According to some colour consultants, the familiar spring, summer, autumn and winter palettes can be divided into 16 seasonal types, giving a more nuanced reading of which colours suit you.

We have 16 stories in this week’s newsletter. That is the link. I appreciate it is doing very little.

Still, the idea of looking more closely at the shades does have some relevance. Put everything under the heading “AI” and you lose rather a lot of detail. A model preview, a bank’s identity-protection service, a supplier breach and a proposed $40bn chip-financing package each deserve a different reading.

Mistral is offering a preview of its next big model. Plaid is applying transaction-sequence AI to underwriting. Anthropic is investing in the people needed to get enterprise AI into production. Elsewhere, deepfake fraud, supplier dependencies and mounting patch volumes give us plenty of reasons to examine the less flattering shades.

Execution Level Governance- What audit-ready agent governance actually looks like
David Girvin, founder and CEO of Assury argues that model-in-the-loop review, AI governing AI, is fundamentally unreliable for regulated environments: even the best-performing models miss a meaningful share of violations, the reviewing model is typically provided by the same vendor being reviewed, and prompt injection or context poisoning can compromise both the acting agent and its supposed overseer simultaneously. He makes the case for deterministic, architecturally enforced controls instead, walking through Assury’s approach of autonomy zones, session risk accumulation, and credential starvation, which lets a compromised agent be cut off from its tools instantly rather than relying on time-boxed access. The conversation touches on why David is sceptical of just-in-time credentialing as a solution for agent security more broadly, since agent sessions don’t run on predictable human timescales, along with the current gap between how identity and security vendors are pitching agent protection and what he sees happening at the execution layer in practice. He also discusses the compliance and audit implications of probabilistic decision-making, arguing that regulated industries will increasingly need tamper-evident, hash-chained audit trails that can withstand scrutiny from auditors and regulators who are only beginning to understand agentic risk, and reflects on a named frontier lab’s own published framework as an example of the gap between research and practitioner reality. Elsewhere, David reflects candidly on building a bootstrapped security company in an increasingly crowded market, why he turned down aggressive VC funding to stay in control of the product, and what a credible third-party assessment of his own gateway would need to look like given that Assury sits directly in the execution path for every customer’s agents.

Then there are the permissions. IBM is previewing identities for individual agents, Apple plans tighter controls over access to private data, and the ICO is asking how organisations manage the data-protection risks of autonomous systems. The detail matters: who is acting, what they can access, what they are authorised to do and what evidence survives afterwards.

Those are the questions I want our AI-360 Research Notes and practitioner conversations to explore. I’ll provide the non-expert overview and ask the questions. Practitioners and vendors can bring the experience of what happens when these systems meet an actual business. The Research Notes will be live at the beginning of next week after I've got used to talking to myself on camera. Dates for webinars with actual subject matter experts will follow over the coming weeks. Expect a busy December is a fair hint.

Sixteen stories follow. Finding your ideal wardrobe remains somebody else’s department.

Execution Level Governance- What audit-ready agent governance actually looks like
David Girvin, founder and CEO of Assury argues that model-in-the-loop review, AI governing AI, is fundamentally unreliable for regulated environments: even the best-performing models miss a meaningful share of violations, the reviewing model is typically provided by the same vendor being reviewed, and prompt injection or context poisoning can compromise both the acting agent and its supposed overseer simultaneously. He makes the case for deterministic, architecturally enforced controls instead, walking through Assury’s approach of autonomy zones, session risk accumulation, and credential starvation, which lets a compromised agent be cut off from its tools instantly rather than relying on time-boxed access. The conversation touches on why David is sceptical of just-in-time credentialing as a solution for agent security more broadly, since agent sessions don’t run on predictable human timescales, along with the current gap between how identity and security vendors are pitching agent protection and what he sees happening at the execution layer in practice. He also discusses the compliance and audit implications of probabilistic decision-making, arguing that regulated industries will increasingly need tamper-evident, hash-chained audit trails that can withstand scrutiny from auditors and regulators who are only beginning to understand agentic risk, and reflects on a named frontier lab’s own published framework as an example of the gap between research and practitioner reality. Elsewhere, David reflects candidly on building a bootstrapped security company in an increasingly crowded market, why he turned down aggressive VC funding to stay in control of the product, and what a credible third-party assessment of his own gateway would need to look like given that Assury sits directly in the execution path for every customer’s agents.

