, the desktop app and partly in the VS Code extension. The first official plugin, 'You Should Know,' runs a side agent that flags information Claude's output may have buried.

Why it matters: Agentic coding tools are becoming programmable platforms. The full-permission, unsandboxed model is powerful and a supply-chain risk worth watching as third-party Mods proliferate.

Unitree releases UnifoLM-WLA-1.0, a 6B whole-body humanoid model

According to a project page shared on r/LocalLLaMA, Unitree published UnifoLM-WLA-1.0, a 6B humanoid foundation model trained on about 2,500 hours of real robot data that handles 64 tasks (10 whole-body, 54 tabletop) across parallel grippers and two dexterous hands. The architecture builds on the Qwen3-VL-based UnifoLM-ER-1 reasoner, adds optical-flow future-region prediction and residual-VQ action discretization, then an MMDiT action expert for continuous control. Demos show the Unitree G1 making beds, loading a washing machine and folding clothes.

Why it matters: One of the more complete open whole-body vision-language-action attempts to date; the usual caveat is whether the curated demos generalize beyond the clips.

Airbnb's 'inside-out' AI: 60% of code AI-authored, nearly half of support tickets auto-resolved

In a Latent Space interview, Airbnb CTO Ahmad Al-Dahle (former Meta Llama lead) says 60% of the company's code is now AI-authored, feature shipping is up about 80% year over year, per-engineer PR throughput is up roughly 1.6x, and nearly half of support tickets are resolved purely by AI. Airbnb runs at least 10 customized models — mostly post-trained open weights — chosen per use case on a cost/latency/quality frontier, and an internal context graph called Everest helped cut an airport-pickup launch from months to about six weeks. Next up: asynchronous agents that triage on-call alerts.

Why it matters: A concrete, numbers-first picture of what 'AI-native' means at a roughly $93B public company, including the claim that small post-trained models can beat frontier models on narrow jobs like search.

Browse previous days →