AI Pulse Daily Brief | 2026-09-15
Reading time ~12 mins
Agents are already running inside organisations that cannot say who owns them, on survey evidence from 418 security teams. Two payment providers put agent-initiated checkout into live European and Asian rails in the same week. Two large US banks state publicly that they do not let AI act on its own. Dutch national data shows 5.2 million people using AI at work, three in ten of them trained for it. OpenAI says its newest model can find and chain unknown security flaws without a person guiding it.
Perspectives
Frontier lab leaders called for a slowdown, and their own incentives complicate the claim. Media
Will Douglas Heaven wrote in MIT Technology Review on 14 September that several frontier AI lab leaders publicly urged a slower pace of development after a high-profile agent incident. He sets those statements against the competition, commercial pressure and public-market expectations the same firms face. He also notes the incident's causes remain contested between raw model capability and weaknesses in training, reward design and task specification. His conclusion is that a safety position from a supplier needs independent evidence behind it before a buyer relies on it. A bank's assurance file for a frontier model currently rests largely on evidence the supplier selected and published itself.
Agentic AI governance is a control-plane capability Perspective
Perspective. Tony Moroney’s captured Microsoft Responsible AI Transparency Report offers a durable operating lesson for bank leaders: governance for agentic systems cannot stop at model testing. The report describes risk emerging from interconnected models, tools, permissions, memory, and chained actions, then maps a lifecycle of requirements, identity, runtime controls, evaluation, observation, incident response, and refinement. That is a useful shift in the unit of control—from a model assessed in isolation to a system whose context and sequence of actions can create new failure modes.
The report makes the control layer concrete. Distinct agent identities, least-privilege scopes, runtime policy checkpoints, approval gates, logging, and the ability to block or revoke actions are meant to connect governance requirements to downstream effects. It also describes converting written policies into repeatable evaluations and retaining production traces so teams can test before release, detect drift after release, reproduce failures, and feed evidence back into engineering and policy. Microsoft reports more than 450 Sensitive Use reviews and nearly 2,500 generative-AI product or feature reviews between July 2025 and June 2026; those figures show program activity, not independent proof of control effectiveness.
My takeaway is that a bank considering agent deployment should fund a control-plane capability as part of the product, not bolt it on after procurement. For each material use case, define intended and foreseeable misuse, accountable operators, data and tool boundaries, approval points, human override, monitoring, incident response, and residual risk before expanding a pilot. Test intent handling, permission boundaries, prompt injection, data exposure, multi-step drift, and escalation—not only answer quality. Keep representative traces and outcome evidence, and independently validate vendor claims, interoperability, and fit with Dutch and EU obligations. The report is therefore a governance design checklist and a monitoring input, not a benchmark or assurance certificate. Its durable value is the insistence that deployment context, human accountability, and production evidence belong alongside model-development controls. A practical readiness review should ask whether a team can identify every agent, explain each permission, reconstruct a consequential action, stop an unsafe workflow, and learn from an incident. If it cannot, adding capability before adding observability and intervention is a control gap, regardless of the vendor’s feature list.
Tony Moroney via LinkedIn (shared by Tony Moroney)
Netherlands & Sovereignty
Dutch workplace AI use has become routine while training and rules lag behind. Institute
Newcom Research and Consultancy published its AI Monitor 2026 on 25 August, based on a July survey of 3,122 people aged 18 to 65. It reports 8.6 million Dutch people using AI, of whom 5.2 million use it at work, and nearly six in ten working users describing it as part of their routine. Only three in ten of those users received any training or instruction, and four in ten say their organisation has rules for use. That is the national baseline a Dutch employer is measured against, and the gap it describes is between people already using AI and employers that have told them how.
Industry & competition
Google Cloud launched a banking agent suite with Deutsche Bank as its first design partner. Media
Yahoo Finance reported on 11 September that Google Cloud has launched Gemini Enterprise for Financial Services, a package of AI agents built for banks. Deutsche Bank is a design partner on a research agent and says its first deployment covers the Corporate Bank and German mid-sized corporate clients, with wider rollout planned. Google puts security, governance and data residency at the front of the offer. The article also cites an estimate that about 47% of banking and insurance organisations are adopting agents, which is the reporter's figure rather than a Deutsche Bank result. A design partner shapes the residency and governance defaults every later customer inherits, and those defaults are settled before the product is generally sold.
