AI Pulse Daily Brief logo

AI Pulse Daily Brief

Archives
Log in
Subscribe
July 27, 2026

AI Pulse Daily Brief | 2026-07-27

Reading time ~4 mins

A Dutch financial-stability body links AI cyber risk to concentration in critical third parties and non-European infrastructure. The cabinet made reducing that dependence a national policy aim four days earlier. An investment bank has an AI assistant in production over live trading data, with the control design published and no business case attached. Two security researchers argue agent testing must cover the tools an agent is given, not just the model. On the radar: EU transparency obligations start applying on 2 August.

Regulatory

Dutch financial-stability body ties AI cyber risk to reliance on non-European technology suppliers. Authority

On 7 July the Financial Stability Committee, where Dutch supervisors and the finance ministry coordinate, published its latest risk assessment. It said advanced AI models can amplify cyber risk through supply-chain dependencies, concentration risk and reliance on critical third parties. It also named dependence on non-European technology and digital infrastructure as a financial-stability concern, and called for stronger coordination and information sharing across banking and other vital sectors. No measure, deadline or supervisory programme is attached; this is a risk assessment rather than rulemaking. The stake is that a Dutch financial-stability body now reads AI exposure and supplier concentration as one question, while banks typically keep their critical-supplier register and their AI system inventory as two separate records.

Autoriteit Financiële Markten

Perspectives

Two security researchers argue AI agent testing must cover the tools an agent is given, not just the model. Skeptic

Writing in IEEE Spectrum, Barath Raghavan and Bruce Schneier propose measuring the gap between what someone asks an AI agent to do and what they reasonably mean. Their argument is that unwanted behaviour is a property of the model plus its harness, meaning the tools it can call and how much freedom it has to act. They recommend testing agents in safe copies of real systems, varying that freedom, separating types of unwanted behaviour and weighting each failure by the harm it could cause. This is a proposed framework, not a validated benchmark, with no reported use in financial services. The stake for a bank is ownership: model validation covers the model, and this argument puts the agent's tool permissions and autonomy inside the same assurance question.

IEEE Spectrum (publication date unverified)

Netherlands & Sovereignty

The Dutch cabinet made reducing dependence on non-European AI infrastructure a national policy aim. Authority

The cabinet sent its International AI Strategy to parliament on 3 July, pairing support for European AI capacity with measures to reduce strategic dependencies across the AI value chain. It names reliance on non-European AI infrastructure as an economic and security risk. Other action lines cover market access for Dutch AI providers, international research and talent partnerships, and standards for safe and responsible AI. The announcement carries no funding envelope and no delivery timetable, so there is nothing yet to plan against. Four days later the Financial Stability Committee reached for the same dependency frame, and that is the language a Dutch bank will meet if it is asked to justify its cloud and model sourcing.

Rijksoverheid

Industry & competition

Jefferies runs an AI assistant over live trading data, and its cloud provider published the control design. Vendor

Amazon Web Services published a case study on 23 July describing a trade assistant the US investment bank Jefferies has put into production for its equities sales and trading desks. Staff ask it questions in plain language and it retrieves answers from the bank's trade repositories and live trading messages. The reusable part is the control design: access is authenticated, each user sees only the rows they are entitled to, personal data is filtered before the model, and every conversation is logged. The write-up is the vendor's own and reports no efficiency or cost figure at all. That split is the point for a bank running agent pilots: the controls are documented in enough detail to copy, and the business case is not there to borrow.

AWS Machine Learning Blog

On the radar

  • The EU AI Act's transparency obligations for AI-generated content and chatbots start applying on 2 August, with the European Commission's implementation guidance published on 20 July. European Commission

Don't miss what's next. Subscribe to AI Pulse Daily Brief:
← Newer AI Pulse Daily Brief | 2026-07-28 Older → AI Pulse Daily Brief | 2026-07-24
Powered by Buttondown, the easiest way to start and grow your newsletter.