AI Pulse Daily Brief logo

AI Pulse Daily Brief

Archives
Log in
Subscribe
July 30, 2026

AI Pulse Daily Brief | 2026-07-30

Reading time ~8 mins

- The European Central Bank has asked every bank it supervises for an AI cyber action plan by October, and folded critical-supplier oversight into it.
- De Nederlandsche Bank has told Dutch financial firms to redo their patching, response and resilience assumptions for AI-speed threats.
- Santander published the control design behind its production AI agents; DBS made its corporate assistant agentic for 350,000 business users.
- IBM's responsible-AI lead argues use-case risk classification breaks for agents, and a practitioner offers six safety-engineering rules in its place.

Top signal

The ECB has asked every bank it supervises for an AI cyber action plan by October. Authority

A member of the European Central Bank's Supervisory Board said in an interview on 28 July that the most capable AI models are compressing the time banks have to respond to an attack. Detection, patching and incident response all get shorter. The ECB has written to the chief executives of every bank it supervises, asking for action plans by October. The letter ties that work to cyber resilience, to incident response, and to oversight of the outside suppliers a bank depends on to keep running.

The third item is what makes this more than a security deliverable. Supplier oversight sits with procurement and outsourcing, model risk sits elsewhere, and each function keeps its own register. A plan due in October has to reconcile those records into a single dependency picture. Otherwise the bank submits commitments its own supplier data cannot evidence.

European Central Bank

Regulatory

UK supervisors are moving from writing resilience rules to inspecting whether they work. Advisory

EY's 18-page mid-year review of UK financial services regulation reports that the country's conduct and prudential regulators will back AI for growth only where governance, testing, oversight and resilience are demonstrably strong. The review describes attention shifting from rule-setting to hands-on supervision of resilience outcomes, concentration in critical technology, and unified reporting of incidents and third-party dependencies. It also records an expectation that boards challenge how AI-enabled customer journeys are monitored, including outcomes delivered through third parties. Read as a leading indicator rather than a foreign-market update, this points at the same evidence set the October European Central Bank submission will need, which makes the UK expectations usable as a dry run.

EY (LinkedIn; original source not verified) (publication date unverified)

Perspectives

IBM's responsible-AI lead says classifying AI risk by use case breaks down for agents. Corporate

Francesca Rossi, IBM Fellow and the company's global leader for responsible AI, wrote on 28 July that AI risk is almost always classified by what a system is used for. The EU AI Act works that way and so do most corporate risk registers, and she argues the test fails for agents. What decides an agent's risk is its autonomy, the tools and data it can reach, how reversible its actions are, and how long it runs before a person checks. She calls for a second classification axis alongside use case, and for risk assessment to run during operation rather than only before deployment. Without it, the same approved use case configured with wider tool access is under-tiered while every register entry and sign-off still reads as correct.

Francesca Rossi (LinkedIn; original source not verified)

A Forbes column argues banks are measuring AI against the wrong number. Advisory

Michael Abbott's 23 July column says the question that dominates AI discussion in banking, how many jobs it will remove, is the wrong one. He points at three earlier automation waves that arrived with the same prediction: tabulating machines, mainframes, and online banking. US deposit-insurance data shows banking employment there nearly doubled from the 1960s, from around one million to just under two million. His argument is that the measure that matters is capacity. The framing decides which business cases get written, because a headcount case is signed off by cost owners while a capacity case has to name what the freed time is actually for.

Forbes

Gary Marcus says AI capacity deals are being financed by the suppliers selling into them. Skeptic

In a 27 July post, Gary Marcus argues that recent AI infrastructure commitments lean on interlocking vendor, customer and financing relationships rather than on demonstrated end-customer profit. He contrasts the cooler market reaction to a reported Nvidia financing backstop with earlier enthusiasm for an Oracle and OpenAI agreement, reading the shift as investors pricing the economics. This is one commentator's reading of public reporting rather than a deal-level financial analysis. The usable part is a distinction vendor reviews tend to collapse: a supplier's announced capacity and its independently profitable demand are separate facts. Only the second one supports a pricing and roadmap commitment the bank can plan against.

Gary Marcus

Industry & competition

Santander has published the control design behind its production AI agents. Corporate

Banco Santander has described the design it uses to keep production AI agents inside bounds. Six controls sit inside the agent's working loop: stopping conditions, a cap on retries, grounding on verified sources, independent evaluation, a human hand-off, and limits on which actions the agent may take. Santander says the surrounding monitoring is detailed enough to reconstruct after the fact why an agent did what it did. It also points to an open-source project it uses to test candidate guardrail rules against ordinary and adversarial inputs before keeping a change. A directly comparable European bank has now put its agent control assumptions in public, which turns an internal design debate into a written specification that can be read line by line.