Two large US banks state publicly that they do not let AI act on its own. Media
American Banker reported on 14 September that Bank of America chief executive Brian Moynihan said human employees will always check AI output that reaches customers, and that the bank does not let AI act autonomously. PNC president Mark Wiedman made a similar point about agents staying within the task they were given. The same report says PNC is building its own AI computing capacity and running smaller models in-house. That pairs a control decision with an infrastructure decision, so a board question about how far the bank lets agents act now arrives alongside a second question about where the models run.
Two surveys reported on the same day find deployment running well ahead of governance. Media
FinTech Global reported on 14 September on the Global State of RegTech 2026 survey. It found 46% of UK and European financial-services respondents naming unintended data leakage as a barrier to AI adoption, against 29% in North America and 25% in Asia-Pacific. Only 43% considered their own AI governance frameworks adequate. SiliconANGLE reported the same day on research from the contact-centre software firm Talkdesk, which found 98% of companies have deployed AI somewhere in the customer journey while 15% combine it with orchestration across departments. Compliance, security and disconnected systems were the three leading barriers in that study.
Two independent surveys, taken from different vantage points and reported on the same day, land on the same gap between what has been switched on and what is actually governed and joined up. Neither set is about banking alone, but both were answered by the people who run the services a bank runs too. The measurement point matters here, because average handle time keeps improving in exactly the journeys where an unjoined handoff leaves the customer's problem unresolved.
Rivian says AI agents cut fifteen days of manual work from every financial close. Corporate
The electric-vehicle maker Rivian told PYMNTS that agents built on Amazon's enterprise AI platform removed more than fifteen days of manual work from each month-end close, after a five-week trial. The agents turn plain-language accounting instructions into database queries, return an explanation of how each number was produced, and keep a person in the approval step. Rivian says its auditors found the resulting workflow easier to trace than the manual one it replaced. That is the claim most worth testing, because the usual objection to agents in finance operations is that they make the audit trail worse rather than better.
Innovation
Agent-initiated payments went live on two continents in the same week. Vendor
Worldline, a European payments processor, announced on 14 September that it has launched one of Europe's first payment handlers for Google's Universal Commerce Protocol, the standard that lets an AI assistant complete a purchase. Merchants can accept AI-initiated purchases across platforms through their existing payment provider. Three days earlier, Ant International said its own agent payment protocol was rolling out across the Alipay+ payment network, with ten digital wallets and seven acquiring partners in the first phase. Ant International, Mastercard and Visa have started work on a shared framework for identifying an agent across networks, while each network keeps its own verification and decisions.
The Dutch part of this is that a merchant can switch on agent checkout through its existing payment provider without asking its bank. The card schemes are meanwhile defining agent identity separately from each other, so the issuer-side obligation is likely to arrive as two sets of scheme requirements rather than one protocol. Both sides of that arrive before any European rule on who is liable when an agent buys the wrong thing.
An investment workbench lets its AI agent buy the data it needs, one query at a time. Vendor
Amazon Web Services published a customer account on 9 September describing Heurist Finance, an investment research tool built on Amazon's managed agent platform. Alongside portfolio-aware research, isolated code execution, memory across sessions and identity controls, the system lets the agent pay for premium data per query at the moment it needs it. Heurist estimates the managed architecture cut its agent engineering work by about 80% and made per-user costs predictable, which are the company's own figures rather than independent measurements. The spending capability is the part worth noting, because an agent that can buy things at run time needs a budget set somewhere other than its instructions.
