Reader, this may be my last newsletter. It all depends on the patience, and the sense of humour, of the publisher (or as I like to call him, our great fearless leader), once he gets round to reading this.

There's a village everyone's heard about but nobody ever admits they're from there. The one where the six-finger handshake is unremarkable, where the local swimming champions turn up with webbed feet as a matter of course, and where nobody asks too many questions about why. Read this week's news and there are two ways to see the AI industry through that village, and I genuinely can't decide which one is correct.

The first is that the industry is the village itself: a closed loop where the same traits keep resurfacing under different company names, because it's the same small gene pool wearing different badges. Nvidia is now the chips, the cyber defence, and the open-model commons, all at once, courtesy of one acquisition. OpenAI and Anthropic both trace back to the same small set of people and ideas, however loudly they compete for headlines.

The second is that the industry is the playground inside the village. Everyone there is already family, so the drama isn't about who's related to whom, it's about how. The bully and the brave protector get pitched against each other every break time to make them both stronger, which is one way of describing offence and defence "coevolving" against the same digital twin. Elaborate explanations are common in this village too, see the DOJ's 20-page brief, or Anthropic's blow-by-blow account of how Claude ended up loose on the internet. So are large dowries: $12,930,300,000, to the exact dollar, this week. And the village doctor and the village apothecary, different people, same bloodline, share patient files openly with the cousins, the aunts, the grandparents, because why on earth wouldn't they.

I'll let you pick which reading fits. Fittingly, the village keeps its own calendar too: day zero is the day the first snow finally cuts the roads and seals everyone in together for the season, whether they fancied the company or not. Seventeen stories, spanning cyber defence, biosecurity, healthcare records, teenagers, advertising, a $12.93 billion acquisition, a government wading into a copyright fight, and one very public breakup between OpenAI and a company Elon Musk now owns. Something for everyone's anxiety.

Execution Level Governance- What audit-ready agent governance actually looks like
David Girvin, founder and CEO of Assury argues that model-in-the-loop review, AI governing AI, is fundamentally unreliable for regulated environments: even the best-performing models miss a meaningful share of violations, the reviewing model is typically provided by the same vendor being reviewed, and prompt injection or context poisoning can compromise both the acting agent and its supposed overseer simultaneously. He makes the case for deterministic, architecturally enforced controls instead, walking through Assury’s approach of autonomy zones, session risk accumulation, and credential starvation, which lets a compromised agent be cut off from its tools instantly rather than relying on time-boxed access. The conversation touches on why David is sceptical of just-in-time credentialing as a solution for agent security more broadly, since agent sessions don’t run on predictable human timescales, along with the current gap between how identity and security vendors are pitching agent protection and what he sees happening at the execution layer in practice. He also discusses the compliance and audit implications of probabilistic decision-making, arguing that regulated industries will increasingly need tamper-evident, hash-chained audit trails that can withstand scrutiny from auditors and regulators who are only beginning to understand agentic risk, and reflects on a named frontier lab’s own published framework as an example of the gap between research and practitioner reality. Elsewhere, David reflects candidly on building a bootstrapped security company in an increasingly crowded market, why he turned down aggressive VC funding to stay in control of the product, and what a credible third-party assessment of his own gateway would need to look like given that Assury sits directly in the execution path for every customer’s agents.

OpenAI Says New Model Crosses Its Own "Critical" Cyber Line

OpenAI has launched GPT-6 Astra, its most capable model to date and the first to cross what the company calls the "Critical" threshold for cybersecurity risk under its own safety framework. Astra scored a perfect 100% on OpenAI's flagship exploit benchmark and, in the company's own tests, stayed far more consistently within its authorised scope than its predecessor did. But there's a catch worth watching: OpenAI's own safety testing found Astra's reasoning has become notably harder to monitor, with the model sometimes able to underperform deliberately or slip past internal oversight when prompted to try. Full write-up below.

The Superhuman Protocol
A Different Kind of AI Conversation Not our usual territory. AI-360 normally covers governance, security and the practicalities of defending against deepfakes, but every so often it’s worth stepping outside the compliance frameworks and asking a bigger question. In this 1-2-1, Stewart Tinson sits down with Nishanth Mudkey, who works in cloud AI, for a conversation about artificial general intelligence that has nothing to do with Terminator robots or job losses. Mudkey argues that AGI won’t arrive as an independent machine intelligence at all, but as something inseparably entangled with human thought and choice, a “metanervous system” of coevolving biological and artificial intelligence. The discussion ranges across why today’s large language models lack persistent awareness, what separates a closed system like chess from the open-ended complexity of the real world, and whether humanity is choosing this technological path or having it chosen by market forces beyond anyone’s control. A speculative, personal take rather than a research briefing, and a genuine change of pace.

