Reuters reported on 12 September that Revolut disclosed sensitive customer information to an unauthorised party after fraudulent requests appeared to originate from a legitimate government-agency email domain. Revolut confirmed the incident and said it was cooperating with authorities. Reuters did not report this as a compromise of Revolut’s core banking systems.

The case is useful because it exposes a weakness between channel trust and authorisation. An apparently legitimate institutional channel can still carry a request from someone who is not entitled to receive the information. Proving where a communication appears to come from is not the same as proving the requester has legitimate authority.

That problem becomes more important as enterprises begin allowing AI agents to act through real credentials, APIs and institutional workflows. An agent may be correctly authenticated and still be compromised, incorrectly delegated or operating outside its mandate.

The Sovereign AI Reality Check- Governance, cost, and the limits of control
Carolyn Duby, Field CTO at Cloudera, joins Stewart Tinson for a candid look at what sovereign AI actually protects, and where the concept stops being useful. Carolyn frames sovereign AI as a risk mitigation strategy rather than a silver bullet: it reduces the exposure that comes from handing data to third parties, but it doesn’t replace insider threat monitoring, access controls, or offboarding discipline. She’s direct about the limits, pointing out that basic cyber hygiene has to be in place before sovereign infrastructure adds any real protection, and that a sovereign AI system is simply another piece of IT requiring the same auditing and monitoring as everything else. The conversation covers the practical trade-offs businesses face when moving off SaaS models onto owned infrastructure, including the cost predictability that comes with saturating owned GPUs versus the unpredictability of pay-as-you-go pricing. Carolyn also discusses model provenance and supply chain risk when downloading open source models, why guardrails have to be built around what a system should do rather than relying on a model’s built-in defaults, and Cloudera’s work on an AI gateway designed to route requests to the most appropriate model based on sensitivity, cost, and performance. She closes on the growing importance of data in motion for agentic and autonomous systems, arguing that stale context undermines decision quality just as much as poor governance of data at rest. Key takeaways: sovereign AI mitigates specific risks but doesn’t replace basic security hygiene, cost predictability often matters more than raw cost, and model choice increasingly depends on matching sensitivity and task to the right infrastructure.

Reuters later reported, citing the Financial Times, that attackers claiming responsibility threatened to sell customer records unless Revolut paid $3 million. Revolut told Reuters it had received no direct contact or demand from the group. Reuters also cited a source familiar with the matter saying roughly 680 customers were affected and that Revolut’s core infrastructure, databases and customer accounts were not hacked.

Those distinctions are important. Claims made by an attacker, facts confirmed by Revolut and information reported by Reuters from sources are different categories of evidence and should not be collapsed into one account.

For banks, the broader lesson is that trust should attach to authority, not merely to an apparently legitimate channel.


Garbage In, Garbage Faster: Why Agentic AI Exposes Your Organisational Debt
If Agentic AI follows your documented processes, what happens when those processes don’t reflect reality? Most organisations assume AI will figure things out. Business Architect Laura Van Weegen argues the opposite: AI doesn’t create new problems — it removes your ability to ignore the ones that have existed forever and a day. Undocumented workflows, undefined decision ownership, and human workarounds masking broken systems all get amplified at machine speed. You’ll learn: • Why “garbage in, garbage faster” is the real Agentic AI risk • The critical difference between feeding AI data versus information • How process debt compounds the same way technical debt does • Why exception handling is the new decision design priority • What one conversation reveals more than most AI readiness assessments • How to build explainability in from day one Key topics: Agentic AI readiness • Information architecture • Process debt • Data vs information • Contextual blindness • Decision ownership • Explainability vs traceability • Semantic infrastructure • Exception handling • Organisational accountability • Workflow documentation • AI governance Essential viewing for CISOs, CIOs, CFOs, and Chief Legal Officers evaluating Agentic AI deployment — before the human safety net disappears.
Share this post
The link has been copied!