AI Pulse Daily Brief | 2026-09-22
Reading time ~12 mins
Société Générale puts a EUR 500 to 600 million figure on its AI programme and names Anthropic as its control partner. The Commission's AI Board turns to enforcement support and drafts AI-literacy recommendations ahead of an 18 November meeting. The ECB's supervisory vice-chair names AI-capable attack tooling as a resilience-investment driver. Eurofiber will host the Dutch AI Factory in Groningen, operational in early 2028. Docusign reports a 90 percent AI cost cut from small models. IBM's CHRO study finds only 26 percent of organisations define where humans stay accountable. Two critical flaws in AI infrastructure land on the radar.
Regulatory
The Commission's AI Board has shifted to enforcement support and is drafting AI-literacy recommendations. Authority
The European Commission's AI Board, the body of national authorities that coordinates AI Act implementation, held its ninth meeting on 17 September and reviewed enforcement priorities. The Commission said it is drafting recommendations to support the Article 4 AI-literacy duty already in force. It is also preparing a Code of Practice and guidelines to operationalise the Article 50 transparency rules that have applied since 2 August 2026. Members discussed market-surveillance cooperation and the Action Plan on Cybersecurity and AI, and the next meeting is expected on 18 November. No new obligation was created, but these two texts are the first Commission-level yardsticks a market-surveillance authority can hold a bank's staff-training records and chatbot disclosures against.
The ECB's supervisory vice-chair named AI-capable attack tooling as a reason banks must invest in resilience. Authority
On 8 September Frank Elderson, Vice-Chair of the ECB Supervisory Board, said in a supervisory fireside chat that European banks need to invest in artificial intelligence and cyber resilience to remain competitive. He cited AI models such as Mythos, Anthropic's most capable model with documented cyber-exploitation capability, as making cyber threats more sophisticated, and said banks must invest so that critical services remain available. He also disclosed that the ECB now uses digital tools and AI in its fit-and-proper assessments of bank board members. The speech announces no rule, guidance or deadline. It does put the bank's direct supervisor on record that AI-enabled attack tooling is a resilience-investment driver, and that a supervisory judgment on a board member's suitability can now itself be AI-assisted.
Perspectives
Paul Krogdahl argues banks should let AI agents reason freely but grant them the authority to act narrowly. Independent
Paul Krogdahl, an independent banking-technology practitioner, argued in a 13 September analysis that agentic banking is three different transformations: agents that write software, agents in controlled back-office operations, and customer-facing agents that can move money. He finds the first two entering controlled use at banks such as NatWest, DBS, BBVA and Revolut, while the third stays unsettled because liability and security get harder once an agent can execute a payment. His design rule is to separate reasoning freedom from execution authority, and to invest without regret in data quality, identity, granular permissions and auditability. It is one practitioner's synthesis with no measured outcomes. The distinction matters now because this year's deployment evidence comes almost entirely from the first two transformations and does not transfer to customer-authorised money movement.
Europe’s truck transition tests AI execution and lifecycle finance Perspective
Perspective: The useful lesson in McKinsey’s September 2026 truck-industry report is not the size of its forecasts; it is the operating discipline required to make those forecasts investable. The report connects zero-emission infrastructure, autonomous freight, Chinese competition, and AI-enabled operations into one transition. For a bank, that is a reminder that sector change will arrive through linked choices about assets, funding, data, controls, and service models rather than through a single technology bet.
The evidence gives the transition practical weight. McKinsey estimates that autonomous road freight in Europe could become a €100 billion value pool by 2035, while its analysis says zero-emission trucks already have a total-cost-of-ownership advantage in about 30 percent of use cases. It also identifies a large infrastructure requirement and describes financing, residual-value management, insurance, remarketing, and portfolio monitoring as parts of a broader lifecycle proposition. These are not bank forecasts, but they are credible prompts for scenario work because the report identifies the assumptions that can break the economics: charging access, standards, service networks, reliability, customer demand, and capital intensity. The report’s observation that universal banks and specialist lenders hold about 70 percent of the European truck financing and leasing pool makes the ownership question especially relevant, while still calling for careful validation before a portfolio decision.