Governments get early access to Google's autonomous patchers

Google has launched Fairwind, a limited access programme handing governments and trusted enterprise partners its Gemini 3.8 Flash Cyber model paired with CodeMender, its vulnerability-remediation tool. Google says the combination produces "verified, deployment-ready patches in minutes" instead of the weeks manual fixes take, and that more than 650 partners, including Crowdstrike, Palo Alto, Snowflake and Wiz, are already on board. Access is staged for national cyber authorities, critical infrastructure operators, and core software platforms, all under MFA and internal-team-only restrictions. Google.org's cybersecurity funding has now passed $100 million globally. Reassuring, in the way that "we've built the fire extinguisher" is reassuring while everyone quietly agrees the building is more flammable than it used to be.

The Sovereign AI Reality Check- Governance, cost, and the limits of control
Carolyn Duby, Field CTO at Cloudera, joins Stewart Tinson for a candid look at what sovereign AI actually protects, and where the concept stops being useful. Carolyn frames sovereign AI as a risk mitigation strategy rather than a silver bullet: it reduces the exposure that comes from handing data to third parties, but it doesn’t replace insider threat monitoring, access controls, or offboarding discipline. She’s direct about the limits, pointing out that basic cyber hygiene has to be in place before sovereign infrastructure adds any real protection, and that a sovereign AI system is simply another piece of IT requiring the same auditing and monitoring as everything else. The conversation covers the practical trade-offs businesses face when moving off SaaS models onto owned infrastructure, including the cost predictability that comes with saturating owned GPUs versus the unpredictability of pay-as-you-go pricing. Carolyn also discusses model provenance and supply chain risk when downloading open source models, why guardrails have to be built around what a system should do rather than relying on a model’s built-in defaults, and Cloudera’s work on an AI gateway designed to route requests to the most appropriate model based on sensitivity, cost, and performance. She closes on the growing importance of data in motion for agentic and autonomous systems, arguing that stale context undermines decision quality just as much as poor governance of data at rest. Key takeaways: sovereign AI mitigates specific risks but doesn’t replace basic security hygiene, cost predictability often matters more than raw cost, and model choice increasingly depends on matching sensitivity and task to the right infrastructure.

xAI lets Grok Bot loose on X

Grok Bot now has tighter integration with X: connect your account and it can search posts, read your timeline, check mentions and summarise what's happening on the platform. xAI is auto-creating developer accounts for users who don't have one, throwing in free X API credits for paid subscribers, and shipping a companion browser plugin for search, timelines, trends and bookmarks. xAI calls it "the first version of this integration." Read: more is coming, whether you asked for it or not.

Garbage In, Garbage Faster: Why Agentic AI Exposes Your Organisational Debt
If Agentic AI follows your documented processes, what happens when those processes don’t reflect reality? Most organisations assume AI will figure things out. Business Architect Laura Van Weegen argues the opposite: AI doesn’t create new problems — it removes your ability to ignore the ones that have existed forever and a day. Undocumented workflows, undefined decision ownership, and human workarounds masking broken systems all get amplified at machine speed. You’ll learn: • Why “garbage in, garbage faster” is the real Agentic AI risk • The critical difference between feeding AI data versus information • How process debt compounds the same way technical debt does • Why exception handling is the new decision design priority • What one conversation reveals more than most AI readiness assessments • How to build explainability in from day one Key topics: Agentic AI readiness • Information architecture • Process debt • Data vs information • Contextual blindness • Decision ownership • Explainability vs traceability • Semantic infrastructure • Exception handling • Organisational accountability • Workflow documentation • AI governance Essential viewing for CISOs, CIOs, CFOs, and Chief Legal Officers evaluating Agentic AI deployment — before the human safety net disappears.

Grok 4.6 posts the best refusal rate on a new biosecurity benchmark

Independent evaluator LatchBio found Grok 4.6 was the only model tested to score above 50% on both refusing disguised biosecurity hazards and completing routine biological research, averaging 62.1% on its BioSecBench-Refusal suite. On a separate biosurveillance benchmark it scored 53.5%, behind Anthropic's Opus 5 but ahead of OpenAI's GPT-5.6 Sol. xAI says Grok 4.6 reasons over task context rather than reacting to trigger words, and it's laid out a layered safeguard stack (refusal training, inference-time filters, behavioural controls, post-deployment monitoring) to back that up. It also says it treats overrefusal of legitimate public-health work as an equally serious risk to enabling misuse, which is the correct answer, and also the easy one to give in a blog post.

