AI Pulse Daily Brief logo

AI Pulse Daily Brief

Archives
Log in
Subscribe
September 23, 2026

AI Pulse Daily Brief | 2026-09-23

Reading time ~11 mins

The ECB says more than 90% of the banks it supervises now use AI, and that accountability cannot be outsourced to a model or a vendor. The EBA finalised third-party risk guidelines for services outside technology, with a two-year transition. ING co-signed six-bank principles for payments authorised by AI agents, and Deutsche Bank put agents into live source-of-wealth checks. Brussels extended export controls to chipmaking equipment, and Europe's cybersecurity agency folded AI into dependency risk. OpenAI halved list prices on two new models. Five practitioner voices make the same argument from different angles: agent cost and reliability are set by workflow design and ownership, not by model quality.

Top signal

The ECB says more than 90% of the banks it supervises now use AI, and accountability cannot be outsourced. Authority

Claudia Buch, who chairs the European Central Bank's Supervisory Board, said in a 22 September keynote that more than 90% of banks the ECB directly supervises now use AI. She put generative AI use at 85%, and said 64% of those banks apply AI to fraud and cybercrime prevention. Buch said AI raises fraud, bias, cyber and outsourcing risks, and that AI agents make board-level governance and human judgement necessary. Accountability, she said, cannot be outsourced to a model or a third-party provider. ECB Banking Supervision separately said it asked banks over the summer to reassess their defences against cyber threats powered by the most capable AI models, and to submit concrete action plans.

Those summer submissions are being assessed horizontally, so one bank's action plan sits beside every peer's in the same supervisory review. The board's documented record of who owns AI accountability is already inside that file. The ECB has also now put a number on how ordinary supervised AI use has become, which removes "still early" as a description of where any European bank stands.

European Central Bank

Regulatory

The European Banking Authority finalised third-party risk guidelines covering services outside technology. Authority

The European Banking Authority published final guidelines on managing third-party risk for services outside information technology on 18 September 2026. They apply to arrangements supporting critical or important functions, and set lifecycle requirements across risk assessment, due diligence, contracting, subcontracting, monitoring, documentation and exit strategy. The EBA aligned them with the EU's Digital Operational Resilience Act (DORA) and took account of Basel Committee principles. It cited Article 74 of Directive 2013/36/EU as the legal basis, alongside PSD2, MiFID II and MiCAR, and set a two-year transitional period. Many AI and model services a bank buys sit outside technology outsourcing as it has been drawn until now, and this is the instrument that reaches them.

European Banking Authority

Perspectives

Ed Zitron argues headline AI capacity figures hide how little compute is actually usable. Skeptic

Zitron's 22 September essay separates three numbers that vendors and reporters routinely merge: total data-centre footprint, the share built for AI chips, and the share that is energised and running. He cites a report putting Microsoft's total capacity near 12 gigawatts, against roughly 2 gigawatts centred on AI-specific chips. A separate estimate puts the fleet at about 2.2 million chips backed by roughly $50 billion of hardware. Several figures are assembled from public reporting and his own estimates rather than from an audit. The distinction is usable in procurement, because installed, energised and contractually available capacity are three different commitments and a vendor's capacity headline answers none of them.

Where's Your Ed At

Enterprise AI is entering a phase of capital discipline, a software executive argues. Vendor

TechRadar published the piece on 16 September by Manuel Haug, who holds a senior technical role at the process-mining software company Celonis. He argues that the enterprise conversation is moving from experimentation, adoption and speed toward what value was created for the compute consumed. His recommendation is to tie compute spending to business outcomes such as efficiency, customer satisfaction or revenue, and to treat codified process knowledge as an asset that reduces repeated model work. He sells software that codifies process knowledge, so that half of the argument carries a commercial interest. Value per unit of compute is still a portfolio question a board can ask at the next review without buying anything.

TechRadar

A Microsoft product manager argues agent cost is set by workflow design, not token prices. Independent

Rod Trent, writing on 21 September on his personal Substack rather than a Microsoft channel, separates agent spend into model, orchestration, retrieval and side-effect costs. His argument is that retries, repeated context replay, sub-agent calls and tool invocations compound, so an estimate built from token prices misses most of what an agent actually consumes. He recommends budgets tied to successful outcomes, caps on loops and tool calls, model routing, sandboxing and graceful degradation. The metric that follows is cost per successful completion, and it is the one number showing whether an agent workflow is still cheaper than the deterministic automation it replaced.