The stronger takeaway for bank leaders is an execution test. The report says AI gains come from redesigning end-to-end workflows, making data agent-readable and auditable, handling exceptions, measuring financial and operational value, and assigning senior ownership. Its client examples are directional and may not transfer to regulated banking processes, so they should not be copied as business cases. Banks can also use the report’s uncertainty list as a diligence checklist: distinguish observed operating results from projections, test dependency on external partners, and ask whether data rights and accountability survive a lifecycle model. They can, however, sharpen monitoring: track whether financing portfolios are exposed to residual-value shifts, whether counterparties have credible infrastructure plans, and whether internal AI pilots have control evidence and measurable outcomes. That turns a transport report into a durable question about where the bank wants to own lifecycle capability and where it should rely on partners.
McKinsey & Company via LinkedIn (shared by Tony Moroney)
Prediction markets are narrower than their signal Perspective
Perspective: The useful challenge in HODL UP Research’s report is not that prediction markets have no value. It is that a quoted price should not automatically be read as a calibrated belief held by a broad crowd. The report argues that a small group can set the price, that profits and notional activity are concentrated, and that headline volume can be distorted by wash trading. It also shows why venue context matters: Kalshi’s reported sports concentration makes it a different instrument from a general forecasting market, while Polymarket mixes sports, politics, and crypto activity.
For a bank, that changes how prediction-market data should enter preparation, monitoring, and decision processes. A market-cent price can be a useful observation, but it should be accompanied by checks on participant concentration, category mix, open interest, liquidity, trading integrity, and the quality of the resolution mechanism. The report’s distinction between volume as a flow and open interest as a stock is especially important: a record turnover number does not by itself establish durable economic participation or reliable information content. Treating the signal as one input among several is safer than presenting it as an objective probability.
The durable governance lesson is to inspect the layer that decides what is true. The report says that centralized venues rely on rulebooks and regulators, while onchain venues rely on oracle and token-holder processes; a wrong resolution can overwhelm otherwise strong liquidity and execution. Its regulatory discussion likewise makes rulemaking and court decisions part of the operating outlook. The report’s figures are carefully qualified: some are snapshots or reconstructed series, addresses are not people, separate studies should not be merged, and the calibration graphic is schematic. That makes the right stance neither dismissal nor adoption by headline. Banks assessing these markets, vendors, or embedded products should ask what the number measures, who sets it, how conflicts are handled, and what evidence would cause the signal to be discounted or a deployment paused. The report’s own thesis points toward regulated operators with surveillance, compliance, data, and credible resolution infrastructure rather than pure retail velocity. That is a decision framework likely to remain useful after this particular market cycle. Source label: HODL UP Research Prediction Markets Report 2026.
HODL UP Research Prediction Markets Report 2026 via LinkedIn (shared by Richard Turrin)
Netherlands & Sovereignty
SURF has contracted Eurofiber to host the Dutch AI Factory in Groningen, fully operational in early 2028. Vendor
Eurofiber Cloud Infra announced on 21 September that SURF, the Dutch national research-computing organisation, has awarded it the contract to build and run the data centre for the Dutch AI Factory in Groningen. The facility is due for completion in 2027 and its EuroHPC AI supercomputer is to be fully operational in early 2028, serving research, public-sector and business workloads on Dutch soil. The design includes water-free cooling, heat recovery for about 2,000 homes, battery storage and grid-operator agreements to avoid congestion. This is the supplier's own announcement, and capacity, commercial eligibility and service levels for business users remain unpublished. The Dutch sovereign-compute option now has a contracted site, a named operator and a date, the point at which it becomes comparable with the American hyperscalers' EU-region offers.
Industry & competition
Société Générale puts a EUR 500 to 600 million figure on its AI programme and names Anthropic as control partner. Corporate
Société Générale's Capital Markets Day presentation, dated 21 September, estimates a current AI opportunity of EUR 500 to 600 million, with about EUR 350 million embedded by 2029. The deck targets more than 30 percent lower coding costs, more than 20 percent productivity gains in streamlined workflows and 40 percent of incoming calls covered by AI assistants. IT costs are to fall about 30 percent between 2022 and 2029. It describes a strategic collaboration with Anthropic covering recurring rollouts of Claude models, coding tools and agentic capabilities, plus jointly built responsible-AI use cases and control frameworks. These are management targets rather than audited outcomes, yet a European universal bank has now published a 2029 AI yardstick in units that analysts and supervisors can apply to any peer.