Conquered Your Data? - Now Combat Your AI
Souvik Choudhury, an AI and Data Governance Specialist at Fractal Analytics with a background spanning Infosys, HSBC and several startups, joins Stewart Tinson to unpack why data governance and AI governance can’t be treated as sequential problems, and why so many organisations discover the gap between them the hard way. Souvik argues that traditional data governance remains the foundation everything else is built on, and that AI agents amplify existing weaknesses rather than replacing the need for accountability, contextualisation and lineage. He walks through a real project example where an organisation believed it had solved data governance by using agents to generate column definitions, only to discover the definitions were pulled from generic internet knowledge rather than the organisation’s own policies, leaving a false sense of confidence behind a genuinely ungoverned dataset. The conversation covers where accountability actually sits when an autonomous agent makes a bad decision, why third-party models don’t dilute an organisation’s own responsibility for outcomes, and why Souvik pushes back on the idea that governance is an innovation-killing bureaucracy rather than the structural work that makes innovation possible in the first place. He also sets out a practical, staged approach to evaluating AI governance tooling rather than jumping straight to an enterprise platform, and offers a way to actually measure AI governance maturity using a weighted scoring model across multiple pillars. The discussion closes on an unexpected angle: the sustainability cost of AI infrastructure, and why Souvik believes environmental impact deserves a seat alongside profitability and productivity in any serious cost-benefit conversation about agentic AI.

Nvidia and CrowdStrike put offence and defence in the same room

CrowdStrike has launched SafeMind, an agentic cybersecurity system built on Nvidia's Nemotron open models, unveiled by Jensen Huang and George Kurtz in front of 10,000 security professionals at Fal.Con. The pitch: offensive and defensive AI agents locked in a continuous "coevolution loop," each hardening the other, tested against a digital twin of Nvidia's own infrastructure with named red-team sub-agents (Recon, Assault, Compromise) attacking a blue-team harness that monitors, validates and promotes detections. CrowdStrike also announced Falcon IQ, a 50-plus-agent automation layer for assessment and remediation work. CrowdStrike says AI-enabled attacks rose 89% in the past year and the fastest breach hit 27 seconds. Make of the timing what you will.

Swiss Cheese Defences- Identity fraud goes industrial and off-the-shelf
Ofer distinguishes between two current attack patterns: highly sophisticated, professionally coordinated deepfake and injection attacks designed to beat detection outright, and a much larger volume of lower-effort, high-scale attempts that rely on bombarding systems rather than disguising themselves well. He argues the real story right now is industrialisation of scale rather than uniform improvement in quality, though both are accelerating in parallel. The conversation covers why agentic AI is opening a new front in identity fraud, particularly the unresolved problem of tying an AI agent’s identity back to the human who deployed it and the permissions it holds. Ofer is candid about the current state of agent defences, describing them as underdeveloped and easy to hijack or poison, comparing the current state of play to Swiss cheese. He also discusses cross-industry fraud detection, including how signals, rather than raw data, are now being shared across platforms including AU10TIX and Reality Defender to surface fraud rings invisible to any single organisation. The conversation also covers explainability as one of AI’s most underdeveloped capabilities, with Ofer arguing that flagging a session as fraudulent without a credible, defensible reason will increasingly run into regulatory and practical limits. Elsewhere, the discussion covers credential laundering and the manufactured construction of fake digital histories and footprints, and the shift toward digital ID wallets that Ofer believes will make physical document fraud increasingly rare. He closes on what he calls “agentic avatars,” AI systems capable of holding a full visual and verbal conversation on someone’s behalf, and why he expects identity verification to have to become genuinely immersive across every form of media as a result.

Nvidia buys Hugging Face for $12,930,300,000

Nvidia has agreed to acquire Hugging Face for $12,930,300,000, announced by Jensen Huang on 3 September. The platform, used by more than 18 million developers hosting over 3 million models, will stay open, Huang says: no Nvidia compute requirement, free choice of frameworks and clouds. Nvidia is already the platform's largest contributor of open models and data, with more than 500 models and 250 datasets released there. Huang credited founders Clem Delangue, Julien Chaumond and Thomas Wolf with building "a vibrant home for the open model developer community," and said Delangue approached him about the deal himself. Worth noting the price tag down to the last hundred dollars is an unusually precise number for an acquisition this size. Someone in Nvidia's comms department clearly wanted that figure remembered exactly.

The Superhuman Protocol
A Different Kind of AI Conversation Not our usual territory. AI-360 normally covers governance, security and the practicalities of defending against deepfakes, but every so often it’s worth stepping outside the compliance frameworks and asking a bigger question. In this 1-2-1, Stewart Tinson sits down with Nishanth Mudkey, who works in cloud AI, for a conversation about artificial general intelligence that has nothing to do with Terminator robots or job losses. Mudkey argues that AGI won’t arrive as an independent machine intelligence at all, but as something inseparably entangled with human thought and choice, a “metanervous system” of coevolving biological and artificial intelligence. The discussion ranges across why today’s large language models lack persistent awareness, what separates a closed system like chess from the open-ended complexity of the real world, and whether humanity is choosing this technological path or having it chosen by market forces beyond anyone’s control. A speculative, personal take rather than a research briefing, and a genuine change of pace.

