AI Pulse Daily Brief logo

AI Pulse Daily Brief

Archives
Log in
Subscribe
October 5, 2026

AI Pulse Daily Brief | 2026-10-05

Reading time ~15 mins

France's banking supervisor says DORA and the AI Act are probably not enough for the most advanced AI models, and wants them released first to trusted partners. A US standards body, the UK regulator and a payments firm point to one missing control for AI agents that act for customers: their own identity, with authority that can be withdrawn. Société Générale's CEO calls AI's realised benefit minimal so far. ISO's first guidance on AI security threats is due this month, and an open AI model stripped of its safety refusals is now rented by the call. OpenAI moves into Microsoft's office territory, and two pieces by Nate B. Jones look at Microsoft's new agent and at how agents change software buying.

Perspectives

Nate B. Jones argues the agent an employer approves matters more than the smartest model, and Microsoft holds that ground Perspective

Microsoft is bringing Autopilot, an agent that holds an assignment over time instead of answering one prompt, into Microsoft 365. Nate B. Jones, an independent AI commentator who has used it, wrote on 2 October that Microsoft describes its forerunner as built on OpenClaw, the open-source agent many IT teams treated as a security risk this year. Microsoft gave it an identity IT departments can audit and sells it as enterprise software with a support contract. Nate B. Jones puts it bluntly: "Microsoft took the agent that was too dangerous to install." Microsoft's announcement of 25 September describes an agent with its own identity, memory and workspace that carries work across sessions. It is in expanded private preview.

His prediction rests on distribution, not model quality. Microsoft counted more than 450 million paid Microsoft 365 commercial seats in January and more than 30 million paid Copilot seats in July. He sets those against OpenAI's February figure of more than 9 million paying business users, while noting that the products and dates differ and not every seat pays for AI. Autopilot will still show up inside Excel, Outlook and Teams, through a vendor whose contracts, support and administration tools employers already know. "Microsoft is monetizing trust in Microsoft," Nate B. Jones says. He expects workplace AI to stay Microsoft-shaped in many firms unless a challenger gives them a compelling reason to change.

His hands-on verdict is that the agent is not especially intelligent, and that its value comes from the data it can reach. A company's customer records, access rights, named owners and recorded decisions let an agent work without the user rebuilding the business for it. Nate B. Jones says: "Instead of worrying about how smart it is, worry about what data it has access to." This brief carried his general version of that point on 30 September, and here he applies it to the agent many office staff are likely to be offered. When an answer is weak, he says, check what the tool could see before blaming the model, because the system may not be connected or the account may lack permission.

He also warns against judging cost by the model bill. Microsoft's automatic routing picks a model for each request, but the same words can describe an easy job or a hard one, and Microsoft has not disclosed everything its router uses to decide. Nate B. Jones says: "If a cheap model misses the customer commitment and you redo the briefing, the low model bill that IT gets does not capture the cost of what just happened." For work an agent repeats, he says the person delegating should set which accounts it checks, how often, what counts as a material change and when a person comes in. Nate B. Jones adds: "Be clear about whether it can contact anybody or only prepare a draft."

He states the strongest case against himself. A capable enough model may find a better way to do the job than producing today's reports faster. Claude already works inside Excel, PowerPoint and Word, so a company can keep its Microsoft files while staff hand the assignment to another vendor's agent, and Meta has launched its own enterprise platform. His figure that about 5% of staff get useful work out of AI is a number he says he has heard repeatedly, not a measurement.

This brief has reported OpenClaw's security failures three times this year: a privilege-escalation flaw with malicious add-ons in April, exposed installations in May, and hidden instructions that persisted in its memory in June. His post does not say which parts of OpenClaw carry into Autopilot. An agent that arrives through the existing Microsoft 365 contract can skip the review a new AI vendor would face, while it reaches whatever its identity is allowed to read. In a bank, whether such an agent only drafts or also contacts customers and colleagues is decided in its permissions.

Nate's Substack (By Nate B. Jones)

Nate B. Jones argues agents split bought software into data, screens and workflows, each needing its own decision Perspective

In an executive briefing published on 4 October, Nate B. Jones argues that a software subscription bundles three things: data, the screens people work in, and the workflows that turn information into action. As agents get better at finding, arranging and acting on information, those parts come apart. A team can stop using an application's screens and still depend on its records, approval rules and execution. It can build its own search process and still need someone else's data, or use one agent for one job and another for the next. In his reading, each part now needs its own decision to keep paying, build or drop.

His case is a recruiter, a real person he says he lightly anonymised. Her agent pulled candidate profiles from a data provider and drafted shortlists that she reviewed. She stopped opening the recruiting tool, while the data provider still got paid. Her manager had not realised how much was locked up between her AI, the data and the application until a change was discussed. The people using AI on a team, he concludes, are already making the company's software decisions, choosing which data matters, which steps they skip and which workflows they still trust.

