AI Pulse Daily Brief | 2026-09-24
Reading time ~13 mins
EU supervisors name frontier AI as a cyber accelerant and route it through existing technology-dependency monitoring. The Dutch government signs an international call for mandatory pre-deployment testing of frontier models. A UK payments provider runs the first live account-to-account payment authorised inside an AI chat. BNP Paribas and Citi both publish AI operating-model detail without a defined benefit or adoption denominator. A bank pilot study and a board survey agree the missing piece is measurement, not capability. OpenAI proposes an industry template for disclosing models that misbehave, and a shared perspective argues AI readiness is now limited by power, hardware and validation capacity.
Regulatory
European supervisors put frontier AI inside their existing technology-dependency monitoring. Authority
The Joint Committee of the European Supervisory Authorities published its autumn risk update for the EU financial system on 23 September. It says frontier AI models can find and exploit software weaknesses at speed and scale, and that rapid AI advances could widen those vulnerabilities. The same report puts around 80% of bank respondents ranking technology service-provider dependencies as their largest external dependency, with payment-solution dependencies second at around 60%. Its recommendations ask supervisors to keep monitoring critical and concentrated provider dependencies through the joint oversight teams set up under the EU's Digital Operational Resilience Act (DORA), and to adopt AI-assisted security testing. No article number, threshold or deadline is attached, which places this on the bank's existing third-party dependency register rather than on its AI Act workstream.
Joint Committee of the European Supervisory Authorities
The Dutch government has signed an international call for mandatory safety testing of frontier AI models. Authority
Rijksoverheid published the joint international statement on 22 September 2026. Its signatories ask for transparent safety protocols, mandatory testing before a frontier model is deployed, independent evaluation with real access for the evaluators, and reporting of serious incidents. They also call for coordinated standards across countries and invite the United Nations to examine what international institutional support for AI safety would look like. The scope is frontier models, meaning the most capable general systems, rather than the narrower AI tools already running inside banks. The statement is nonbinding and creates no new Dutch legal obligation, yet a supplier's own government has now publicly endorsed evaluator access and incident reporting, previously a vendor's discretion.
Perspectives
A survey of 83 company directors finds boards renting AI capability rather than building it. Institute
INSEAD Knowledge published the findings on 10 September 2026, written by strategy professor Andrew Shipilov, who surveyed 83 directors at mostly large European and American firms during April and May. Just over a fifth of respondents came from finance. Close to half reported moderate productivity gains from generative AI, 18% reported significant or transformational impact and 11% had reduced headcount. Where AI had displaced tasks or roles, 57% named hiring AI-literate people as their main response and 40% named reskilling, against 16% prioritising job cuts. On capability, 54% said they rely on AI vendors and only 5% said they go it alone, which makes renting the peer default rather than a decision anyone made.
Physical bottlenecks now define AI readiness Perspective
Perspective: The durable argument in McKinsey's Technology Trends Outlook 2026 is that AI progress is no longer a screen-only story. The report connects agentic software, scientific discovery, robotics, chips, cybersecurity, energy, and space technologies into one system whose constraints are increasingly physical: reliable power, specialized hardware, skilled people, secure infrastructure, and the operating capacity to validate what machines produce. Its 14-trend framework is broad, but the useful editorial signal is the dependency between capability and readiness. Faster generation of code, drug candidates, or materials hypotheses does not remove the need for testing, clinical or laboratory validation, secure deployment, or accountable human judgment.
For a bank, that changes preparation from asking which AI tool to buy to asking which enabling conditions a material use case requires. Before scaling, decision owners should map the energy and compute assumptions, data and legacy-system dependencies, workforce skills, security exposure, validation steps, and escalation points that sit behind the proposed workflow. The report's treatment of adoption as a spectrum—from frontier innovation through experimentation, piloting, scaling, and full deployment—also supports a more disciplined investment posture. A use case can be strategically important while still needing bounded pilots, explicit evidence thresholds, and a named owner for exceptions. The practical choice is not whether to follow every trend, but which constraints must be monitored before a capability changes a customer, risk, or operational decision.
The report is analyst research rather than a bank-specific causal assessment, and it describes its metrics as directional indicators. Its investment comparisons include extrapolations and limitations, while adoption varies by technology and region. Those caveats improve the decision value: a bank should treat the report as a durable monitoring map, then test local assumptions against observed outcomes. Useful signals include infrastructure capacity, model and control performance, human overrides, workforce readiness, vulnerability response time, and whether pilots survive contact with legacy processes. The source's central lesson is therefore an operating-model one. AI readiness is demonstrated when technology, energy, security, talent, governance, and accountability can move together—and when the institution can slow, redirect, or stop a deployment whose evidence no longer supports the original decision. Source label: McKinsey Technology Trends Outlook 2026.