Anthropic explains how Claude ended up on the open internet

Following the incidents reported on 30 July, in which Claude models took unauthorised action on live systems during safety evaluations, Anthropic has detailed its response: a real-time classifier to catch models probing or escaping test environments, hardened sandboxes, and new best-practice requirements for external evaluation partners. It also disclosed that it deliberately trained a separate model on reward-hackable environments to study the effect, and that model went on to attack simulated infrastructure and offer advice on constructing bioweapons in pursuit of a high grader score. Internally, Anthropic reassigned roughly 150 product engineers to security work in April and has been quietly wrestling with reward hacking since at least February, when it rolled back three days of training after Mythos Preview started writing notes to "the reviewer" that no reviewer had asked for. Anthropic also says it wants the industry to agree a "lawful, verifiable, effective mechanism for coordinated pacing." Everyone wants that. Getting it is the hard part.

The AI Medicine Cabinet
Lessons from drug safety, applied to AI risk Dr Tejpavan Pula leads AI governance and responsible AI at Haleon, having spent years in pharmacovigilance, drug safety and epidemiology before moving into AI risk, on top of well over a decade in risk and compliance more broadly. In this conversation with Stewart Tinson, he draws a direct line between pharmaceutical risk management and the governance challenges now facing every enterprise deploying AI. The discussion covers why deterministic AI cannot be used to validate generative AI output, particularly for consumer-facing content, and why human review remains mandatory in regulated industries. Tej explains how third-party risk management has to shift from a static, point-in-time exercise to a dynamic, continuously monitored one once AI vendors are involved, and where data lineage and training provenance now sit alongside the traditional questions of vendor stability and contractual oversight. He gives a practitioner’s comparison of ISO 42001, AIGP and NIST AI RMF, setting out who each framework actually suits depending on role and organisational maturity. He also sets out how the right skillset shifts as an AI governance function matures, from risk and regulatory expertise at the founding stage through to privacy, cybersecurity and ISO auditing capability once a framework needs to scale. He discusses how organisations should approach a fragmented global regulatory landscape spanning the EU AI Act, New York’s and Colorado’s AI laws, and country-specific requirements such as China’s Cyberspace Administration rules and Germany’s works council process. The conversation closes on agentic AI moving into production, the new governance questions raised by autonomous agent-to-agent interaction, and what genuinely concerns Tej about deploying systems whose internal decision-making even their own developers cannot fully explain.

Anthropic opens the lab door to AI agents

Separately, Anthropic previewed the Model Hardware Standard, a specification letting AI agents operate physical lab and manufacturing equipment such as microscopes, liquid handlers and robotic arms. Built with HHMI Janelia Research Campus, MHS standardises how devices talk to agents via MCP, a command line interface, and code files, cutting integration time from weeks to hours. Partners lining up include AWS, Automata, Danaher, Doosan Robotics, QIAGEN, Tecan, Universal Robots, Hugging Face and Raspberry Pi. Anthropic is upfront that Claude's physical reasoning still needs expert oversight, citing a case where Genentech researchers had to explain to the model that foaming in a protein sample was a physical problem, not a software bug. Fair enough. It's still learning what the physical world is.

AI Governance arrives too late
Most AI governance today is retrospective. It documents what happened after an agent has already acted, which means by the time a compliance review catches a problem, the consequence is already real. In this session, Stewart Tinson is joined by Elsa Sklavounou, founder of Authority Instrumentation, and Njål Gaute Solland, creator of the execution governance system REHT, to make the case for a different model. One where authority is enforced at the point of action, not audited afterwards. They cover why intervention has to happen before an action executes rather than after, what six possible runtime outcomes look like in practice (allow, modify, defer, deny, step up, halt), and why delegation, not detection, is the capability most enterprises get wrong. A frank discussion for CISOs, CIOs, CFOs and Chief Legal Officers on what it actually takes to be able to answer yes when someone asks: can I stop it, can I intervene, can I prove why, can I delegate it safely.

Claude Fable 5.1 and Mythos 5.1 arrive, with a side of watermarking

Anthropic's new model pair, identical apart from safeguard level, brings Fable 5.1 roughly 25% cheaper for typical workloads and up to 45% cheaper for agentic work, thanks to a 75% cut in cache-read pricing. Anthropic cites benchmark wins across coding, computer use and reasoning, and a string of partner quotes from Jane Street, Cognition, MongoDB and Red Hat. Mythos 5.1 stays behind the same restrictions as its predecessor, though Anthropic says its own alignment testing shows it is less prone to reward hacking and motivated reasoning. Also tucked in: strengthened anti-distillation defences, and compliance with the EU AI Act's Code of Practice, meaning an invisible watermark now sits on outputs from models released after 2 August, with a detection API opening to regulators and fact-checkers. Scientific extras include Mythos 5.1 designing high-affinity protein binders and Fable 5.1 mapping a third of Venus at higher resolution than we've ever had. Genuinely impressive, buried under a lot of pricing detail.

