The Agent Stack mascot
The Agent Stack _
Daily B2B AI automation brief Β· Sunday, October 4, 2026 Β· Issue #114

Hey there πŸ‘‹

I opened three tabs this morning and only one of them was the story. The other two were recaps of recaps. The GitHub changelog was short, dated, and specific: Copilot can drive desktop apps now, with an approval gate before it takes the wheel. That is the kind of primary I keep.

My bias, plain: once an agent can click the same buttons you click, the interesting fight is not the demo. It is who says yes, how loud that yes has to be, and what the OS does when the agent asks for the whole disk. This week GitHub handed the mouse to a coding agent most teams already pay for, and Apple started rewriting the permission that lets agents see almost everything.

- Ron


The Big Thing

GitHub Copilot can drive desktop apps

GitHub put computer use into public preview on October 1 for Copilot CLI and the GitHub Copilot app on macOS and Windows. Copilot can read accessible app content and visual context, then click controls, type and edit text, press keys, scroll, drag, and carry a workflow from one app into another. The point of the launch is software with no API, no command line, and no MCP server: the legacy GUI tools that used to sit outside every agent stack.

You stay in the loop. Copilot asks before it controls an app, and you can review or reset the apps you always allow. On macOS it walks you through Accessibility and Screen Recording. Organizations can kill the feature from managed settings. Turn it on with /computer on in the CLI, or under Settings, Computer Use in the app. /computer show and /computer off do what they say.

Why this lands for builders: OpenAI and Anthropic already shipped computer use earlier in the year. What changed is distribution. Copilot is the coding agent a huge share of engineering orgs already license. The same surface that writes your PR can now open Safari, fill a form, or poke a GUI-only admin panel. Early notes from the field talk about iPhone Simulator loops and Blender sessions running without stealing the focused window. Treat those as anecdotes until you reproduce them.

The product is not "full autonomy." The product is an approval model bolted onto a mouse. If you turn this on with no review culture, you did not ship an agent. You shipped a junior with your login and no ticket queue.

Ship it? DEPLOY the preview on one throwaway workflow this week: a status page check, a form fill, a test you already trust by hand. Leave production GUIs alone until your team has a rule for which apps may be always-allowed. Org admins should decide the managed-settings default before curiosity does.

Sources: GitHub Changelog, The New Stack.


Tour de Headlines

🍎 Apple names AI agents as the reason Full Disk Access gets louder

Apple told developers on October 2 it will add controls around Full Disk Access so anyone who really wants that level of reach must take a very explicit action. Full Disk Access was built so backup tools could work. It also lets an app see files, mail, messages, and browsing history. Apple's own line is the one that matters: as AI agents get more capable and autonomous, the risks of that permission grow substantially. No ship date yet. Verdict: WATCH every agent installer on your Macs, and assume the quiet FDA grant path is going away.

⏳ October 9: free Gemini drops to Flash-Lite only

Google is cutting model choice in the Gemini app. From October 9, personal accounts with no Google AI plan keep Flash-Lite and lose Flash and Pro. AI Plus ($4.99) keeps Flash-Lite and Flash but loses Pro; those users get an email with their personal switch date. AI Pro and Ultra keep the full set. If your free stack still assumes Pro or Flash is there for agent work, you have five days. Verdict: ACT if free Pro is load-bearing.

πŸ—“οΈ October 14: GPT-5.5 leaves ChatGPT Work and Codex

OpenAI's docs are blunt. On October 14, 2026, GPT-5.5 retires from ChatGPT, ChatGPT Work, and Codex on all plans. The OpenAI API is not in that cut. If you use Codex with ChatGPT sign-in, move workspace defaults, saved settings, managed configs, custom agents, scheduled tasks, and scripts off gpt-5.5. Paid plans are pointed at GPT-6 Sol (gpt-6-sol) when available; Free and Go at GPT-6 Luna in the desktop app. Verdict: ACT before the 14th if anything still pins 5.5 on a ChatGPT-signed surface.


Sponsor

Your calls leave a signal. Read it.

RapportScore measures how your team communicates on real calls and coaches them on it. It scores what happened on the call, using human signals plus AI, so your people get better at the conversation itself, meeting after meeting.

See your team’s score β†’

Tool of the Day

πŸ”§ Claude Code 2.1.288 and 2.1.289

The day after mods, the deny rules got teeth.

We covered Anthropic's mods launch yesterday. The follow-up is the patch train. Version 2.1.288 (October 2) closed a path where a dangerous rm inside bash -c or sh -c could run without a prompt under bypassPermissions or a shell allow rule. Version 2.1.289 (October 3) makes deny or ask rules on nested parts of compound shell commands hold even when a user-installed mod tried to approve them on managed machines. If you installed third-party mods this week, update before you treat the sandbox story as settled. The screwdriver shipped first. The lock work is arriving in point releases.

Read the changelog β†’


Worth a Click


Two moves landed in the same news cycle. GitHub gave a mainstream coding agent hands on the desktop. Apple started rewriting the permission that lets apps (and the agents inside them) see almost everything on a Mac. One side expands reach. The other raises the cost of a quiet yes.

My bet, with a stake on it: the teams that win the next stretch will not be the ones with the flashiest computer-use demo. They will be the ones who design permission the way they design deploy gates. Always-allow lists, managed defaults, and a human in the loop for anything that can spend money or wipe a disk. The mouse was the easy part. The yes is the product.

- Ron