Banco Santander

DBS turned its corporate assistant agentic for 350,000 business customers. Corporate

Singapore's DBS said its corporate virtual assistant now handles agentic requests for 350,000 business users, letting them ask in plain language for transaction and payment information once they have logged in and been authenticated. In the first half of 2026 the bank reports chats up 22%, active users up 61%, satisfaction up 17%, and calls or emails to customer service down 7%. Human support paths stay open, and DBS says selected fulfilment tasks such as card servicing come next. The design choice is the transferable part: authentication sits before the agent reaches any tool. The 7% fall in calls also sets a more realistic first-year expectation than vendor case studies usually imply.

DBS Group

Revolut trained a banking model on 40 billion of its own transaction events. Advisory

Revolut has built what it calls a transactional foundation model, an AI model trained on its own customers' activity rather than on general text, using 40 billion recorded events. Reported results are fraud detection improved by 64.7%, credit-risk prediction up 16%, and product recommendations 41% more effective. Michael Abbott, who circulated the research, draws the wider point: the tools will converge across banks, and the data behind them will not. His sharper observation is about disposal rather than construction, since most banks run fragmented models on fragmented data while routing their richest transaction signal through third-party providers. That routing is decided one vendor selection at a time, with nobody holding the aggregate picture.

Forbes

Research

McKinsey stages agentic customer service in three steps and gates the second on the first. Advisory

McKinsey's ten-page publication 'Rewiring customer experience for the agentic era' maps a move from predefined journeys to governed real-time decisions. It sets out three horizons, rewiring single workflows, then orchestrating a domain, then connecting an ecosystem, and asks for explicit rules, defined escalation paths and tight human oversight from day one. The value case rests on client examples, including a European telecoms provider reporting €40 million of margin from joining customer decisions across channels. That joining step is also what makes an agent's mistakes wider and harder to unwind. The sequencing is what a bank can borrow: decision rights, escalation thresholds and reversibility settled per workflow before cross-channel context is connected.

McKinsey & Company: Rewiring customer experience for the agentic era (LinkedIn; original source not verified) (publication date unverified)

Deloitte offers Dutch financial firms three tests for whether AI governance actually works. Advisory

Koen Dessens, a partner in Deloitte's financial risk practice, has framed the firm's report 'Banking on trust: AI governance for growth, resilience and scale' explicitly for Dutch banks, insurers and pension providers. The headline finding he draws out is that well-built governance does not have to slow innovation, and that it gives teams the confidence to move faster. He sets three tests: governance clear enough that teams know what they may use AI for, embedded enough to support decisions in real time, and credible enough to hold trust with employees, customers and regulators. Those three questions work as a scoring instrument, and they are framed in the bank's own market and its own supervisory set rather than borrowed from a different jurisdiction.

Deloitte: Banking on trust

Security

The Dutch central bank tells financial firms to redo their cyber assumptions for AI-speed threats. Authority

De Nederlandsche Bank published a supervisory item for the sector on 10 July, saying the most capable AI models increase both the scale and the speed of cyberattacks. It tells institutions to reassess their risk assumptions, technology priorities, investment and capacity as a result. The named control areas are how fast patches are applied, how incidents are handled, how resilience is tested, and how dependencies on critical technology suppliers are managed. It links that testing to the EU's Digital Operational Resilience Act and to threat-led penetration testing. This is the Dutch supervisor naming its evidence in advance, so patching and response timings have to be re-derived against AI-accelerated attack speed in this planning cycle rather than defended in the next examination.

De Nederlandsche Bank

A governance practitioner puts six safety-engineering rules behind agent design. Independent

James Kavanagh, who came to AI governance from chemical engineering, argues that safe agent design is being improvised when the principles already exist in safety engineering. He names three recurring failures: not separating the control from what it protects, not checking what crosses a boundary, and failing into a permissive state. His six rules follow: separate the control from what it constrains, verify everything crossing a boundary, and never rely on a single control for a safety-critical property. The remaining three: design each component for how it fails, make every action observable and attributable, and give every control a feedback signal. The value is that these read as review questions rather than principles, and two of them surface fail-open behaviour that a controls inventory records as present and working.

James Kavanagh (LinkedIn; original source not verified)

Don't miss what's next. Subscribe to AI Pulse Daily Brief:
← Newer AI Pulse Daily Brief | 2026-07-31 Older → AI Pulse Daily Brief | 2026-07-29
Powered by Buttondown, the easiest way to start and grow your newsletter.