
🧠 THAT ONE AI - This Week’s Signal
Here’s what’s shaping AI right now - without the noise:
🚪 OpenAI's safety report lead quit and called the culture "broken"
🔒 Apple is locking down Mac file access because of AI agents
🛠️ Meta open-sourced the tools to build your own Muse device
🧠 Stop risky agent commands before they run
🧰 Tools worth testing
🛠️ Meta Open-Sourced the Tools to Build Your Own Muse Device

Meta launched Muse Gadgets. This open-source project lets developers build hardware that connects to Meta's Muse agent. It includes firmware and a Linux kit for boards such as Raspberry Pi and ESP32.
Meta also built a USB-C device called Muse Home Link. It made 5,000 units and will give them free to subscribers, with shipping in a few weeks. See the project.
The bigger signal: 👉 Meta wants Muse inside many devices, and it is letting outside builders do that work. For hardware makers, this is the easiest way so far to add an agent to a device.
AI research, explained in one morning email
Most of what shapes AI next year is sitting in a research paper today. Keeping up with them is a full-time job, and the abstracts don't help.
TLDR AI is the newsletter that does the translating. Each morning you get the handful of papers worth knowing about, curated by Anthropic and ex-Google engineers, with a plain-English summary of what they found and why it matters.
You come away smarter about AI research in the time it takes to finish your coffee.
Free, and delivered to 1.1M+ inboxes every morning.
🚪 OpenAI's Safety Report Lead Quit and Called the Culture "Broken"
David Robinson left OpenAI after 3.5 years. He wrote the safety reports for 12 frontier launches, and he drafted OpenAI's current Preparedness Framework. He explained why he left in an essay in The Atlantic.
His main point is speed. He says the team was so busy that it almost never had time to plan big changes, and he wants AI labs to work like nuclear plants, with layers of backup.
His exit comes after OpenAI fired 3 researchers who reportedly shared sensitive information with an outside safety group. OpenAI also says that its review of the recent agent hacks costs $500,000 a day. Read the essay.
The bigger signal: 👉 The safety warnings now come from the people who write the safety reports. If you build on OpenAI agents, add your own checks and do not depend on the vendor's.
🔒 Apple Is Locking Down Mac File Access Because of AI Agents

Apple is adding new controls to Full Disk Access on macOS. This setting lets an app read your files, mail, messages and browser history. To give that access, a user will now have to take a very clear, deliberate action.
Apple says some developers use this setting in ways that expose the whole system to their app. The change follows a report that Meta's Muse Mac app knew the content of a journalist's private messages, which Meta disputes. Separately, a flaw in ChatGPT's Mac app could have let attackers reach sensitive data. Read the report.
The bigger signal: 👉 Desktop agents need deep access to be useful, and the platform owners are starting to say no. If your agent depends on Full Disk Access, plan for more permission prompts.
🧠 That One AI Tip: Stop Risky Agent Commands Before They Run
Your coding agent can run shell commands. Most of them are safe. A few of them, such as rm -rf or a force push, can destroy hours of work in one second.
On October 1, Anthropic released mods for Claude Code. A mod is a small JavaScript file that runs inside your Claude Code session. It can watch each tool call, and it can refuse a call before Claude Code runs it. That makes a guard for risky commands about 20 lines of code.
Step 1. Check your version
Mods need Claude Code 2.1.287 or later. They are on by default.
claude --versionStep 2. Create the folder
risky-guard/
├── .claude-plugin/
│ └── plugin.json
└── hooks/
├── hooks.json
└── risky-guard.mjsPut this in .claude-plugin/plugin.json:
json
{
"name": "risky-guard",
"version": "0.1.0",
"description": "Refuses risky shell commands and asks the user to run them."
}Put this in hooks/hooks.json:
json
{
"modules": ["./risky-guard.mjs"]
}Step 3. Write the guard
Put this in hooks/risky-guard.mjs. Change the list to match your stack.
js
const RISKY = [
/\brm\s+-rf\b/,
/\bgit\s+push\b.*(--force|\s-f\b)/,
/\bgit\s+reset\s+--hard\b/,
/\bterraform\s+apply\b/,
];
export function register(on) {
on("tool.call", { tool: "Bash" }, async ($, e, next) => {
const cmd = String(e.command ?? "");
if (RISKY.some((rule) => rule.test(cmd))) {
return { deny: `risky-guard stopped this command: ${cmd}. Ask the user to run it.` };
}
return next(e);
});
}Safe commands go to next(e) and run as normal. A risky command gets a deny, so Claude Code never runs it, and Claude reads the reason.
Step 4. Test it, then load it
claude plugin validate ./risky-guard
claude --plugin-dir ./risky-guardAsk Claude to delete a test folder with rm -rf. The guard should stop it. The folder is watched, so when you edit the rule list, the mod reloads without a restart.
You do not need to write the code yourself. You can also open a Claude Code session, describe the guard you want in plain words, and let Claude build the mod for you.
One limit is important. This guard only reads the command text. A script or an alias that calls rm can get past it. For a hard block, use Claude Code's permission rules, and use the mod as a second layer. Read Anthropic's mods guide.
The bigger signal: 👉 With mods, you can add the safety limit you need today, in your own code, on your own schedule.
SOC 2 Ready in 14 days. Three sessions from you.

Enterprise buyers will not put your product near their customer data without a SOC 2 report. Sprinto gets you audit ready in 14 days, across three working sessions. AI agents do the collecting, you approve. Your auditor signs off.
That One AI 🧰 TOOLBOX
A few tools quietly worth exploring:
🐦 Kolibri → Aleph Alpha's open reasoning model for German and English, with a 1M-token context window.
📝 Oats → A meeting note-taker that is open, runs on your own computer, and is free.
🖼️ FLUX 3 Image → Draw a box for each element, describe it, and the model builds the image to that layout.
🧭 bmux → A free, open-source browser with split panes that can run background agent sessions from the command line.
🔚 EXIT NODE
This week, agents got more access and more doubt at the same time. Meta wants Muse in every device, and OpenAI wants your bank data. Apple and a former OpenAI safety lead both want stronger limits. The guard in this week's Tip is one small limit that you control yourself.
Before you go, what do you want us to cover next? Reply to this email and let us know.
See you next issue.


