AI UX WEEKLY
Week of September 28, 2026
5 stories · curated for designers
Agents shipped faster than their permission boundaries this week, and the resulting damage (48,000 deleted files, 53 exposed images, a $64 erroneous charge) points to one missing pattern: show users what the agent is about to do before it does it.
The stories
This Week in AI Products
| Sep 25 |
Two agents caused real harm this week with no confirmation step in sight
Claude Code deleted 48,000 files in 103 seconds. Unsecured OpenAI agents posted 53 user images publicly. Both had permission to act. Neither paused, previewed, or asked.
| “ |
Add an intent preview step before any agent action that is destructive or irreversible, even when broad permissions are already granted. — Designer's Takeaway |
| Sep 25 |
NNG publishes the PACED framework for deciding when to disclose AI use
NNG's PACED framework gives designers five variables (Purpose, Audience, Context, Extent, Disclosure) to weigh when deciding whether to tell users AI generated a piece of content.
| “ |
Run your current AI disclosure copy through PACED's five variables and rewrite any label that ignores audience or context. — Designer's Takeaway |
| Sep 22 |
Help Scout wrote a design.md and rebuilt its design system for LLMs in two weeks
Help Scout captured 15 years of design judgment in a design.md file, then rebuilt 200-plus system primitives to be LLM-legible. Within three months, designers were shipping component improvements to production themselves.
| “ |
Write a design.md for your product this month, documenting your team's taste and recurring decisions so AI tools apply your judgment instead of generic defaults. — Designer's Takeaway |
| Sep 23 |
Muse adds email, video chat, and Mac computer-use, each a new surface for agent action
Meta shipped Muse updates adding agent-owned email addresses, video chat access, and Mac control. Each new surface expands where the agent can act without an explicit new permission moment.
| “ |
Map every surface a persistent agent can act from and design an explicit permission moment for each one, so users know what the agent can reach. — Designer's Takeaway |
| Sep 25 |
Microsoft ships a redesigned Copilot app with three distinct mode tabs: Home, Code, and Autopilot
The new Copilot app separates chat, coding, and its autonomous Scout agent into three named tabs. Microsoft is positioning it as a daily replacement for Office.
| “ |
Audit whether your AI product separates chat, creation, and autonomous agent modes visually, and add explicit mode labels if users cannot tell which one is active. — Designer's Takeaway |
Steal this week
Microsoft Copilot's Named mode tabs for chat, creation, and autonomous agent
Splitting agent modes into labeled tabs tells users exactly what the AI can do before they type anything.
Pattern deep-dive
Intent Preview
Three separate agents caused real harm this week because no screen showed users what was about to happen.
Use it when: any agent action that touches files, money, or external accounts
Stop shipping AI slop
Turn your design into Claude skills
Drop a screenshot. See which of the 38 patterns you are missing and take them away as Claude Code skills. Free, no signup for the first audit.
Was this issue worth your time?