That moves where the lock-in sits. Single-purpose tools are getting easier to leave, while the lessons a person has taught an agent live in a custom set-up, on one machine or in that agent's memory. Nate B. Jones says: "And the agent you trained on is getting much harder to leave." When the CTO or the finance team wants staff to switch AI vendor, everyone may be counting different costs, and he calls that the battle coming to teams in 2027.

He sorts the decision by what a business would lose. The Firm, a two-person recruiting business, built its own Claude skill on Crustdata's data instead of buying another packaged recruiting tool, and kept paying for the data. Where compliance and dependable execution are the product, the case for buying holds. Nate B. Jones says: "Getting an AI to explain a paycheck is a very, very different proposition from replacing the system that gets people paid." Being reachable by other companies' agents, as DoorDash made itself in a limited trial on 30 September, gets a vendor considered. Nate B. Jones adds that it "does not establish why someone ought to keep paying you."

The claim that agents erode bought software is not new, and his evidence is one anonymised case and vendors' own announcements. What he adds is the buyer's side: the dependency a renewal has to price may sit in staff's own agent set-ups rather than in the product being renewed. For subscribers, his post adds how a buyer can test which parts of an employee's agent set-up would survive a change of AI provider. A bank renewing its software estate for 2027 while choosing which AI assistant staff may use is making both decisions at once. Read beside his Autopilot piece above, the assistant an employer settles on also decides which of those staff set-ups carry over.

Nate's Substack (By Nate B. Jones)

Industry & competition

Société Générale's CEO says AI's realised benefit is still minimal, and warns token costs can offset staff savings. CxO voice

On 22 September this brief reported Société Générale's target of EUR 500 to 600 million in AI cost reductions by 2029, about EUR 350 million of it already built into the plan. Diginomica reported on 24 September what chief executive Slawomir Krupa told analysts about it. He said the AI impact already showing in revenue or costs is "a minimal figure if we're honest." He warned that AI firms already spend 10% to 15% of their costs on tokens, the units AI providers bill by. In his words, a firm could be "down 30% with your workforce, but you're also up 50% in your IT costs." He said the bank never claimed AI would cut its workforce by 30%. Group headcount is down 17% since the end of 2023, which Diginomica does not attribute to AI. He also asked whether a whole core banking system could now be rewritten with AI, a project banks have tried before and failed at, often losing EUR 500 million. The savings figures remain management forecasts. One of the largest AI savings targets a European bank has published now comes with its owner's statement that little of it is realised yet. His token warning puts the running cost of AI on the same page as the staff savings it is meant to fund.

Diginomica

Innovation

Nate B. Jones reads OpenAI's new agents and shared workspace as a move into Microsoft's office territory. Independent

At its DevDay developer conference, OpenAI launched Dots, agents that take on standing tasks and keep working in the background with their own cloud computer and memory. It also launched Space, a shared place where people and AI work together on documents, and Sol, a cheaper model. OpenAI says Sol comes close to its strongest model on selected tests at a fifth of the price. Nate B. Jones, an independent AI commentator, reviewed the launches on 3 October after using them himself. He reads them as one bet that more work, and the context behind it, stays inside ChatGPT. Nate B. Jones says of OpenAI: "They are building the future Microsoft Office competitor." OpenAI is also previewing specialist Dots for company workflows, and working with Microsoft to bring them under Microsoft's Agent 365 controls for managing agents. Nate B. Jones doubts most employers are ready: "It feels like space is essentially presupposing AI-native and AI-fluent organizations that I do not see very often outside the valley." The individual version of Dots is not yet available in the European Economic Area, the UK or Switzerland. Private chats and memories stay out of shared spaces, and on what people should carry across, Nate B. Jones says: "We don't have norms around it." A second vendor now sells the shared layer where staff and AI work together. Its agents can also be registered in the Microsoft controls an employer already uses to keep track of agents. What staff move from private AI chats into a shared space then becomes a data-handling choice with no settled practice.

Nate's Substack

Research

Three independent sources say AI agents acting for someone need their own identity and authority that can be withdrawn. Authority

The US National Institute of Standards and Technology (NIST) published on 29 September a summary of more than 600 responses to its paper on identity and permissions for AI agents. Most respondents want existing identity standards extended rather than a separate system built for agents. They ask for a distinct identity for each agent, tied to the person or service accountable for it, and short-lived access limited to one task. They also want a fixed rule check at every action, so the model's own reasoning never decides what it may do, because hidden instructions in content can steer it. NIST will test this first on agents inside a firm's software development, and only later on agents that customers own. The UK Financial Conduct Authority's Smart Data Accelerator published research the same day on the infrastructure behind open finance, where customers share their financial data with authorised third parties. It says that as AI services act for consumers and firms, this infrastructure may need to establish the service's identity, its authority and its permitted actions. Its next phase could test how a consumer's authority is delegated to an AI service, read across institutions and withdrawn, with no dates given. Tony Moroney shared the note on LinkedIn on 1 October. Equals Money, a UK payments firm, lets customers' AI tools read account data and make minor changes through its connection for AI assistants, but not instruct payments. Its chief operations and product officer, James Simcox, told SiliconANGLE on 29 September that passing an agent's identity between systems is unsolved. Cutting off an agent's access is still done by hand.

