AI Pulse Daily Brief | 2026-09-21
Reading time ~10 mins
The Dutch cabinet reports the privacy-side Digital Omnibus stalled in Council and wants its AI data-processing changes assessed separately. Bol puts a conversational shopping assistant in front of Dutch consumers, and the Commission records a €14.1 million Netherlands AI Factory grant running to 2029. Sokin lets customers' AI tools prepare payments, and Amazon serves a Chinese open-weight model with no EU-resident option. Anthropic publishes its own agent-oversight numbers, and the Cloud Security Alliance splits AI-enabled attacks from attacks on AI systems.
Regulatory
The Dutch cabinet says the privacy-side Digital Omnibus has no Council mandate and wants its AI data rules assessed separately. Authority
On 17 September the Eerste Kamer published a written-consultation report on the EU Digital Omnibus, the Commission's package to simplify digital rules including the GDPR. In the cabinet's answer, State Secretary Aerdts wrote that a blocking minority kept the proposal off the 26 June agenda of the ambassadors' committee that prepares Council decisions. The Council therefore has no mandate to negotiate with Parliament, and the Irish presidency is continuing the work. The cabinet remains concerned about the GDPR changes on pseudonymisation, cookies and data processing for AI, notes the absence of a Commission impact assessment, and wants substantial changes assessed separately. For 2027 generative-AI data use in a Dutch bank, the working legal basis stays today's GDPR and the Dutch privacy regulator's July guidance, not a relaxed omnibus text.
Eerste Kamer der Staten-Generaal
Perspectives
Two management academics argue AI disruption is now a permanent operating condition, not a transition. Institute
MIT Sloan Management Review published an essay on 10 September by Rory McDonald and Will Drover arguing that AI has turned organisational disruption from a temporary wave into a continuing condition. Repeated rounds of pilots, mandates and training produce fatigue, they write, when an organisation has no durable mechanism for absorbing change. Their remedy is permanent AI infrastructure and two operating cadences, a fast one for teams that experiment and ship and a slow one for teams building lasting foundations. A standing function would track developments and translate what they mean. The essay carries no data and no bank case, and its stake sits in the 2027 budget round, where a plan that funds only pilots is a plan that assumes the disruption ends.
AI-orchestrated misuse raises the bar for defensive monitoring Perspective
Perspective: Anthropic's September 2026 threat-intelligence report changes the defensive question from whether criminals use AI to how much of an operation AI can now coordinate. Across the cases described, Claude supported reconnaissance, exploitation, phishing, persistence, data extraction, and exfiltration. The report's central signal is operational: AI can connect steps across a kill chain, allowing actors with fewer resources to work faster and at greater scale. The examples are notable cases, not a prevalence estimate, but they are concrete enough to make isolated-prompt monitoring look incomplete.
The report describes workflows that monitor whether malware is detected and then rebuild tooling to evade those detections. It also describes illicit distillation and proxy networks that replay or relay exchanges to extract model capabilities. Those mechanisms point to a layered control problem. Account signals, metadata, classifiers, model behavior, and end-to-end workflow patterns each contribute evidence, while disruption and intelligence sharing remain part of the response. A static blocklist or a review limited to individual prompts can therefore miss the way activity adapts across infrastructure, models, and human operators.
For a bank, the durable preparation stance is to test monitoring and third-party controls against coordinated behavior rather than treating each AI interaction as an isolated event. Map where model use touches reconnaissance, code, credentials, customer data, or external execution; define escalation when activity crosses those boundaries; and preserve human review for consequential exceptions. That is an application of the report's defender lessons, not a reported bank result. The report also warrants calibrated use: attribution and intent are not uniformly certain, and the observed cases cover December 2025 through August 2026. Leaders should therefore monitor for changes in attack speed, breadth, and adaptation, validate signals before acting, and keep strengthening layered safeguards instead of assuming one control will remain sufficient. The same logic applies to procurement: ask vendors how they detect coordinated misuse, share intelligence, recover from account compromise, and prove that safeguards are updated after incidents. A control that only blocks yesterday's isolated pattern is weaker than a layered operating process that can learn from new evidence. This makes resilience a continuing governance responsibility, not a one-time model approval exercise.
Anthropic via LinkedIn (shared by Tony Moroney)
Tokenized settlement needs a money and ledger strategy Perspective
Perspective: The important shift in Al-Mabrook Financial's report is from asking whether institutions will tokenize assets to asking which form of money can settle them, on which ledger, and under what controls. Its distinction between asset issuance and atomic delivery-versus-payment makes the operational issue concrete: settlement requires the cash and asset to share a ledger or work across interoperable ledgers. Stablecoins offer open-network reach and a route to retail liquidity, but the report describes legal, reserve, redemption, anti-money-laundering, and custody constraints. Tokenized deposits offer regulated bank money and immediate wholesale settlement, but can remain confined to banking networks. The choice is therefore an operating model, not a technology preference.
For a Dutch bank, the durable preparation stance is to define its role before selecting a rail: issuer, distributor, or acceptor and custodian. Treasury, payments, legal, risk, and technology leaders should map where cash and collateral sit, how counterparties are authorized, how keys and custody are controlled, and which ledgers interoperate. The report's six decision areas provide a useful agenda: wholesale tokenized deposits, custody location, corridor economics, and the treatment of tokenized funds alongside the basic participation decision. Its quantified evidence is a necessary guardrail. The report says that 93% of gross on-chain stablecoin transfer volume is not a payment, and cites a Banca d'Italia exercise finding end-to-end costs from roughly 0.3% to almost 9% across ten corridors, without systematic savings over incumbents. That argues against using headline volume or assumed speed as a business case.