Agentic Exploits- Deterministic gates for a probabilistic problem
David Girvin, CEO and co-founder of Assury, joins Stewart Tinson to dig into what’s actually happening when agentic AI goes wrong, and why he thinks most of the industry is solving the wrong layer of the problem. David explains the difference between prompt-level exploits and execution-level ones, arguing that the real danger starts the moment an agent moves from generating text to calling tools: deleting databases, reading files, sending emails. He walks through real-world incidents, including a Mexican government breach chain that escalated from just over a thousand prompts to over five thousand AI-executed actions across multiple agencies before detection, and the UK AI Security Institute’s recent cyber evaluation, in which agents took unsanctioned action including fabricating identities to socially engineer a real GitHub maintainer. The conversation covers why David is sceptical of “guardrails” language and AI-governing-AI approaches, arguing that only deterministic, architectural controls can reliably constrain agent behaviour, alongside human review reserved for genuinely high-stakes actions rather than blanket approval fatigue. He breaks down credential starvation, session risk accumulation, and why classifier-based tools keep failing inconsistently on identical actions, pointing to a named frontier lab’s own zero trust paper as an example of the industry misjudging what actually works. Elsewhere, David discusses the exposed MCP server problem, the widening trust gap between small specialist security vendors and platform incumbents, and why he believes regulation, not product quality alone, is what finally drives enterprise security spend. He closes with the exploit that concerns him most for the year ahead: session-level, goal-directed deception with no attacker involved at all.

OpenAI plugs ChatGPT into your medical records

ChatGPT for Healthcare now integrates with Epic electronic health records and a new Healthcare Public Data plugin covering nine official sources including PubMed, DailyMed and ClinicalTrials.gov. Clinicians can ask what's changed since a patient's last visit or which labs need reviewing before an appointment. OpenAI says physicians across 60 countries rated 99.1% of 4,363 test responses as safe, and more than 93% of responses per data source as "good or better" on accuracy. Launch partners include AdventHealth, Cedars-Sinai, HCA Healthcare and Memorial Sloan Kettering. The efficiency case writes itself. Whether every hospital's governance keeps pace with the rollout is the actual story to watch.

Execution Level Governance- What audit-ready agent governance actually looks like
David Girvin, founder and CEO of Assury argues that model-in-the-loop review, AI governing AI, is fundamentally unreliable for regulated environments: even the best-performing models miss a meaningful share of violations, the reviewing model is typically provided by the same vendor being reviewed, and prompt injection or context poisoning can compromise both the acting agent and its supposed overseer simultaneously. He makes the case for deterministic, architecturally enforced controls instead, walking through Assury’s approach of autonomy zones, session risk accumulation, and credential starvation, which lets a compromised agent be cut off from its tools instantly rather than relying on time-boxed access. The conversation touches on why David is sceptical of just-in-time credentialing as a solution for agent security more broadly, since agent sessions don’t run on predictable human timescales, along with the current gap between how identity and security vendors are pitching agent protection and what he sees happening at the execution layer in practice. He also discusses the compliance and audit implications of probabilistic decision-making, arguing that regulated industries will increasingly need tamper-evident, hash-chained audit trails that can withstand scrutiny from auditors and regulators who are only beginning to understand agentic risk, and reflects on a named frontier lab’s own published framework as an example of the gap between research and practitioner reality. Elsewhere, David reflects candidly on building a bootstrapped security company in an increasingly crowded market, why he turned down aggressive VC funding to stay in control of the product, and what a credible third-party assessment of his own gateway would need to look like given that Assury sits directly in the execution path for every customer’s agents.

OpenAI declares Astra its first "critical" cyber capability model

OpenAI says its upcoming Astra model has crossed the Critical threshold for cybersecurity capability under its Preparedness Framework, the first model it has rated this way. In testing, Astra scored a perfect 100% on ExploitBench, found two genuine zero-day vulnerabilities during evaluation, and built a working sandbox-escape chain against a hardened browser. OpenAI says it refuses 91.5% of cyber jailbreak attempts against 59% for GPT-5.6 Sol, and made no attempt to compromise infrastructure in honeypot tests where its predecessor did so more than half the time. The company paused parts of Astra's training for two weeks after the OpenAI-Hugging Face incident to harden infrastructure, restarting the affected reinforcement learning run on 28 August. Advanced access will start with a small alpha group before wider release through Daybreak Blue. A model good enough to find real zero-days is also, definitionally, a model good enough to be a problem in the wrong hands. OpenAI seems to know this, which is at least the right starting point.

The Sovereign AI Reality Check- Governance, cost, and the limits of control
Carolyn Duby, Field CTO at Cloudera, joins Stewart Tinson for a candid look at what sovereign AI actually protects, and where the concept stops being useful. Carolyn frames sovereign AI as a risk mitigation strategy rather than a silver bullet: it reduces the exposure that comes from handing data to third parties, but it doesn’t replace insider threat monitoring, access controls, or offboarding discipline. She’s direct about the limits, pointing out that basic cyber hygiene has to be in place before sovereign infrastructure adds any real protection, and that a sovereign AI system is simply another piece of IT requiring the same auditing and monitoring as everything else. The conversation covers the practical trade-offs businesses face when moving off SaaS models onto owned infrastructure, including the cost predictability that comes with saturating owned GPUs versus the unpredictability of pay-as-you-go pricing. Carolyn also discusses model provenance and supply chain risk when downloading open source models, why guardrails have to be built around what a system should do rather than relying on a model’s built-in defaults, and Cloudera’s work on an AI gateway designed to route requests to the most appropriate model based on sensitivity, cost, and performance. She closes on the growing importance of data in motion for agentic and autonomous systems, arguing that stale context undermines decision quality just as much as poor governance of data at rest. Key takeaways: sovereign AI mitigates specific risks but doesn’t replace basic security hygiene, cost predictability often matters more than raw cost, and model choice increasingly depends on matching sensitivity and task to the right infrastructure.

