July 2026 — agent permissions and toolchain disclosures
July review of the AI Data Use Index baseline products plus new toolchain disclosures. Cursor published agent permissions documentation (permissions.json, MCP allowlists) that production teams must map to PSF-7; GitHub Copilot enterprise policy pages unchanged on training use. No material reversals on consumer training opt-outs across the 15-product baseline.
Reviewed this edition
15 products in the baseline.
Material changes
Cursor
Agent permissions documentation surfaced
Cursor's public agent permissions docs now describe permissions.json, autoRun, and MCP/terminal allowlists. PAI published a schema reference record on 2026-07-02; this edition records the vendor page as the primary source for the policy watch.
Public record
This record is maintained by PAI and free to cite. If something is wrong or missing, tell us. Corrections and source suggestions keep the record honest.