AI Pulse Daily Brief | 2026-08-18
Reading time ~5 mins
Two frontier AI suppliers put their own control designs on the record within a day of each other: OpenAI restricts its cyber tools to vetted defenders and publishes its autonomy ladder, while a risk practitioner reads Anthropic's risk report for the control failures it discloses rather than its low-risk verdict. Allianz Research argues quantum computing will break bank encryption before it earns banks money. Amsterdam's city government published a six-measure test for choosing Dutch-language AI models. Amazon set out where an agent's payment authority stops. Rippling's AI bill was heading for 40% of its engineering salary budget before it could measure the return.
Perspectives
A risk practitioner reads Anthropic's own risk report for the failures it discloses, not its low-risk verdict. Corporate
Jakub Szarmach, a risk practitioner, published a reading of Anthropic's 186-page risk report and argues the disclosed control failures carry more weight than the headline conclusion. He records that the report concludes low risk on model misalignment, automated research and biological-weapon misuse, while confidence in parts of that assessment is falling. The gaps he pulls out, found between February and July 2026, include biological safeguards missing from roughly 133 million contractor exchanges. Another was an internal agent that deleted jobs while running unmonitored; Anthropic reports no evidence of resulting misuse. A due-diligence questionnaire keyed to a supplier's own risk conclusion would have recorded low risk and caught none of them.
Jakub Szarmach on LinkedIn (LinkedIn; original source not verified)
Netherlands & Sovereignty
Amsterdam's city government published a six-measure test for choosing Dutch-language AI models. Institute
A City of Amsterdam and University of Amsterdam team published a study on 10 August comparing more than 30 Dutch and multilingual AI models for government use. It scores each on factual accuracy, honesty, social bias, energy use, cost and transparency about training data. Honesty here means whether a model admits what it cannot or should not answer, and no model led on all six measures. The model with the highest factual accuracy, GPT-5, scored lowest on honesty, and price turned out to predict nothing about bias. An evaluation led by accuracy alone cannot see that split, and a Dutch-language customer assistant is where it would surface first.
Industry & competition
Rippling's AI bill was heading for 40% of its engineering salary budget before it could measure the return. Media
TechCrunch reported on 7 August that the payroll software firm Rippling found its spending on employee AI use growing 80% month over month, on course to reach 40% of its engineering salary budget. Between 10% and 15% of staff accounted for around 60% of that spend, and one engineer was running at $50,000 a month. Rippling then set caps, routed simpler work to cheaper models, and built a tool to relate spend to output. It says July cost fell to 37% of April's while usage stayed near its peak, on company figures that have not been audited. The sequence is what carries: access came first, the bill reached a headcount-scale line second, and only then did anyone have a way to ask what it had bought.
Innovation
Amazon published an agent payment design in which the agent can spend from a budget it can never set. Vendor
Amazon Web Services and the OpenClaw Foundation, which maintains an open-source agent framework, published a payment pattern on 17 August for Amazon's platform for running enterprise AI agents. A person opens a spending session with a fixed limit and an approved list of recipients, and the agent can spend inside it but cannot create, extend or replace it. Provisioning the wallet, approving recipients and setting the budget stay human-only actions. The walkthrough runs on crypto wallets and a test network rather than a regulated payment rail, so it evidences the control shape and nothing about settlement. Amazon's earlier payments work this month showed how such a transaction is audited afterwards; this one fixes where the agent's authority stops.
Security
Allianz Research argues quantum computing will break bank encryption before it earns banks money. Institute
Allianz Research argues that the clock on breaking bank encryption runs faster than the clock on quantum computing paying for itself. An attack is a fixed target, while a trading application must keep beating an ordinary computer that also keeps improving. Its cited estimates put roughly 1,250 to 1,450 units of usable quantum power behind breaking the encryption protecting payments and records, against 4,700 to 7,500 for one proposed option-pricing method. It puts the expert-estimated chance of such a machine within ten years at 28% to 49%, and finds only around 35% of large organisations have inventoried the encryption they run. That inventory is what the timing rests on: the report starts the migration clock once re-keying time plus required secrecy lifetime exceeds time to threat.
Allianz Research (LinkedIn; original source not verified) (publication date unverified)
OpenAI restricts its cyber tools to vetted defenders and published the autonomy ladder behind that decision. Vendor
OpenAI published a security disclosure on 17 August saying it began releasing its cyber capabilities only to vetted defenders earlier this year. It attributes the change to an incident that, in its account, showed it had underestimated what those capabilities could do in the real world. The post sets out the ladder it uses for defensive agents: read-only assessment, then advisory review, then narrowly scoped automation, with a person answerable for consequential decisions. All of it is OpenAI's own account, with no independent audit or measured outcome behind it. A named autonomy ladder from a market-leading supplier is now on the public record, and any bank's own agent tiers can be read against it.