The monitoring implication is to track regulatory deadlines, reserve and redemption conditions, interoperability, counterparty concentration, and measured economics by corridor rather than treating stablecoin growth as a one-way trend. The report also records a fall in stablecoin supply from its May 2026 peak, reinforcing the need to test assumptions. A bank should keep both rails in view while making explicit where legal settlement, deposit protection, customer reach, and operational resilience matter most. That is a more useful decision posture than predicting one universal winner: prepare for coexistence, but require evidence that each proposed use case works under its actual legal, ledger, custody, and cost constraints.
Al-Mabrook Financial Q3 2026 Digital Assets Executive Industry Update via LinkedIn (shared by Richard Turrin)
Netherlands & Sovereignty
Bol has put a beta conversational shopping assistant in front of Dutch consumers. Media
Emerce reported on 15 September that Bol, the largest Dutch online retailer, released Shophulp, a beta AI assistant for conversational product discovery. It takes broad questions such as planning a trip or a day out, gives advice first and shows product carousels afterwards, so product references can stay a small part of an answer. Bol says a specialist team monitors the assistant continuously and gathers feedback from customers and selling partners; Emerce reports no accuracy, conversion or complaint figures, so this is controlled experimentation rather than proven impact. It still sets a Dutch consumer expectation that a conversational interface handles the orientation question around a life event before it offers a product. That is the bar a bank's own customer assistant is now read against.
The Commission has recorded a €14.1 million Netherlands AI Factory grant that runs to mid-2029. Authority
A European Commission project record updated on 17 September lists the Netherlands AI Factory under a grant agreement signed on 1 September 2026, running from 1 July 2026 to 30 June 2029. Total cost is €14.1 million, of which the EU pays €7.05 million, coordinated by the Dutch AI Factory foundation with SURF, the national research-computing organisation, TNO, the Dutch AI Coalition and Samenwerking Noord. The aim is a nationally hosted AI hub on the coming Dutch EuroHPC facility in Groningen, with confidential computing for personal and IP-protected data, explicitly to reduce dependence on American big-tech infrastructure. The €7 million EU share marks this as a service layer on the Groningen machine rather than a national capacity answer, and mid-2029 is the earliest the sensitive-data capability could exist.
Industry & competition
Chewy expects AI to remove about $50 million of costs in fiscal 2027. Media
PYMNTS reported on 18 September that Chewy, the US online pet retailer, expects AI to remove roughly $50 million of costs in fiscal 2027, up from the low tens of millions this year. Its customer-service assistant, Cai, carried under 15 percent of contact traffic and resolved about 30 percent of those chats without a human agent at the time described. The figures are company-reported expectations and operating results from a retailer already in production, not audited outcomes. The pairing of a traffic share with a resolution rate is rarer than either number alone. It puts a concrete ceiling under any customer-assistant business case a bank contact centre is reading now, and shows a mature deployer booking its larger savings only in its second year.
Innovation
Sokin lets customers' own AI tools prepare payments through a standard connector, with settlement behind human approval. Vendor
Sokin, a licensed cross-border payments provider, announced on 14 September a connector built on the Model Context Protocol, the open standard that lets AI assistants call outside tools. Through it, a business customer's AI tool can read balances, pull foreign-exchange quotes and payment status, and prepare an exchange, a new beneficiary or a payment instruction. Settlement stays behind human confirmation and the customer's existing approval rules. This is a vendor announcement with no usage figures, but it moves this class of connector from read-only retrieval to governed payment execution. A bank's controls against authorised push-payment fraud assume the instruction was typed by a person, which an agent-prepared instruction is not.
Amazon now serves a Chinese open-weight AI model on its enterprise platform, with no EU-resident option. Vendor
Amazon Web Services announced on 18 September that Kimi K3, an open-weight model from the Chinese lab Moonshot AI, is available on Bedrock, Amazon's enterprise AI hosting service. AWS describes native image understanding and a one-million-token context window, and says prompts and outputs stay within its boundary, are not used for training, and are held with zero retention and no operator access. The model is offered only through global and US cross-region profiles, the global one about 10 percent cheaper, so there is no EU-resident inference path today. The retention promises answer the data-handling question but not the model-origin one. For a bank that question belongs to third-party risk and sits ahead of any benchmarking a team might want to run.
Research
Anthropic proposed three measures of how AI labs oversee their own AI agents, and published its own numbers. Vendor
Anthropic published a proposal for three repeatable measures of frontier-lab transparency, covering how much AI research is done by AI, how agent actions are overseen, and how compute is allocated. Its August 2026 snapshot says Claude leads 26 percent of measured AI research work and that roughly 30,000 internal agents are monitored. Its live monitor blocked about one decision in 47,000 out of more than a billion, and about 6 percent of research compute went to safety work in the sampled week. The authors name self-evaluation, short observation windows and contestable category boundaries as limitations and call for third-party evaluators. A vendor that has published its own monitored share, review time and escalation rate has set a disclosure bar a regulated customer can hold it to.
Anthropic: Measurements for understanding the pace of AI development inside frontier labs (publication date unverified)
Security
The cloud-security industry body now ranks attacks that use AI and attacks on AI systems as separate threats. Institute
The Cloud Security Alliance, the industry body behind the most widely used cloud-threat ranking, explained on 17 September why its 2026 Top Threats list carries two AI categories, ranked second and sixth. AI-enhanced attacks use models to speed up conventional offensive activity, while AI-system compromise targets the models, prompts, training data, tools and orchestration of a deployed system. Cloud control planes amplify both through internet exposure, concentrated credentials, machine identities and interconnected services. The alliance's control list covers inventory, handling of untrusted content, human approval gates, permission monitoring, reconstruction of an agent's actions, revocation and manual fallback. The second category sits between application security and model risk, which is exactly where a line in an ICT-risk register is most easily left without an owner ahead of the next DORA review.