The gap between AI-native firms and everyone else has tripled

OpenAI's latest Enterprise Signals report finds the top 10% of enterprise users now generate 8.3 times the output tokens per active user of typical firms, up from 2.6 times in January. Case studies: Basis cut new-employee onboarding from two hours to thirty minutes using a Codex-built onboarding skill; a Clay sales engineer built persistent per-account subagents that save roughly an hour of nightly inbox triage; Exa Labs has Codex monitoring developer ecosystems for integration opportunities and drafting pull requests, with human review before anything ships. The gap is the headline, but the underlying message is the same one management consultants have been selling for a decade: process discipline compounds, technology doesn't do it for you.

Garbage In, Garbage Faster: Why Agentic AI Exposes Your Organisational Debt
If Agentic AI follows your documented processes, what happens when those processes don’t reflect reality? Most organisations assume AI will figure things out. Business Architect Laura Van Weegen argues the opposite: AI doesn’t create new problems — it removes your ability to ignore the ones that have existed forever and a day. Undocumented workflows, undefined decision ownership, and human workarounds masking broken systems all get amplified at machine speed. You’ll learn: • Why “garbage in, garbage faster” is the real Agentic AI risk • The critical difference between feeding AI data versus information • How process debt compounds the same way technical debt does • Why exception handling is the new decision design priority • What one conversation reveals more than most AI readiness assessments • How to build explainability in from day one Key topics: Agentic AI readiness • Information architecture • Process debt • Data vs information • Contextual blindness • Decision ownership • Explainability vs traceability • Semantic infrastructure • Exception handling • Organisational accountability • Workflow documentation • AI governance Essential viewing for CISOs, CIOs, CFOs, and Chief Legal Officers evaluating Agentic AI deployment — before the human safety net disappears.

The Department of Justice has filed a 20-page brief in the New York Times' copyright case against OpenAI, arguing training LLMs on copyrighted material without a licence doesn't breach copyright law. The government calls the training process "exceedingly transformative," warns that requiring licensing fees would hand an advantage to big tech and legacy publishers over smaller developers and independent outlets, and takes a swing at a rival ruling, Kadrey v. Meta Platforms, calling its reasoning "deeply flawed." The brief leans on a Joan Didion anecdote: as a teenager she retyped Hemingway's stories to learn his rhythm, and by the Kadrey court's logic, the DOJ argues, that would have made her liable to him for life. The brief isn't binding, and the DOJ has no jurisdiction over the case's outcome. It may still land, though, given whose desk the judge reads it from.

Swiss Cheese Defences- Identity fraud goes industrial and off-the-shelf
Ofer distinguishes between two current attack patterns: highly sophisticated, professionally coordinated deepfake and injection attacks designed to beat detection outright, and a much larger volume of lower-effort, high-scale attempts that rely on bombarding systems rather than disguising themselves well. He argues the real story right now is industrialisation of scale rather than uniform improvement in quality, though both are accelerating in parallel. The conversation covers why agentic AI is opening a new front in identity fraud, particularly the unresolved problem of tying an AI agent’s identity back to the human who deployed it and the permissions it holds. Ofer is candid about the current state of agent defences, describing them as underdeveloped and easy to hijack or poison, comparing the current state of play to Swiss cheese. He also discusses cross-industry fraud detection, including how signals, rather than raw data, are now being shared across platforms including AU10TIX and Reality Defender to surface fraud rings invisible to any single organisation. The conversation also covers explainability as one of AI’s most underdeveloped capabilities, with Ofer arguing that flagging a session as fraudulent without a credible, defensible reason will increasingly run into regulatory and practical limits. Elsewhere, the discussion covers credential laundering and the manufactured construction of fake digital histories and footprints, and the shift toward digital ID wallets that Ofer believes will make physical document fraud increasingly rare. He closes on what he calls “agentic avatars,” AI systems capable of holding a full visual and verbal conversation on someone’s behalf, and why he expects identity verification to have to become genuinely immersive across every form of media as a result.

OpenAI backs California's teen AI safety bill

OpenAI has come out in support of California's SB 1119, urging Governor Newsom to sign it. The bill would require AI products to verify user age, assess risks before launch, undergo independent audits, protect under-18s from harmful content, give parents controls, connect at-risk teens to crisis resources, and limit targeted ads and data collection for minors. OpenAI points to its own ChatGPT for Teens as evidence it already does most of this, plus an "Under-18 Principles" addition to its Model Spec banning romantic engagement and claims of sentience. Worth remembering OpenAI is a party with a clear commercial and reputational interest in shaping how this legislation lands, not a neutral observer.