A standards body, a regulator and a firm that already runs customer-facing agents reached the same missing control from different directions. The FCA note reads PSD2, the EU payments law banks work under, as a model with no central point of trust. It asks whether legal access rights alone are enough for agents to work across banks. The login standards banks use under PSD2 were built for a customer granting an app access. The FCA asks what more they need when the requester is an AI service: who runs it and what it may do. This brief has carried Sokin letting customers' AI tools prepare payments behind human approval on 21 September, and HSBC opening account data to corporate clients' AI tools on 30 September. Equals Money stops before payments and names agent identity and manual cut-off as the gaps it still has. No reference design for customer-owned agents is due before NIST's later phase.

National Institute of Standards and Technology | Financial Conduct Authority via LinkedIn (shared by Tony Moroney) | SiliconANGLE

Security

France's banking supervisor says DORA and the AI Act are probably not enough for the most advanced AI models. Authority

Denis Beau, First Deputy Governor of the Banque de France and chair of the ACPR, France's banking supervisor, gave a speech on AI risk in Paris on 9 September. The Banque de France published it on 16 September. He said the most advanced AI systems can already find flaws in computer code, help design malicious software and industrialise the manipulation of staff into giving access. AI systems that banks connect to their processes, data and tools have become targets in their own right, he said. He said the current rules, the EU's Digital Operational Resilience Act (DORA) and the AI Act, are "probably not enough to face up to the risks posed by the most advanced models." The ACPR is pressing in international forums for the most powerful models to be released gradually. Access would at first go only to trusted partners, for example at G7 level, with independent testing capacity in Europe. He also said the ACPR will supervise high-risk AI systems from December 2027.

On 2 October this brief carried ECB President Christine Lagarde naming lost access to frontier models as a risk to the financial system. Within about three weeks, four authorities have put frontier-AI cyber capability on the supervisory agenda for EU finance. They are the Banque de France, the ECB President as chair of the European Systemic Risk Board, the European Banking Authority and the joint committee of the three EU financial supervisors. They differ on the remedy. The joint committee works through DORA's monitoring of outside suppliers, while Beau says the framework itself falls short. A release limited to trusted partners would decide which banks get the strongest models to test their own defences, and on what evidence. The speech is one supervisor's position and creates no new legal duty.

Banque de France

ISO lists its first international guidance on security threats to AI systems for publication this month. Institute

The International Organization for Standardization (ISO) lists ISO/IEC 27090 in its final publication stage, with a publication date of October 2026. The guidance covers how to identify, detect and reduce threats specific to AI across a system's life. Its examples include data poisoning, which corrupts the data a model learns from, and theft of the model itself. It also covers protecting training data, models and intellectual property. ISO says it complements ISO/IEC 27001 and 27002, the information-security standards banks already use as their control baseline. That includes risks when operational data is later used to update or retrain a model. It is guidance, not a standard a firm can be certified against. On its own it does not show that a high-risk AI system meets the AI Act's cybersecurity requirement, which European standards still being drafted will cover. Publication dates in ISO's catalogue can slip by a few weeks. A bank's security function now has an international reference for AI threats, written to fit the control set auditors already test. An auditor's question about AI security now has a named benchmark.

International Organization for Standardization (publication date unverified)

Maria Sukhareva notes that an open AI model stripped of its safety refusals is now rented by the call. Independent

In the third part of her series How Agents Hack, published on 1 October, Maria Sukhareva of the AI Realist newsletter turns to a report Anthropic released on 29 September. Anthropic tested GLM-5.3, a model whose weights anyone can download, after abliteration, a technique that strips out the refusals a model was trained to give. In Anthropic's chart, which she reproduces, the model's refusal rate on harmful requests fell from 95% to 6%. Its score on a test of cyber-attack skills moved only from 85% to 81%. Maria Sukhareva writes: "GLM-5.3 is publicly available, and several abliterated versions have been released that reduce its refusals while retaining capabilities that can be used for attacks." Maria Sukhareva adds: "You do not even need to buy powerful GPU hardware: Abliteration.ai offers a hosted, abliterated version of GLM-5.3, accessible through a playground or API." She reads the report as Anthropic positioning against open-weight rivals, yet concedes the risk it documents is real. The figures are one vendor's benchmark results on a competitor's model. Her series ran here as a Perspective on 28 September, and this part adds the measured cost of removing safeguards and the rented service. An attacker no longer needs special skills or hardware to use such a model, and no frontier vendor's misuse monitoring sees what it is used for. That widens the range of attackers a bank's cyber defences have to assume.

AI Realist

Don't miss what's next. Subscribe to AI Pulse Daily Brief:
← Newer AI Pulse Daily Brief | 2026-10-06 Older → AI Pulse Daily Brief | 2026-10-02
Powered by Buttondown, the easiest way to start and grow your newsletter.