According to some colour consultants, the familiar spring, summer, autumn and winter palettes can be divided into 16 seasonal types, giving a more nuanced reading of which colours suit you.
We have 16 stories in this week’s newsletter. That is the link. I appreciate it is doing very little.
Those are the questions I want our AI-360 Research Notes and practitioner conversations to explore. I’ll provide the non-expert overview and ask the questions. Practitioners and vendors can bring the experience of what happens when these systems meet an actual business. The Research Notes will be live at the beginning of next week after I've got used to talking to myself on camera. Dates for webinars with actual subject matter experts will follow over the coming weeks. Expect a busy December is a fair hint.
Early Warning warns that deepfake-enabled corporate fraud can exploit fragmented controls across several banking relationships. A convincing supplier impersonation can become a fraudulent payment-instruction change, particularly where verification differs between channels. The useful question for treasury teams is how the company and its banks establish the intended recipient before money moves, and how quickly they can share evidence when something looks wrong.
The ICO has opened a six-week call for evidence on agentic AI and confirmed enquiries concerning reported incidents involving agents bypassing protections or accessing external systems. It also says ten major developers have made or committed to data-protection improvements following supervision. For organisations deploying agents, the message is clear: autonomy comes with continuing responsibilities for lawful data use, oversight and accountability.
Quantum XChange says an unnamed US federal agency has deployed its post-quantum security product across 15 production sites, using existing routers. The customer’s anonymity limits independent verification, but the case study raises a useful migration question: how much protection can organisations add before replacing their infrastructure? Buyers still need to establish coverage, failure behaviour and how the claimed cryptographic protections apply to their deployment.
Microblink is expanding its identity platform around people and agents moving through digital services. Its reported 100% deepfake-detection result needs to be read within the conditions of the particular test. The wider issue deserves attention: identity assurance must continue as a journey progresses. Organisations need to establish who is acting, what they have been authorised to do and whether that authority remains valid.
U.S. Bank’s Protect 360 brings identity, privacy and credit monitoring into its app and online banking, with an Essentials tier for eligible customers and a paid Premium option. That puts broader identity protection inside the everyday banking relationship. Its effectiveness will depend partly on what follows an alert: whether customers understand the exposure and can take useful action.
The Financial Times reports that a breach at EY exposed information connected to clients of Goldman Sachs’ wealth business, Man Group and Tishman Speyer. Goldman Sachs and Man Group said their own systems were not compromised. Sensitive information can still be exposed elsewhere in the service chain, making the live map of suppliers, sub-processors and their data access particularly important.
Reuters, citing the Financial Times, reports that SpaceX is seeking $40bn in financing to buy Nvidia chips, with Apollo expected to lead the transaction. These are reported negotiations. For lenders, the proposed scale raises questions about utilisation, power availability, chip obsolescence and concentrated exposures across the AI industry. The infrastructure build-out is giving credit teams plenty to examine.
Plaid’s LendScore 2 and LendScore Arc extend cash-flow underwriting, with Arc using a model that examines the sequence and context of transactions. Plaid also describes explainability and fair-lending controls, while its performance figures remain company claims. Lenders will need to assess how those results transfer to their customers and whether the reasons behind a credit decision remain understandable and defensible.
Mistral has opened a public preview of Large 4 and plans to release its weights later this month. It is positioning the model around enterprise work, European infrastructure and strong cyber capability. Self-deployment offers organisations more control over availability and operating policy. It also puts more responsibility for access, monitoring and safeguards into the hands of whoever runs the model.
Anthropic’s expanded Cyber Verification Program introduces tiered access for qualified security professionals, including accepted organisations undertaking authorised penetration testing and red-team work. The company wants legitimate defensive activity to encounter fewer blocks. That makes verification and continuing oversight central to the offer: who receives elevated capability, how their use is monitored and how access can be withdrawn.
Microsoft says September’s patch volume reached a record close to 1,000 and warns customers to expect substantially elevated volumes as AI expands vulnerability discovery. Finding more weaknesses creates a larger workload for validation, prioritisation, testing and deployment. Security leaders will need to examine whether their remediation capacity can keep pace, while maintaining the reliability of the services being patched.
IBM is expanding third-party agent management in watsonx Orchestrate and previewing distinct agent identities connected to existing enterprise identity providers. Separating an agent’s identity from its builder or user should help organisations attribute actions and scope access. The next test is whether each identity is consistently tied to an accountable owner, an approved purpose and enforceable permissions throughout its work.
OpenAI’s textGrain adds a statistical signal to selected model outputs, with detector access restricted to approved experts. The company says the signal cannot establish authorship, ownership or accuracy, and editing can weaken detection. An absent signal also cannot establish that a human wrote the text. Those limits matter wherever provenance evidence might influence a fraud investigation, compliance assessment or employment decision.
Anthropic has committed $100m to Claude Frontier Academy, aiming to train 10,000 engineers by the end of 2027. Commonwealth Bank of Australia and Morgan Stanley are among the organisations in the first cohorts. The programme recognises how much deployment depends on people who understand the business.
Microsoft’s Digital Defense Report places agent identity, privileges and sensitive-data access among the central security concerns raised by AI. Its recommendations include tightly scoped access and stronger oversight of consequential actions. For financial institutions, reviewing the complete workflow matters: permission to read a customer record does not automatically authorise changing it or initiating a payment.
Apple plans to tighten Full Disk Access permissions in macOS, citing the privacy risks from increasingly capable autonomous agents. It has not announced an implementation timetable. The proposal gives IT teams a reason to review applications that already hold broad access to files and communications. Users need to understand what they are granting, and organisations need a clear way to withdraw it.