AI Pulse Daily Brief logo

AI Pulse Daily Brief

Archives
Log in
Subscribe
September 11, 2026

AI Pulse Daily Brief | 2026-09-11

Reading time ~9 mins

The Dutch privacy regulator opened a practice round for the AI Act's fundamental-rights assessment, and registration closes on 21 September. OpenAI shipped three enterprise products in one day, one of them built for finance. A study models what the compromise of a single shared AI supplier could cost the banking sector. Lloyds is described as running eighteen generative AI systems in production. Ed Zitron and Gary Marcus both argue that the evidence a buyer needs is the evidence nobody publishes.

Top signal

The Dutch privacy regulator opened a practice round for a 2027 AI duty, and it closes on 21 September. Authority

On 17 August the Autoriteit Persoonsgegevens, the Dutch data protection authority, opened registration for a pilot on Fundamental Rights Impact Assessments. From December 2027 organisations deploying certain high-risk AI systems must run one of these assessments, which maps how a system affects people's rights and what is being done to limit the harm. The pilot helps participants build the mapping, mitigation and reporting practice before the obligation applies. Registration closes on 21 September 2026, ten days from today. The notice describes the pilot's legal audience in relation to public organisations.

This is where the Dutch template for that evidence is being written, more than a year before the duty binds. The supervisor running the first structured practice round is the one that will later read the submissions. An organisation that arrives in December 2027 without having seen it inherits an assessment workflow shaped entirely by others, and the registration window is the only part of that sequence still open.

Autoriteit Persoonsgegevens

Perspectives

A critic argues the AI vendors' enterprise revenue rests on a very small number of customers. Skeptic

Ed Zitron, a technology writer known for sceptical coverage of the AI industry, published an essay on 8 September arguing that the sector's demand base is narrower than it looks. He cites spend data from the corporate card company Ramp to claim that roughly 80% of OpenAI and Anthropic enterprise revenue comes from about 1% of customers. Many of those buyers are AI startups whose own spending is funded by venture capital. He sets that against compute commitments he puts at around 1.3 trillion dollars, while noting that private disclosures make the exact figures hard to pin down. The concentration test a bank already runs on a single-name loan book has an obvious second use here, and it has never been pointed at a supplier.

Where's Your Ed At

A prominent AI critic argues buyers cannot judge model risk without seeing the evaluation evidence. Skeptic

Gary Marcus, a cognitive scientist and long-standing critic of the field, wrote on 10 September about a US senator's request for detail on the role of AI agents in hacking incidents. He also covered litigation seeking disclosure of how models are evaluated. His argument is that without knowing what a vendor knew, when it knew it, and how it tested the system, no outside party can assess the risk independently. He adds that a more capable model may be harder to monitor rather than easier. A bank's model-risk process assumes a fixed artefact reviewed once, and a supplier-side agent update can quietly invalidate the evidence the original approval rested on.

Gary Marcus

AI agents require accountable performance and lifecycle management Perspective

Perspective. The captured McKinsey discussion is useful to bank leaders because it treats AI adoption as a workforce and operating-model change, not simply a technology rollout. Its central claim is that responsibility for agent performance should remain with the business owners whose workflows use those agents, supported by shared organizational guardrails, standards, and lifecycle management. The source argues that human quality control and critical thinking become more valuable, not less, as agents take on work.

The discussion connects that position to practical organizational choices. Leaders are encouraged to understand their own AI use, preserve the value of domain expertise, redesign rituals and workflows around capabilities and jobs to be done, and examine what agents exist, who is accountable for them, what value they create, what information they can access, and when they should be fine-tuned or retired. Finance and technology teams are described as needing better forecasting and modeling of usage, payment, and compute costs, while people teams need to address the changing capability requirements and cognitive load of employees working intensively with AI.

My takeaway is that a bank should manage agents as accountable operational participants rather than as an untracked layer of software. That means assigning business ownership alongside technical support, keeping an inventory, defining performance and retirement criteria, and testing whether access, guardrails, and quality-control responsibilities remain clear as workflows change. Management should measure jobs completed and capabilities enabled rather than tool adoption alone, and should monitor both agent outcomes and the human experience around them. The source’s observations about anxiety and exhaustion are not bank-specific evidence, but they justify watching cognitive load and employee feedback as adoption expands. This is a durable preparation lens: it changes governance, workforce planning, cost forecasting, and ongoing monitoring before an agent becomes forgotten infrastructure. It also gives executives a practical review question for each proposed deployment: which business owner accepts responsibility, what evidence shows the agent is still fit for purpose, and what event triggers intervention or retirement? That discipline keeps the human accountability described by the source connected to day-to-day controls rather than leaving it as a general aspiration. Source: McKinsey & Company.