Deepfake fraud exposes the control gaps between a company and its banks

Early Warning warns that deepfake-enabled corporate fraud can exploit fragmented controls across several banking relationships. A convincing supplier impersonation can become a fraudulent payment-instruction change, particularly where verification differs between channels. The useful question for treasury teams is how the company and its banks establish the intended recipient before money moves, and how quickly they can share evidence when something looks wrong.

ICO moves agentic AI into active data-protection supervision

The ICO has opened a six-week call for evidence on agentic AI and confirmed enquiries concerning reported incidents involving agents bypassing protections or accessing external systems. It also says ten major developers have made or committed to data-protection improvements following supervision. For organisations deploying agents, the message is clear: autonomy comes with continuing responsibilities for lawful data use, oversight and accountability.

Federal case study moves post-quantum security from inventory to production

Quantum XChange says an unnamed US federal agency has deployed its post-quantum security product across 15 production sites, using existing routers. The customer’s anonymity limits independent verification, but the case study raises a useful migration question: how much protection can organisations add before replacing their infrastructure? Buyers still need to establish coverage, failure behaviour and how the claimed cryptographic protections apply to their deployment.

Execution Level Governance- What audit-ready agent governance actually looks like
David Girvin, founder and CEO of Assury argues that model-in-the-loop review, AI governing AI, is fundamentally unreliable for regulated environments: even the best-performing models miss a meaningful share of violations, the reviewing model is typically provided by the same vendor being reviewed, and prompt injection or context poisoning can compromise both the acting agent and its supposed overseer simultaneously. He makes the case for deterministic, architecturally enforced controls instead, walking through Assury’s approach of autonomy zones, session risk accumulation, and credential starvation, which lets a compromised agent be cut off from its tools instantly rather than relying on time-boxed access. The conversation touches on why David is sceptical of just-in-time credentialing as a solution for agent security more broadly, since agent sessions don’t run on predictable human timescales, along with the current gap between how identity and security vendors are pitching agent protection and what he sees happening at the execution layer in practice. He also discusses the compliance and audit implications of probabilistic decision-making, arguing that regulated industries will increasingly need tamper-evident, hash-chained audit trails that can withstand scrutiny from auditors and regulators who are only beginning to understand agentic risk, and reflects on a named frontier lab’s own published framework as an example of the gap between research and practitioner reality. Elsewhere, David reflects candidly on building a bootstrapped security company in an increasingly crowded market, why he turned down aggressive VC funding to stay in control of the product, and what a credible third-party assessment of his own gateway would need to look like given that Assury sits directly in the execution path for every customer’s agents.

Microblink brings continuous identity intelligence to agent-led journeys

Microblink is expanding its identity platform around people and agents moving through digital services. Its reported 100% deepfake-detection result needs to be read within the conditions of the particular test. The wider issue deserves attention: identity assurance must continue as a journey progresses. Organisations need to establish who is acting, what they have been authorised to do and whether that authority remains valid.

U.S. Bank packages identity and privacy defence as a mainstream account service

U.S. Bank’s Protect 360 brings identity, privacy and credit monitoring into its app and online banking, with an Essentials tier for eligible customers and a paid Premium option. That puts broader identity protection inside the everyday banking relationship. Its effectiveness will depend partly on what follows an alert: whether customers understand the exposure and can take useful action.

EY breach shows how regulated data can escape through a supplier’s supplier

The Financial Times reports that a breach at EY exposed information connected to clients of Goldman Sachs’ wealth business, Man Group and Tishman Speyer. Goldman Sachs and Man Group said their own systems were not compromised. Sensitive information can still be exposed elsewhere in the service chain, making the live map of suppliers, sub-processors and their data access particularly important.

SpaceX’s reported $40bn chip financing makes AI infrastructure a credit-market story

Reuters, citing the Financial Times, reports that SpaceX is seeking $40bn in financing to buy Nvidia chips, with Apollo expected to lead the transaction. These are reported negotiations. For lenders, the proposed scale raises questions about utilisation, power availability, chip obsolescence and concentrated exposures across the AI industry. The infrastructure build-out is giving credit teams plenty to examine.