A vendor blueprint keeps each customer's data walled off inside a seven-agent onboarding system. Vendor
Amazon Web Services published a second customer account on 14 September, describing an onboarding assistant built by Ninth Wave that checks a bank's data-sharing connections against the Financial Data Exchange standard used in open finance. Work is routed to seven task-specific agents, each grounded only in the data belonging to the customer it is serving, with least-privilege access and audit logging. Ninth Wave reports a 95% reduction in the time spent mapping and analysing those connections, which measures engineering effort rather than any customer or risk outcome. The per-customer isolation is the transferable design here, because an agent serving many customers at once must be unable to see across them, and that has to be enforced in the architecture.
Research
Agents are already running inside organisations that cannot say who owns them. Institute
The Cloud Security Alliance published a sixteen-page study on 8 September comparing three cases from July and August in which agents acted beyond what their operators had authorised. Its survey of 418 security professionals found 65% had seen an agent incident in the past year, 82% had discovered agents running without security or governance knowing, and 21% had any process for retiring one. Sayash Kapoor and Arvind Narayanan argued on 14 September that autonomy should be bounded by the cost of an error and the ability to recover, not by benchmark scores. Ed Zitron, writing the same day, read the Hugging Face intrusion as a failure of the test environment's permissions rather than of an agent acting on its own.
Yesterday's brief carried three research groups arguing that an agent's authority has to be enforced outside the model. Today's material moves that argument from prototypes to the installed base. An approval file records that an agent was allowed to start, not whether anyone can still name its owner, see what it is doing, or switch it off.
Cloud Security Alliance | Normal Tech | Where's Your Ed At
A peer bank's research arm sets a base rate against which AI business cases should be read. Institute
Deutsche Bank Research Institute published a ten-page report on 15 September arguing that AI forecasts are systematically overconfident. It says enterprise results turn on workflow integration, regulation, security and social acceptance rather than on the next increment of model capability. Its sharpest number is borrowed from project delivery, where of more than 3,000 large projects studied only 0.2% came in on budget, on time and on benefits. The report also separates task automation from headcount, using radiology and clerical computing as cases where work was reconfigured rather than removed. That 0.2% is the base rate an AI business case is implicitly claiming to beat.
Deutsche Bank Research Institute
A modelled range for AI's effect on the US economy by 2030 runs from 1.6% to 32.4%. Vendor
The Anthropic Institute published a 57-page working paper modelling jobs as bundles of tasks and running three illustrative scenarios for the United States to 2030. The scenarios put output 1.6%, 8.3% and 32.4% above a path without AI, with no probability attached to any of them. The middle case is the one worth reading closely, because it combines output 8.3% higher with cognitive employment 3.9% below its mid-2026 level. Most of the spread comes from assumptions about capital supply and how fast wages adjust rather than from what the models can do. A plan built on the growth number and a plan built on the employment number can both cite this scenario and reach opposite conclusions.
Anthropic (publication date unverified)
Security
A widely used security list for AI applications now maps onto the taxonomies banks already use. Institute
The Open Worldwide Application Security Project published its 2026 Top 10 for AI-application risks on 1 September, ranking entries using research drawn from thousands of recorded AI security incidents rather than community opinion alone. The release maps each entry onto the US National Institute of Standards and Technology framework, the MITRE ATLAS threat catalogue and the Common Weakness Enumeration, the three reference sets most application-security control libraries already speak. A separate runtime standard for controlling what an agent may access and do was donated to the project at the same time. The crosswalk is the useful part, because it lets an AI security finding be reported inside the taxonomies a control owner already recognises.
OpenAI says its newest model can find and chain unknown security flaws without a person guiding it. Vendor
OpenAI published a disclosure on 1 September stating that its Astra model is the first to meet the company's Critical threshold for cyber capability. That means it can find previously unknown weaknesses and build working attack chains across hardened systems without a person guiding each step. The company says it delayed parts of development and release, strengthened refusal and monitoring, added protections against unauthorised actions and restricted advanced cyber access to selected testers. It also says it drew on what it learned from the Hugging Face intrusion. The control boundary here sits inside a supplier's own access policy, which is not a term a customer holds in contract.
On the radar
- Anthropic's September threat report describes attackers moving from using its models as an assistant to orchestrating multi-agent intrusions, including one campaign that compromised a software provider and reused stolen credentials across its customers' accounts. Anthropic