AI Pulse Daily Brief | 2026-09-17
Reading time ~7 mins
Europe's data-protection board puts AI Act and privacy guidelines on its plenary agenda. A Dutch MP asks the cabinet whether current rules cover AI-enabled cyberattacks and sabotage, while the Netherlands still has no finally designated AI Act supervisor. Microsoft's and Salesforce's chief executives argue from different directions for holding AI makers to account. Anthropic publishes measured numbers on how well models locate and identify people from photographs and plain text. ABN AMRO reports one in seven young Dutch adults hit by online fraud.
Regulatory
Europe's data-protection board has AI Act and privacy guidelines on its plenary agenda. Authority
The European Data Protection Board keeps the EU's national privacy regulators reading the law the same way, and on 17 September it published the agenda for its 123rd plenary meeting. Item B.2.1 lists guidelines on how the AI Act and European data-protection law fit together, marked for discussion rather than adoption, with no draft text and no adoption date attached. The timing is what counts, because a text that has reached a plenary discussion is closer to a circulating draft than to an opening conversation. Once adopted it becomes the European benchmark against which the Dutch privacy regulator's own provisional generative-AI guidance from July is read.
European Data Protection Board
A Dutch MP asks the cabinet whether current AI rules cover cyberattacks and sabotage. Authority
On 10 September a member of the Tweede Kamer put written questions to the State Secretary for Economic Affairs and Climate about the safety risks of increasingly powerful AI systems. The questions ask whether the cabinet has assessed scenarios involving cyberattacks, interference with democratic processes and sabotage of vital infrastructure. They also ask whether the current Dutch, European and international framework is sufficient, and whether the Netherlands should seek extra safeguards including a temporary pause on the most powerful systems. These are questions, not a cabinet decision. What is at stake is the frame, because advanced AI treated as an operational-resilience problem answers to different Dutch supervisors than advanced AI treated as a fundamental-rights one.
Tweede Kamer der Staten-Generaal
The Netherlands still has no finally designated AI Act supervisor. Authority
The European Commission's register of AI Act market-surveillance authorities was last updated on 7 September. It lists the Dutch Authority for Digital Infrastructure as the country's single point of contact, with an asterisk beside it: the national designation is still pending final adoption. The register sets out what such authorities may do, which includes investigating, monitoring remotely, demanding documentation, data sets and source code, requiring corrective measures and imposing penalties. Supervision of general-purpose AI models sits separately with the European Commission's own AI Office. The contact point is not the questioner, so it is the allocation of financial-sector duties to the Dutch supervisors that decides who actually asks a bank for AI Act evidence.
Perspectives
Microsoft's chief executive puts autonomous agents in the insider-risk category. CxO voice
Fast Company reported on 16 September that Satya Nadella urged AI companies to keep their systems under human control. His concrete asks are testing by people from outside the team that built the system, a willingness to stop a release over a serious defect, and transparency about data use and intellectual-property leakage. He described autonomous agents as an insider-risk problem requiring containment and close monitoring, and raised the prospect of international safety norms. The article supplies no evidence that Microsoft itself works this way. What it does supply is a supplier's own published bar, which a buyer can ask for evidence against at the next architecture or contract review.
Salesforce's chief executive says AI makers should carry the cost of foreseeable harm. CxO voice
Fortune published an interview with Marc Benioff on 16 September in which he argued that the companies building AI should anticipate and prevent foreseeable harm. They should be held responsible before anyone is hurt, he said, with product-liability rules as the backstop where voluntary self-governance is not credible. He described constrained structures and close monitoring around the agents his own company sells, and called for an ethical ranking of large firms. The position is self-interested, because Salesforce sits above the model layer and would carry less exposure than the model providers. It is also on the record, and it cuts against the standard contract clause that parks AI risk with the deploying customer.
Consumer centricity as a governed operating model for insurance Perspective
Perspective: The report's strongest signal is that life-insurance growth is constrained less by a lack of interest than by a failure to make value legible and continuous. Its survey finds 47% of consumers actively exploring coverage, while 25% leave the purchase journey and about half of discontinued policies end within three years. For a bank, the relevant lesson is to treat clarity, relevance, and post-sale engagement as operating outcomes, not merely communications problems.
Capgemini's proposed response joins three changes: products and journeys organized around life stages and outcomes; plain-language education and proactive triggers; and a unified data foundation that can support AI orchestration. The report describes a hybrid trust model. Digital self-service and AI-guided interactions handle scale and routine work, while advisors remain present for coverage decisions, problem resolution, and other high-judgment moments. That boundary is central to the argument, not an implementation detail. The useful decision frame is therefore narrower than 'should we use agentic AI?' A bank can ask whether one customer journey has a specific unmet need, a measurable outcome, a minimum trusted data view, explicit consent, auditable triggers, and a human exception path. That is an inferred application of the report, not a reported bank result, but it translates the source's operating model into a testable preparation stance. Scaling should follow evidence that the journey becomes clearer and more useful without weakening trust.
The evidence deserves calibrated use. The study combines a survey of 6,175 people with interviews with 198 senior insurance executives, and its best-in-class grouping relies on self-assessed maturity. The reported 41% higher revenue growth and 12% lower lapse rates are correlations, not proof that AI caused the difference; case examples and transfer from life insurance to a Dutch cooperative bank remain unproven. The durable takeaway is disciplined integration: consumer relevance, human judgment, connected data, and governed automation should be monitored as one operating system, with privacy, consent, fairness, and trust treated as countervailing outcomes. This also argues for a monitoring stance that tracks customer comprehension, advisor escalation, retention, and control exceptions together. Those measures can show whether a more connected journey is creating durable value or merely shifting effort and risk between channels.
Capgemini Research Institute (Shared by Tony Moroney)
Industry & competition
ABN AMRO says one in seven young Dutch adults was hit by online fraud last year. Corporate
ABN AMRO published research among its own clients on 3 September, reporting that one in seven 18-to-35-year-olds had been affected by online fraud in the previous year. It attributes the rising risk to increasingly convincing fake messages, images and voices made with AI. The research found that 58 percent do not check an online shop's contact details, and that 39 percent use Call Check, the bank's feature for confirming a caller really is the bank. Its new campaign teaches young customers to tell real contact from fake. The answer here is a customer verification habit rather than better detection, so the peer figure that reaches a board table is take-up of the check.
Security
An AI maker measured how precisely its models can locate and identify people, and published the numbers. Vendor
Anthropic's internal red team published an evaluation on 10 September of what current AI models can do on intelligence-targeting tasks. On 6,000 geotagged photographs, with camera metadata and reverse image search withheld, its strongest preview model placed 23.7 percent of images within one kilometre of the true location. A separate test on plain text put 135 of 1,697 users within a kilometre, and assessing a 37,000-word sample took the model 11 minutes against two and a half hours for a person. Anthropic calls these results a floor rather than a deployment benchmark, because the data is curated and the trials are simulations. Masking a location field is therefore evidence about what a model can retrieve, not about what it infers from everything left unmasked.
On the radar
- Hundreds of AI agents were used to scan for and exploit two flaws in widely used print-management software, compromising 395 organisations across 48 countries and reaching top-level administrator access at 12 of them. BankInfoSecurity
- A Cloud Security Alliance note dated 13 September describes automated agents publishing more than 2,000 packages to a public software registry in two days and using its documentation build service to run code, though the registry could not confirm the AI attribution. Cloud Security Alliance