McKinsey & Company (Shared by Tony Moroney)

Netherlands & Sovereignty

Europe's flagship AI compute plan lets global cloud providers anchor the sites it is building. Institute

Open Future, a Brussels policy think tank, published an analysis on 9 September of the tender for the EU's AI Gigafactories, the publicly backed computing sites meant to give Europe its own AI capacity. The EU's purchase commitment is capped at 17% of each site's infrastructure cost and must be matched by member states, against 1 billion euros for initial deployment. Bidders must keep core operations inside the EU and plan for a European software stack by year four, but the tender also allows global cloud providers to act as anchor customers. At that funding level someone else has to make each site commercially viable, and if that someone is a US cloud giant, the result is European location without European control of the service layer.

Open Future

Industry & competition

A British bank is described as running eighteen generative AI systems in production. Vendor

A Google Cloud customer page reports that Lloyds Banking Group has more than 300 data scientists and AI developers working on a shared machine-learning platform. It says 15 modelling systems containing hundreds of models were migrated, 80 new experiments ran in six months, and 18 generative AI systems are now in production with no unplanned platform downtime. It also reports that an income check inside the mortgage application process fell from days to seconds. The page carries no publication date and the account is the supplier's own. The figure that will travel is eighteen in production, and it is only comparable against a bank's own published definition of what production means.

Google Cloud (publication date unverified)

Innovation

OpenAI shipped three enterprise products in one day, including a version built for finance. Vendor

On 10 September OpenAI launched a finance-specific edition of its workplace assistant, shaped with Morgan Stanley and Evercore. It carries paid market data, source traceability, role-based access, configurable retention, compliance-log export and information barriers, the separation that stops one desk seeing another's client information. The same day it added a data agent that answers questions and builds dashboards straight over connected company data warehouses, enforcing table, row and column limits on every query. It also released a live voice model priced at five cents a minute for the speech layer alone, with the reasoning model behind it charged separately. A chat product that enforces row-level entitlements removes the reviewable query that a data-access approval was attached to.

OpenAI: ChatGPT for Financial Services | OpenAI: Data agent | OpenAI: GPT-Live-1

OpenAI's newest model is now generally available inside Amazon's enterprise AI service. Vendor

Amazon Web Services said on 8 September that GPT-6 Astra, OpenAI's most capable model, is generally available on Bedrock, the service that lets a customer run third-party AI models inside its own cloud account. It arrives behind the access controls, audit logging, private networking and boundary rules a bank already operates on that cloud, with no training on customer inference data and zero retention available on request. One exception sits in the same announcement: traffic captured by automated abuse detection can be held for up to 30 days. Every other control in the set matches what has already been accepted, and that similarity is what makes the single exception easy to wave through.

Amazon Web Services

Research

The OECD finds AI cannot scale in cross-border trade until the paperwork is digitised. Institute

A 46-page OECD report on supply chains argues that AI cannot be scaled reliably in trade facilitation until documents are digitised, data elements are standardised, systems interoperate, and electronic transactions carry legal certainty. It counts 1,600 separate environmental policy instruments across 38 economies, whose divergent formats, templates and verification channels create duplicated checking rather than automation. It also warns that opaque risk profiling is hard for a trader to challenge, and recommends human validation of AI-generated findings. For trade finance and corporate onboarding, that volume of unstandardised provenance data lands in exactly the pipelines being automated, and duplicated verification is what breaks an automation business case.

Organisation for Economic Co-operation and Development: Strengthening Supply Chains through Efficiency, Resilience, AI and Environmental Performance (publication date unverified)

Security

A study models what the compromise of one shared AI supplier could cost the banking sector. Institute

A paper posted to the preprint archive arXiv on 9 September models an attack on a shared AI supplier spreading through four layers: suppliers, banks, interbank exposures and customer accounts. The authors build a synthetic system of 60 suppliers and 220 banks, then vary the inputs to see what drives the damage. Two variables dominate: how many banks depend on the same supplier, and how long a fix takes to reach them. Doubling the patch delay for the most-connected supplier roughly doubled the modelled loss. The loss figures rest on invented exposures and simulator-generated labels, so what transfers is the input list, supplier reach, dependency, patch latency and incident telemetry, and most AI supplier inventories record none of it.

arXiv

The US standards body is writing the rules for how an AI agent proves who it is. Authority

The National Institute of Standards and Technology updated its AI Agent Standards Initiative on 14 August. The programme covers authentication, identity, authorisation and security evaluation for AI agents, and has published a concept paper on agent identity and authorisation alongside a formal request for information. The page records listening sessions held with the finance sector. Agent identity is the control area where a bank is most likely to inherit whatever its supplier ships, because no European standard exists yet to argue with. The first credible reference is being drafted in Washington, with finance in the room.

National Institute of Standards and Technology

On the radar

  • OpenAI, Anthropic and xAI each had service disruptions starting on 3 September, all resolved within two to three hours, prompting an analyst to argue that running several models is not the same as running several failure domains. ITPro
  • CrowdStrike extended its security platform to cover OpenAI's coding agents, adding a live agent inventory, runtime visibility and enforceable action controls, with no bank deployment or pricing named. CrowdStrike

Don't miss what's next. Subscribe to AI Pulse Daily Brief:
Older → AI Pulse Daily Brief | 2026-09-10
Powered by Buttondown, the easiest way to start and grow your newsletter.