McKinsey Technology Trends Outlook 2026 via LinkedIn (shared by Tony Moroney)
Netherlands & Sovereignty
A Dutch poll puts frequent AI use at work at 45%, up from 8% in early 2024. Media
The trade title Computable reported a national opinion poll of about 6,000 Dutch respondents on 22 September. Frequent or intensive use of AI at work rose from 8% in January 2024 to 45% this month, while the share reporting no use at all fell from 55% to 28%. In the same poll, 62% expected AI to reduce employment, including 29% who expected substantially fewer jobs. No sampling detail is published, so the direction rather than the precise figure is the usable part. That direction matters now because works-council conversations this autumn will happen against a national mood in which most people already expect AI to cost jobs.
European employers say the EU cloud plan has a capacity target without a funding path. Corporate
The Employers' Group of the European Economic and Social Committee published its position on 23 September. It accepts the proposed Cloud and AI Development Act's goal of tripling EU data-centre capacity by 2030, then says the financing to reach it remains uncertain. The group asks for cloud and AI infrastructure to be a priority in the EU's next long-term budget, and for European added value to count for more in public procurement. Its sharpest point is that faster permits and grid connections will not help if electricity generation does not keep pace. Naming money and power rather than regulation as the binding constraints means non-EU hyperscaler dependence is likely to outlast the 2030 date in any exit plan built on it.
European Economic and Social Committee
A policy foundation says the EU cloud law forces buyers to choose between control and capability. Institute
Arq Foundation's submission to the European Commission's consultation on the Cloud and AI Development Act makes four arguments. The proposed data-centre acceleration zones speed up permits but give no fast path for grid connections, and do not remove physical power limits. The foundation wants grid infrastructure, flexible connection agreements and on-site generation brought inside the fast-track regime. It also argues the law's sovereignty assessment weighs foreign-access risk without weighing model capability, and that cross-country provider audits could delay approval at the higher assurance tiers. Those tiers may therefore favour self-hosted open-weight models, because providers under third-country control may not qualify, and the same control-against-capability trade-off sits inside the bank's own cloud and model choices.
Arq Foundation (publication date unverified)
Germany and the Netherlands are funding a 40 million euro contest to redesign AI chips. Media
Germany's Federal Agency for Breakthrough Innovation and the Netherlands' National Agency for Disruptive Innovation launched their first joint challenge on 23 September. It runs for 20 months with a total of 40 million euros, aimed at market-ready high-performance chips for training and running AI models. Seven teams can receive up to 2.6 million euros each at the first stage, three finalists up to 7 million euros, and applications close on 30 November 2026. The programme commits to no fabrication, production or purchase, and says only that promising designs may attract follow-on funding at manufacture. Nothing here changes a bank's compute plan this year, and the date that would is the first manufacturing decision roughly two years out.
Industry & competition
A UK payments provider has run the first live account-to-account payment authorised inside an AI chat. Vendor
GoCardless says a donor used an AI chat to pick a recurring monthly gift of 5, 10 or 15 pounds to the charity Trussell, and authorised the Direct Debit with their own bank details. The flow is live on the company's checkout and was built inside the Financial Conduct Authority's AI Live Testing programme, which GoCardless notes is a test environment and not a regulator's endorsement. The company also cites its own research that 64% of UK consumers would accept AI-managed recurring payments if they keep control of limits or final approval. The mandate, not the payment rail, is where control now sits, because the instruction was created in a third party's chat window rather than in a bank channel.
BNP Paribas has put AI at the centre of its 2030 plan and claims the top Eurozone position. Corporate
The bank's 23 September investor presentation places AI across all three divisions and describes a move from scattered initiatives to industrialised execution. Its operating model is listed as high-impact use cases, reusable shared platforms, cyber protection and AI committees chaired by the chief executive. BNP Paribas reports 100,000 people onboarded to its group AI assistant and cites an external AI benchmarking index for the claim of being the number-one Eurozone bank in AI. Average annual support-function savings are shown rising from about 700 million euros in the 2022 to 2026 period to about 1 billion in 2027 to 2030. AI is named as one lever among several, with no standalone AI contribution quantified, so an unquantified savings figure sits beside a ranking claim in any board comparison.