Rod's Blog

Production agents fail on ownership and plumbing, not model quality, a practitioner review finds. Advisory

Jonathan Mast of White Beard Strategies published an analysis on 22 September naming five recurring causes of agent failure in production. They are state lost after a crash, no safe way to resume, expired credentials, unhandled rate limits and absent monitoring. He cites a LangChain survey of 1,340 professionals in which 57% reported agents in production while only 37% used online monitoring. A separate Cleanlab screen narrowed 1,837 respondents to 95 teams running live agents, fewer than a third of them satisfied with their observability, and he notes both samples are directional. Most agents in production therefore have nobody watching them, and in a customer or payment workflow a silent stop becomes a conduct problem long before anyone notices.

White Beard Strategies

Dutch founders say agent autonomy should be earned in stages, after a tester found access outlived its revocation. Corporate

An 18 September opinion column in Emerce by the two Dutch founders of an AI startup describes consumer AI moving from answering questions to executing tasks across email and calendars. They relay tester reports that one assistant kept information from a Gmail account after the connection had been cut. The same assistant sent an email without asking first, and could be steered by instructions hidden inside an incoming message. Their own experiment leaves about 95% of execution to the AI while humans keep decision responsibility, and they argue for task-scoped access, human approval at high-impact steps and visible agent actions. The stale-access finding is the one that travels, because access-control design assumes revocation takes effect immediately and here it did not.

Emerce

Netherlands & Sovereignty

KPN runs AI agents across five million service calls a year and reviews 100 of them daily. Media

The Dutch telecoms operator KPN uses a network of specialised AI agents for routine customer-service work, with people still handling sensitive cases. The programme runs on one central platform with response targets under two seconds, guardrails, automated and human testing, and a daily review of up to 100 real calls. KPN reports employee adoption above 86% and a customer-satisfaction score of 83, which it describes as comparable with human-handled calls, and aims for agents to take 10% to 20% of calls by 2027. Those outcomes are reported by KPN and its consulting partner, not independently audited. The daily call review is the part that transfers, because it is the control that makes a satisfaction-parity claim defensible at all.

Consultancy.eu

The European Commission extended EU export controls to chipmaking equipment and advanced computing chips. Authority

The Commission adopted a delegated regulation on 14 September updating Annex I of the EU Dual-Use Regulation, the list of goods that need a licence to export. The additions cover semiconductor manufacturing and testing equipment and materials, including tooling for inspecting the masks used in advanced chip printing, and single-wafer cleaning equipment. They also cover advanced-computing chips and the electronic assemblies built from them. The list must be published in the Official Journal and survive a two-month scrutiny period in the Council and Parliament before it takes effect. A bank is not the party that has to comply here, and the effect arrives as supplier lead times and licensing friction on AI infrastructure, one layer below where the bank buys.

European Commission

A Finnish AI cloud operator raised $189 million to build more than 250 megawatts of capacity. Vendor

Verda, headquartered in Helsinki, said on 22 September that an oversubscribed funding round raised $189 million, taking its total equity and debt above $450 million. It says capacity is live in Finland and that it will run more than 250 megawatts of operations during 2027, across Europe, the United Kingdom, the United States and Asia, on Nvidia hardware. MUFG Innovation Partners confirmed its investment and described the company as a European vertically integrated AI-cloud provider. What needs decomposing is the phrase European-rooted. Company jurisdiction, the physical location of the machines, the chip supply chain and where support staff sit are four separate questions, and this announcement answers them differently.

Verda

Industry & competition

ING has co-signed six-bank principles for payments authorised by AI agents. Corporate

Bank of America published the paper on 22 September on behalf of ASB Bank, Bank of America, Capital One, Commonwealth Bank of Australia, ING Group and NatWest Group. It sets out a control baseline for agentic commerce, meaning purchases and payments an AI agent carries out on a customer's behalf, organised around transparency, safety, privacy and data, choice, and interoperability. The text covers agent identity, delegated authority, auditable records of what the customer actually authorised, authentication, fraud, disputes and liability. It is voluntary, carries no timetable, and the authors say a follow-up paper will address protocols and standards. A direct Dutch peer has now put its name to a written definition of what a well-controlled agent payment looks like.