Docusign moved routine contract extraction to small AI models and reports a 90 percent cut in processing cost. Media
PYMNTS reported on 21 September that Docusign, which processes more than one million contracts a day, has moved routine data extraction from general-purpose AI models to smaller task-specific ones. The company reports a 90 percent cut in AI processing cost, up to eightfold higher throughput and accuracy within two percentage points of the previous approach. Larger models are reserved for judgment-heavy work, and the system sends only the relevant passages of a contract rather than the whole document. The figures are company-reported through Docusign and Microsoft case-study material and have not been independently measured. For a bank extracting data from lending, KYC and legal documents with general-purpose models, a 90 percent cost difference at a two-point accuracy cost is a number a finance function will expect to see tested.
DoorDash gave 10,000 employees an AI data analyst and credits dataset organisation for most of its accuracy gains. Media
PYMNTS reported on 21 September that DoorDash's internal AI agent, Vera, now answers business questions for more than 10,000 employees across more than 200,000 datasets. On a company test of more than 1,900 questions, its self-reported pass rate rose from 43 to 90 percent. DoorDash credits the largest gains to organising and verifying the underlying datasets rather than to a better model. The agent still struggles with forecasts and causal questions, so the company added a planning step that waits for an employee's approval, and it has not yet shown that faster answers improved core business metrics. For any internal ask-the-data assistant, the case makes the deployer's ordering explicit: dataset verification first, model choice second, and a human approval gate kept even at 90 percent.
Research
IBM's 2026 CHRO study finds only 26 percent of organisations define where humans stay accountable in AI-enabled work. Institute
IBM Institute for Business Value published its 2026 CHRO Study, Designing the Thinking Organization, on 21 September, based on surveys of 1,500 HR executives and 8,800 employees fielded with Oxford Economics. Only 26 percent of organisations clearly define work as human-led, AI-assisted or AI-executed, while 29 percent of workflows already include AI agents. Those that do define it report 18 percent lower risk and 20 percent higher quality. Forty-six percent do not involve the HR chief when AI strategy is set and 60 percent of employees report skill erosion; named interviewees include HR leaders at Rabobank and Crédit Agricole. The findings are cross-sectional associations from a vendor-affiliated institute, and the accountability gap they measure is the one a supervisor asks about when an AI-assisted decision goes wrong.
IBM Institute for Business Value: Designing the Thinking Organization
Alibaba's commerce benchmark shows the best AI agent completing about 60 percent of real multi-step tasks. Media
PYMNTS reported on 18 September on CommerceAgentBench, a test by Alibaba in which 13 AI model families worked through 107 real commerce tasks, with a pass awarded only when automated checks succeeded. The best model, Claude Opus 5, passed 61.7 percent of tasks on Alibaba's own agent harness, 60.7 percent on a second and 56.1 percent on a third, averaging ten minutes per task. Failures clustered in long email threads, landed-cost calculation, contradictory documents and multi-leg shipping. The benchmark is designed and run by a single commercial party without independent replication. Its failure clusters are the long-document, contradictory-record work bank operations consist of, and a five-point swing between harnesses shows the surrounding software matters as much as the model.
PYMNTS: Commerce test shows where AI agents break down
Security
An AI-management certification is entering payments and banking, covering the management system rather than any model. Media
PYMNTS reported on 21 September that ISO/IEC 42001, the international standard for an AI management system, is moving into payments and banking. Financial Software and Systems, a payments technology supplier, and Axis Bank, an Indian bank, have obtained certification, the latter after an audit covering AI governance, risk management and project execution. The certificate attests to a management system within an audited scope and says nothing about any individual model's performance, and the evidence so far is two certifications reported second-hand. The article argues procurement could make the standard a practical benchmark for AI services sold to regulated financial institutions, as ISO 27001 became for information security. For a bank's third-party risk function, the useful question for a certified vendor becomes which systems its audited scope statement actually covers.
On the radar
- A critical flaw in Microsoft's Azure AI Foundry, its cloud platform for building AI applications and agents, let an attacker with no credentials gain elevated privileges, according to a 17 September National Vulnerability Database record. NIST National Vulnerability Database
- A critical flaw in the code sandbox of MCP Context Forge, an open-source gateway connecting AI assistants to company tools, let an unauthenticated attacker run system commands with the server's privileges, fixed in version 1.0.2. NIST National Vulnerability Database
- A high-severity defect in the PraisonAI agent framework ran tools before their approval check, so actions logged as rejected had already taken effect, fixed in version 1.7.2. NIST National Vulnerability Database
- Ant International announced nearly 100 AI products for payments, foreign exchange and treasury with rollout planned for autumn and winter, alongside the previously reported four-bank forecasting deployment and know-your-agent work with Visa and Mastercard. PYMNTS