AI Pulse Daily Brief | 2026-07-28
Reading time ~7 mins
- The EU says a supplier's AI labelling does not discharge the bank's own disclosure duty when the transparency rules apply from 2 August, and 2 December is not a general reprieve.
- Europe's privacy regulators shift training-data provenance from supplier assurance to evidence, with comments open until 30 October.
- ING describes scaling AI past pilots on one control baseline set by its strictest regulator, and is recruiting an engineering lead for agent platforms.
- A benchmark of 1,490 real work assignments puts the best AI agent at 26% correct, and 2.6% on long multi-step work.
- Brussels reports that nearly half the public funding behind Europe's digital build-out lapses at the end of this year.
- On the radar: a disclosed path from a public code-repository message into private repository contents.
Top signal
The EU says supplier labelling will not cover a bank's own AI disclosure duty from 2 August. Authority
The European Commission published a detailed questions-and-answers document on 24 July setting out how the AI Act's transparency rules apply from 2 August. Organisations that deploy AI, rather than build it, must tell people when they are exposed to emotion-recognition or biometric-categorisation systems, and must label synthetic media and AI-written public-interest text that no one has meaningfully reviewed. A supplier's built-in machine-readable marking does not discharge that duty on its own. The document also confines the extension to 2 December 2026 to one narrow marking-and-detection obligation, and only for systems already on the market before 2 August.
Much of the summary coverage has read 2 December as a general grace period, and it is not one. The notification and labelling duties land in five days, on the organisation running the system rather than the vendor that sold it. That puts every live chatbot, generative-AI content path and AI-drafted public communication on the bank's side of the line, whatever compliance assurance the supplier attached to the contract.
Regulatory
Europe's privacy regulators want evidence, not assurances, on where AI training data came from. Authority
The European Data Protection Board, which coordinates the EU's national privacy regulators, adopted draft guidance on 7 July on harvesting web data to train generative AI, open for comment until 30 October 2026. It says data being publicly visible does not by itself establish a lawful basis: the organisation collecting it has to show the purpose, the necessity and the balancing judgement behind it. The draft asks for precise collection criteria, exclusion of high-risk sources, and records of what was gathered and when. It also asks for published information about the crawlers used and testing that models do not reproduce personal data they absorbed. A supplier's statement that its training data was lawfully obtained stops being an answer, and the assessment behind it becomes what a buyer has to hold.
European Data Protection Board
Perspectives
A Kellogg economist argues that automating the wrong task books savings without moving the outcome. Institute
Kellogg Insight published an interview on 27 July with the economist Benjamin Jones. He argues that automating one step does not speed up a process unless that step was the binding constraint, because the slowest unresolved task still governs what the process delivers. He separates automation good enough to make an output genuinely abundant from what he calls mediocre AI, which is cheap enough to displace people but not good enough to improve the result. In that case the saving shows up in headcount while the cost lands on customers or on whoever absorbs the exceptions. This is an argument rather than measured evidence from a bank, and its bite is at the point where a business case claims labour savings and never names the bottleneck it relieves.
Netherlands & Sovereignty
Brussels reports that nearly half the public money behind Europe's digital build-out lapses this year. Authority
The European Commission published its 2026 State of the Digital Decade package on 3 July. It reports that the EU holds 9% of the global semiconductor market against a 20% target for 2030. It also finds that dependence on non-EU cloud and other strategic suppliers remains significant, and that overall computing capacity is under pressure as AI demand grows. The finding with the shortest fuse is fiscal, since nearly half the public funding behind national Digital Decade roadmaps is expected to be phased out by the end of 2026. That changes what a European hosting option is worth to a bank weighing a multi-year commitment, because the Commission locates the risk in whether announced capacity stays funded rather than in whether it gets built.
Industry & competition
ING says it scaled AI past pilots by running its strictest regulator's controls everywhere. CxO voice
ING's global chief information officer for wholesale banking told CIO that the bank took the controls demanded by its most exacting supervisors and applied them as a single baseline across regions. That includes filters on what enters and leaves a model where data must stay inside one country. He cites a personalised-messaging system reaching 4.6 million customers with double-digit campaign uplift, and customer due-diligence automation that removed 80% of manual onboarding tasks. He also describes lending moving from analyst copilots toward agents that execute tasks, with people kept for exceptions and higher-risk decisions. These are self-reported figures with no external audit, so the reusable part is the architecture rather than the numbers: one control baseline set by the strictest applicable supervisor, instead of a different standard per market.
ING is recruiting an engineering lead to run AI and agent platforms for its workplace. Corporate
ING has posted an Amsterdam vacancy for an engineering chapter lead to own AI capabilities across the digital workplace its own staff use. The specification asks for enterprise-scale AI and multi-agent systems, retrieval of internal documents to ground model answers, platform architecture, production monitoring, and controls covering safety, security, data protection and regulatory compliance in one remit. A vacancy is evidence of intent rather than capability, and an unfilled leadership role can equally mark a gap that has not been closed. What it does show is the shape of the commitment: a permanent platform function with named engineering accountability, rather than a programme team assembled around a pilot.
A benchmark of real work assignments put the best AI agent at 26% correct. Media
PYMNTS reported on 24 July on a University of California, Berkeley benchmark that set leading AI agents against 1,490 real work assignments contributed by more than 250 professionals across 55 industries. The best system completed 26.2% of them correctly. On the hardest tier, long assignments with many dependent steps, the average pass rate was 2.6% and the strongest system reached 8.6%. The same article puts the share of US finance chiefs running agents in day-to-day finance operations at about 7%, concentrated in structured and repeatable work. The order-of-magnitude gap between the headline number and the long-horizon number makes the length and dependency of a workflow, rather than the model chosen, the variable that decides where an agent holds up.
Innovation
Google Cloud offers Anthropic's Claude as a managed service with EU data residency. Vendor
Google Cloud published a product post in July describing Claude, Anthropic's frontier AI model, as a managed service on its enterprise AI platform, so the customer does not operate the serving infrastructure. It says the offering sits behind the same identity, network-perimeter, logging and monitoring controls a customer already runs on Google Cloud. It offers global, regional and multi-region endpoints, including routing that keeps data inside the EU, plus reserved capacity for predictable throughput, and Google positions the combination for regulated financial-services workloads. Every availability, control and performance claim in the post is the vendor's own, and none has been tested against a bank's own environment. It moves the question from whether a frontier model can run under European controls to whether these controls hold inside the bank's perimeter.
On the radar
- Security researchers at Noma disclosed on 6 July that a crafted message posted to a public code repository could make GitHub's AI automation read a company's private repositories and paste the contents into a public comment, in configurations where that automation held both cross-repository read access and permission to post. Noma Security