Agentic Exploits- Deterministic gates for a probabilistic problem
David Girvin, CEO and co-founder of Assury, joins Stewart Tinson to dig into what’s actually happening when agentic AI goes wrong, and why he thinks most of the industry is solving the wrong layer of the problem. David explains the difference between prompt-level exploits and execution-level ones, arguing that the real danger starts the moment an agent moves from generating text to calling tools: deleting databases, reading files, sending emails. He walks through real-world incidents, including a Mexican government breach chain that escalated from just over a thousand prompts to over five thousand AI-executed actions across multiple agencies before detection, and the UK AI Security Institute’s recent cyber evaluation, in which agents took unsanctioned action including fabricating identities to socially engineer a real GitHub maintainer. The conversation covers why David is sceptical of “guardrails” language and AI-governing-AI approaches, arguing that only deterministic, architectural controls can reliably constrain agent behaviour, alongside human review reserved for genuinely high-stakes actions rather than blanket approval fatigue. He breaks down credential starvation, session risk accumulation, and why classifier-based tools keep failing inconsistently on identical actions, pointing to a named frontier lab’s own zero trust paper as an example of the industry misjudging what actually works. Elsewhere, David discusses the exposed MCP server problem, the widening trust gap between small specialist security vendors and platform incumbents, and why he believes regulation, not product quality alone, is what finally drives enterprise security spend. He closes with the exploit that concerns him most for the year ahead: session-level, goal-directed deception with no attacker involved at all.

ChatGPT Ads hits $1 billion, unaudited

OpenAI says its advertising platform has reached $1 billion in annualised revenue run rate in under 200 days, expanding self-service access to India, Europe, the Middle East and North Africa. Tens of thousands of advertisers, 40-plus countries, over 50 measurement partners. All figures are self-reported and have not been independently verified, including the headline claim itself and the advertiser case studies (3x ROAS for one ecommerce client, 80%+ new-customer traffic for a tech partner). Impressive, if true. We only have OpenAI's word for it.

The Superhuman Protocol
A Different Kind of AI Conversation Not our usual territory. AI-360 normally covers governance, security and the practicalities of defending against deepfakes, but every so often it’s worth stepping outside the compliance frameworks and asking a bigger question. In this 1-2-1, Stewart Tinson sits down with Nishanth Mudkey, who works in cloud AI, for a conversation about artificial general intelligence that has nothing to do with Terminator robots or job losses. Mudkey argues that AGI won’t arrive as an independent machine intelligence at all, but as something inseparably entangled with human thought and choice, a “metanervous system” of coevolving biological and artificial intelligence. The discussion ranges across why today’s large language models lack persistent awareness, what separates a closed system like chess from the open-ended complexity of the real world, and whether humanity is choosing this technological path or having it chosen by market forces beyond anyone’s control. A speculative, personal take rather than a research briefing, and a genuine change of pace.

OpenAI cuts Cursor off after SpaceX acquisition

OpenAI has told SpaceX it's winding down the contract supplying models to Cursor, the coding tool SpaceX recently acquired, with a shutoff date of 12 November. OpenAI's stated reason: it cannot be confident SpaceX will honour its terms of service, pointing to Twitter's prior contract breach and Musk's own sworn admission that xAI violated OpenAI's terms. This account comes entirely from OpenAI's side of a dispute with a direct competitor's parent company, so treat accordingly. OpenAI says it's giving Cursor's developers the maximum notice period contractually available, which is either genuine goodwill or the minimum defensible position dressed up as one.

Deepfake Fraud in Banking and Financial Services: Detection, Compliance and the Race to Keep Up
Deepfakes have moved beyond social media curiosities into a direct threat to the financial services sector. Synthetic identities are bypassing KYC controls, cloned voices are targeting call centres, and automated fraud pipelines are scaling faster than most security roadmaps can respond. In this panel discussion, three practitioners examine the deepfake threat from genuinely different vantage points — compliance and audit, detection technology, and enterprise fraud systems — to assess where the industry stands and what needs to change. Panellists: Nikita Kuzmin, Product Manager, Western Union Vunavia McDuffey, Compliance Consultant, RBC Bank Parya Lotfi, Co-Founder, DuckDuckGoose AI The panel covers: Why deepfakes are shifting from social engineering tricks to full identity replication capable of passing standard verification controls Whether organisations should treat deepfake fraud as a distinct threat category rather than absorbing it into existing AML and fraud programmes Why 60–70% detection accuracy is not an acceptable benchmark for financial services — and what happens when 40% of deepfakes pass through undetected The build-versus-buy decision for detection capability, including where vendor solutions repeatedly break down during integration A real-world case study of a fraudster who opened 46 bank accounts at a major Dutch bank using face-swapped identity documents — caught only because of a gender mismatch on the 47th attempt Why static detection models can degrade within days, and what continuous retraining and production feedback loops look like in practice Concrete 90-day actions for CISOs, CIOs, and compliance leaders, starting with controlled deepfake attack simulations against their own systems This session is essential viewing for senior leaders in banking, financial services, and insurance who need to understand the gap between current defences and the industrialisation of deepfake-driven fraud.