Citi reports its internal AI workspace reaching 180,000 staff with adoption above 87%. Corporate
A Citigroup feature published on 22 September says its internal AI workspace is available to more than 180,000 people across 87 countries and jurisdictions, with more than 65 million interactions since December 2024. The bank says controls across the AI lifecycle are automated at platform level and that a person remains in the loop, without publishing a control specification or an independent test of effectiveness. It describes a separate tool launched in April 2026 for deploying agents across business lines, with no deployment count or outcome measure. No denominator is given for the 87% adoption figure, which makes it a communications number rather than a performance one, and a peer ratio answered with an equally undefined ratio settles nothing.
Innovation
Anthropic cut its top model's list price by a fifth and made it available on all three big clouds. Vendor
Claude Opus 5.5 was announced on 22 September through Anthropic's own service and the Amazon, Google and Microsoft cloud marketplaces. Published rates are 4 US dollars per million input tokens, the billing unit for text, and 20 dollars per million output tokens, 20% below the previous model. Cached input reads, which dominate retrieval-heavy workloads, are priced at 20 cents per million. Anthropic says typical workload costs fall 40% and output is more than 30% faster, both vendor claims with no independent benchmark behind them. The verifiable number is the list price, and for a bank workload built on retrieval the cached-read rate rather than the headline rate is where the cost actually moves.
OpenAI says its voice agent platform handles seven million calls a month. Vendor
A 23 September customer page for the Ringg platform says it takes more than seven million connected calls a month and can settle up to 65% of routine enquiries without a human. The named users are an insurance marketplace handling 67% of calls without a person, a health platform reporting 85% first-call resolution, and an investment platform self-serving 72% of listing and derivatives queries. OpenAI says the health platform also cut costs by 70%, and that selected workloads on its newer model cost about 90% less than on the older one. None of the named customers is a bank. Every figure counts calls that did not reach a human, which is not the same as calls answered correctly, and deflection can rise while service quality falls.
Research
A bank pilot with strong scores concludes it cannot yet justify scaling. Institute
A preprint posted to arXiv on 18 September describes a generative-AI pilot run by the innovation function of an anonymised global systemically important bank, across control assessment, wholesale credit-memo drafting and procedure rewriting. Human graders scored one model at 88% citation precision, 99% capture of required elements and a 1.6% rate of invented content, against 76%, 96% and 3.2% for a second model. The authors then say their own results cannot support a scale decision, because sample sizes, confidence intervals and grader agreement were not recorded and graders were not always blind. That omission list is the usable output, since it names the evidence a bank would need before an AI drafting pilot becomes an approval.
European AI application start-ups now raise 44% of comparable US funding, up from 11% in 2018. Advisory
McKinsey and the European software network Boardwave published a 39-page study on 17 September, built on proprietary venture-funding analysis and more than 30 interviews. It puts European AI application start-ups at 44% of comparable US funding levels in the first half of 2026, and industry-specific start-ups at 67%, up from 11% and 9% in 2018. Across January 2025 to June 2026 it still puts North America at 71% of 835 billion euros of venture funding, against 10% for Europe. The argument is that Europe's advantage lies in deep integration with complex regulated workflows, and it names five scale practices including adoption-focused selling and value-based pricing. That thesis converts into a vendor test scoring demonstrated integration with systems of record rather than model benchmark results.
McKinsey & Company and Boardwave: Europe's new AI edge? The emerging application layer opportunity
Security
OpenAI has published a template for disclosing when one of its models behaves in ways it should not. Vendor
OpenAI published the framework on 16 September. It sets out three investigation tracks, chosen by how serious the behaviour is and how well it is already understood. Each full report follows a fixed structure covering what was observed, how severe it was, who outside the company was affected, what remains unanswered and what was changed in response. OpenAI says no industry-wide equivalent exists, invites other developers, standards bodies and regulators to help define more objective criteria, and notes that the framework does not replace legal disclosure duties. Because one supplier wrote it, its value to a bank is as a comparison template for what a frontier-model contract actually obliges that supplier to tell the bank.
On the radar
- Google has confirmed that its Gemini model reached systems at three real companies during commissioned security tests in May, after the test network was unintentionally connected to the internet; Google says the model stopped, the companies were notified and no damage was found. The Guardian
- Deutsche Bank's finance chief told an investor conference that a customer-facing AI tool launched at Postbank is being extended to the Deutsche Bank brand, and named transaction monitoring and credit underwriting as back-office AI areas, with no measured outcomes given. Investing.com