Execution Level Governance- What audit-ready agent governance actually looks like
David Girvin, founder and CEO of Assury argues that model-in-the-loop review, AI governing AI, is fundamentally unreliable for regulated environments: even the best-performing models miss a meaningful share of violations, the reviewing model is typically provided by the same vendor being reviewed, and prompt injection or context poisoning can compromise both the acting agent and its supposed overseer simultaneously. He makes the case for deterministic, architecturally enforced controls instead, walking through Assury’s approach of autonomy zones, session risk accumulation, and credential starvation, which lets a compromised agent be cut off from its tools instantly rather than relying on time-boxed access. The conversation touches on why David is sceptical of just-in-time credentialing as a solution for agent security more broadly, since agent sessions don’t run on predictable human timescales, along with the current gap between how identity and security vendors are pitching agent protection and what he sees happening at the execution layer in practice. He also discusses the compliance and audit implications of probabilistic decision-making, arguing that regulated industries will increasingly need tamper-evident, hash-chained audit trails that can withstand scrutiny from auditors and regulators who are only beginning to understand agentic risk, and reflects on a named frontier lab’s own published framework as an example of the gap between research and practitioner reality. Elsewhere, David reflects candidly on building a bootstrapped security company in an increasingly crowded market, why he turned down aggressive VC funding to stay in control of the product, and what a credible third-party assessment of his own gateway would need to look like given that Assury sits directly in the execution path for every customer’s agents.

Plaid brings transaction-sequence AI into cash-flow underwriting

Plaid’s LendScore 2 and LendScore Arc extend cash-flow underwriting, with Arc using a model that examines the sequence and context of transactions. Plaid also describes explainability and fair-lending controls, while its performance figures remain company claims. Lenders will need to assess how those results transfer to their customers and whether the reasons behind a credit decision remain understandable and defensible.

Mistral previews trillion-parameter Large 4

Mistral has opened a public preview of Large 4 and plans to release its weights later this month. It is positioning the model around enterprise work, European infrastructure and strong cyber capability. Self-deployment offers organisations more control over availability and operating policy. It also puts more responsibility for access, monitoring and safeguards into the hands of whoever runs the model.

Anthropic expands access to reduced-safeguard cyber capabilities for vetted defenders

Anthropic’s expanded Cyber Verification Program introduces tiered access for qualified security professionals, including accepted organisations undertaking authorised penetration testing and red-team work. The company wants legitimate defensive activity to encounter fewer blocks. That makes verification and continuing oversight central to the offer: who receives elevated capability, how their use is monitored and how access can be withdrawn.

Execution Level Governance- What audit-ready agent governance actually looks like
David Girvin, founder and CEO of Assury argues that model-in-the-loop review, AI governing AI, is fundamentally unreliable for regulated environments: even the best-performing models miss a meaningful share of violations, the reviewing model is typically provided by the same vendor being reviewed, and prompt injection or context poisoning can compromise both the acting agent and its supposed overseer simultaneously. He makes the case for deterministic, architecturally enforced controls instead, walking through Assury’s approach of autonomy zones, session risk accumulation, and credential starvation, which lets a compromised agent be cut off from its tools instantly rather than relying on time-boxed access. The conversation touches on why David is sceptical of just-in-time credentialing as a solution for agent security more broadly, since agent sessions don’t run on predictable human timescales, along with the current gap between how identity and security vendors are pitching agent protection and what he sees happening at the execution layer in practice. He also discusses the compliance and audit implications of probabilistic decision-making, arguing that regulated industries will increasingly need tamper-evident, hash-chained audit trails that can withstand scrutiny from auditors and regulators who are only beginning to understand agentic risk, and reflects on a named frontier lab’s own published framework as an example of the gap between research and practitioner reality. Elsewhere, David reflects candidly on building a bootstrapped security company in an increasingly crowded market, why he turned down aggressive VC funding to stay in control of the product, and what a credible third-party assessment of his own gateway would need to look like given that Assury sits directly in the execution path for every customer’s agents.

Microsoft tells CISOs to prepare for rising AI-driven patch volumes

Microsoft says September’s patch volume reached a record close to 1,000 and warns customers to expect substantially elevated volumes as AI expands vulnerability discovery. Finding more weaknesses creates a larger workload for validation, prioritisation, testing and deployment. Security leaders will need to examine whether their remediation capacity can keep pace, while maintaining the reliability of the services being patched.

IBM gives enterprise AI agents distinct identities across rival platforms

IBM is expanding third-party agent management in watsonx Orchestrate and previewing distinct agent identities connected to existing enterprise identity providers. Separating an agent’s identity from its builder or user should help organisations attribute actions and scope access. The next test is whether each identity is consistently tied to an accountable owner, an approved purpose and enforceable permissions throughout its work.