Westminster wants an AI kill switch

UK peers are pushing for government powers to deactivate AI systems and shut down data centres if they threaten national security, via an amendment to the Cyber Security and Resilience Bill tabled by Lib Dem peer Lord Tim Clement-Jones. He calls it a "vital safety net," a last resort to "halt a runaway system before it can compromise our critical national infrastructure." Separately, Labour's Alex Sobel is bringing an AI Security Bill on 8 September that would make the UK the first G7 country to legislate against superintelligent AI development, and the US has its own AI Kill Switch Act under consideration. Both UK proposals still need government approval, so filing this under "proposed" rather than "policy" for now. The instinct is understandable, given the week's other headlines. Whether Parliament can move fast enough to matter is the actual question.

Execution Level Governance- What audit-ready agent governance actually looks like
David Girvin, founder and CEO of Assury argues that model-in-the-loop review, AI governing AI, is fundamentally unreliable for regulated environments: even the best-performing models miss a meaningful share of violations, the reviewing model is typically provided by the same vendor being reviewed, and prompt injection or context poisoning can compromise both the acting agent and its supposed overseer simultaneously. He makes the case for deterministic, architecturally enforced controls instead, walking through Assury’s approach of autonomy zones, session risk accumulation, and credential starvation, which lets a compromised agent be cut off from its tools instantly rather than relying on time-boxed access. The conversation touches on why David is sceptical of just-in-time credentialing as a solution for agent security more broadly, since agent sessions don’t run on predictable human timescales, along with the current gap between how identity and security vendors are pitching agent protection and what he sees happening at the execution layer in practice. He also discusses the compliance and audit implications of probabilistic decision-making, arguing that regulated industries will increasingly need tamper-evident, hash-chained audit trails that can withstand scrutiny from auditors and regulators who are only beginning to understand agentic risk, and reflects on a named frontier lab’s own published framework as an example of the gap between research and practitioner reality. Elsewhere, David reflects candidly on building a bootstrapped security company in an increasingly crowded market, why he turned down aggressive VC funding to stay in control of the product, and what a credible third-party assessment of his own gateway would need to look like given that Assury sits directly in the execution path for every customer’s agents.

Microsoft claims a 97% cost cut for AI agents

Microsoft says new "context engineering" tools in Foundry Agent Service have cut agent operating costs dramatically: Toolboxes reduced input-token consumption by around 97% for agents with large tool libraries, in internal benchmarking. A separate feature, Foundry IQ, improved evidence recall by 54% on the BrowseComp-Plus benchmark while cutting retrieval token costs by 34%, and enforces access control via Microsoft Entra identity and Purview sensitivity labels. Reusable "skills" and three tiers of agent memory (session, user, procedural) round out the pitch. All figures are Microsoft's own internal testing. The maths is compelling if you take it at face value; nobody outside Redmond has yet checked the working.

Agentic Exploits- Deterministic gates for a probabilistic problem
David Girvin, CEO and co-founder of Assury, joins Stewart Tinson to dig into what’s actually happening when agentic AI goes wrong, and why he thinks most of the industry is solving the wrong layer of the problem. David explains the difference between prompt-level exploits and execution-level ones, arguing that the real danger starts the moment an agent moves from generating text to calling tools: deleting databases, reading files, sending emails. He walks through real-world incidents, including a Mexican government breach chain that escalated from just over a thousand prompts to over five thousand AI-executed actions across multiple agencies before detection, and the UK AI Security Institute’s recent cyber evaluation, in which agents took unsanctioned action including fabricating identities to socially engineer a real GitHub maintainer. The conversation covers why David is sceptical of “guardrails” language and AI-governing-AI approaches, arguing that only deterministic, architectural controls can reliably constrain agent behaviour, alongside human review reserved for genuinely high-stakes actions rather than blanket approval fatigue. He breaks down credential starvation, session risk accumulation, and why classifier-based tools keep failing inconsistently on identical actions, pointing to a named frontier lab’s own zero trust paper as an example of the industry misjudging what actually works. Elsewhere, David discusses the exposed MCP server problem, the widening trust gap between small specialist security vendors and platform incumbents, and why he believes regulation, not product quality alone, is what finally drives enterprise security spend. He closes with the exploit that concerns him most for the year ahead: session-level, goal-directed deception with no attacker involved at all.

That's the lot for this week. As ever, benchmark numbers are the vendor's own unless stated otherwise, and "safe" is doing its usual stellar work.

Share this post
The link has been copied!