Bank of America

Deutsche Bank put AI agents into live source-of-wealth checks in Singapore and Hong Kong. Corporate

Deutsche Bank Private Bank announced on 22 September that an agent-based workflow for source-of-wealth checks went live during September in its Singapore and Hong Kong booking centres. Source-of-wealth checks are the part of know-your-customer work that establishes how a client's money was made. The workflow gathers research, assembles documentation and flags gaps or inconsistencies from client information and approved external sources, with an adviser reviewing before anything is decided. It is connected to the bank's digital know-your-customer process, a wider Private Bank rollout is planned, and the bank states that accountability stays with people. The deployment sits inside a regulated first-line control rather than a service channel, and the open question is what audit trail behind an agent's research would satisfy a supervisor.

Deutsche Bank Private Bank

Santander's AI lab argues small specialised models, not general assistants, fit regulated bank work. Corporate

Banco Santander published a summary on 24 July of a report by its AI Lab with the Spanish research foundation Fundación General CSIC. The report favours specialised or small language models for recurrent, document-heavy and regulated tasks, rather than general-purpose assistants. It proposes connecting those models to governed internal repositories at query time, instead of retraining a model on all internal knowledge. It names anti-money-laundering, fraud, know-your-business checks, document processing, model governance and supervised agents as priority areas, and links each to the EU AI Act, the Digital Operational Resilience Act, GDPR and network-security rules. The claim is testable rather than positional, because what it promises is traceability and control, and a tooling review can measure both.

Banco Santander

Innovation

OpenAI added two cheaper models at half the previous list price. Vendor

OpenAI announced GPT-6 Sol and GPT-6 Luna on 22 September as lower-cost additions to its GPT-6 family. It lists Sol at $2 per million input tokens and $10 per million output tokens, and Luna at $0.10 and $0.50 respectively. OpenAI puts both at 50% below the promotional prices it cites for its previous generation, a comparison that is vendor-stated rather than independently checked. Both are available through the programming interface and through the company's enterprise work and coding products. A halving of list price changes the arithmetic on workloads that were shelved on cost rather than on capability, and those business cases were built against the old number.

OpenAI

OpenAI reworked how repeated context is billed for long-running agents. Vendor

A second 22 September announcement covers prompt caching, the mechanism that stores the instructions and context an agent reuses on every turn so they are not charged in full each time. OpenAI says cached reads can attract discounts of up to 90%. The release adds a usage dashboard, diagnostics, explicit cache breakpoints, prewarming and the ability to change reasoning effort without losing the cache. It cites customers reporting 20% to 36% lower inference cost, figures supplied by the vendor and its customers rather than measured independently. Cache-hit rate becomes an architecture decision rather than an unavoidable cost line, and it raises a question a pricing note does not answer, which is what retained cached context means for data residency and retention.

OpenAI

Security

Europe's cybersecurity agency puts AI inside dependency risk rather than in a category of its own. Authority

The European Union Agency for Cybersecurity published the press release for its 2026 Threat Landscape on 22 September. The underlying analysis covers incidents from January to December 2025, drawn from open sources and anonymised data shared under a partnership with Microsoft. It says supply-chain and third-party attacks can produce large, high-impact incidents across dependent digital systems. It also says malicious groups increasingly use AI, and that building AI into a business widens the attack surface because the AI itself becomes a target. Treating AI as part of dependency risk puts it inside the third-party register that resilience rules already require, rather than in a separate AI control domain that no existing process owns.

European Union Agency for Cybersecurity

On the radar

  • A security firm disclosed a flaw on 17 September letting attackers silently run code through the plugin systems of four widely used AI coding assistants, with uneven patch coverage at disclosure. Air Security
  • A BNP Paribas Cardif survey of financial advisers, run with Kantar, reports AI use rising from 56% to 72% in a year. BNP Paribas Cardif
  • A practitioner discussion on enterprise AI governance argued that agent gateways should record denied actions as well as allowed ones, so a guardrail leaves evidence when it fires. SiliconANGLE

Don't miss what's next. Subscribe to AI Pulse Daily Brief:
← Newer AI Pulse Daily Brief | 2026-09-24 Older → AI Pulse Daily Brief | 2026-09-22
Powered by Buttondown, the easiest way to start and grow your newsletter.