OpenAI begins rolling out text provenance signal for EU users

OpenAI’s textGrain adds a statistical signal to selected model outputs, with detector access restricted to approved experts. The company says the signal cannot establish authorship, ownership or accuracy, and editing can weaken detection. An absent signal also cannot establish that a human wrote the text. Those limits matter wherever provenance evidence might influence a fraud investigation, compliance assessment or employment decision.

Execution Level Governance- What audit-ready agent governance actually looks like
David Girvin, founder and CEO of Assury argues that model-in-the-loop review, AI governing AI, is fundamentally unreliable for regulated environments: even the best-performing models miss a meaningful share of violations, the reviewing model is typically provided by the same vendor being reviewed, and prompt injection or context poisoning can compromise both the acting agent and its supposed overseer simultaneously. He makes the case for deterministic, architecturally enforced controls instead, walking through Assury’s approach of autonomy zones, session risk accumulation, and credential starvation, which lets a compromised agent be cut off from its tools instantly rather than relying on time-boxed access. The conversation touches on why David is sceptical of just-in-time credentialing as a solution for agent security more broadly, since agent sessions don’t run on predictable human timescales, along with the current gap between how identity and security vendors are pitching agent protection and what he sees happening at the execution layer in practice. He also discusses the compliance and audit implications of probabilistic decision-making, arguing that regulated industries will increasingly need tamper-evident, hash-chained audit trails that can withstand scrutiny from auditors and regulators who are only beginning to understand agentic risk, and reflects on a named frontier lab’s own published framework as an example of the gap between research and practitioner reality. Elsewhere, David reflects candidly on building a bootstrapped security company in an increasingly crowded market, why he turned down aggressive VC funding to stay in control of the product, and what a credible third-party assessment of his own gateway would need to look like given that Assury sits directly in the execution path for every customer’s agents.

Anthropic commits $100 million to training engineers for enterprise AI deployment

Anthropic has committed $100m to Claude Frontier Academy, aiming to train 10,000 engineers by the end of 2027. Commonwealth Bank of Australia and Morgan Stanley are among the organisations in the first cohorts. The programme recognises how much deployment depends on people who understand the business.

Microsoft puts agent identity and data controls at the centre of cyber defence

Microsoft’s Digital Defense Report places agent identity, privileges and sensitive-data access among the central security concerns raised by AI. Its recommendations include tightly scoped access and stronger oversight of consequential actions. For financial institutions, reviewing the complete workflow matters: permission to read a customer record does not automatically authorise changing it or initiating a payment.

Apple plans tighter Mac permissions as autonomous agents increase privacy risks

Apple plans to tighten Full Disk Access permissions in macOS, citing the privacy risks from increasingly capable autonomous agents. It has not announced an implementation timetable. The proposal gives IT teams a reason to review applications that already hold broad access to files and communications. Users need to understand what they are granting, and organisations need a clear way to withdraw it.


Execution Level Governance- What audit-ready agent governance actually looks like
David Girvin, founder and CEO of Assury argues that model-in-the-loop review, AI governing AI, is fundamentally unreliable for regulated environments: even the best-performing models miss a meaningful share of violations, the reviewing model is typically provided by the same vendor being reviewed, and prompt injection or context poisoning can compromise both the acting agent and its supposed overseer simultaneously. He makes the case for deterministic, architecturally enforced controls instead, walking through Assury’s approach of autonomy zones, session risk accumulation, and credential starvation, which lets a compromised agent be cut off from its tools instantly rather than relying on time-boxed access. The conversation touches on why David is sceptical of just-in-time credentialing as a solution for agent security more broadly, since agent sessions don’t run on predictable human timescales, along with the current gap between how identity and security vendors are pitching agent protection and what he sees happening at the execution layer in practice. He also discusses the compliance and audit implications of probabilistic decision-making, arguing that regulated industries will increasingly need tamper-evident, hash-chained audit trails that can withstand scrutiny from auditors and regulators who are only beginning to understand agentic risk, and reflects on a named frontier lab’s own published framework as an example of the gap between research and practitioner reality. Elsewhere, David reflects candidly on building a bootstrapped security company in an increasingly crowded market, why he turned down aggressive VC funding to stay in control of the product, and what a credible third-party assessment of his own gateway would need to look like given that Assury sits directly in the execution path for every customer’s agents.
Share this post
The link has been copied!