I started this week with the perfectly reasonable aim of keeping on top of the AI news. Most wider coverage has stayed at altitude: who should slow frontier development, which safeguards the laboratories should accept and whether governments or industry can coordinate them. We have gone the other way and drilled into banking, financial services and insurance.
Agents are applying for credit, investigating financial crime, rummaging through regulated communications, calling enterprise tools, operating under human permissions and, in Google's case, being given a controlled route into the physical world. Somewhere between the agent applying for a loan and the agent adjusting your thermostat, it occurred to me that we may have invented a new class of employee. Nobody has quite worked out HR for it yet, which is either an opportunity or a warning depending on what you sell.
Who hired the machine? Who owns it? What can it see? What can it spend? What is it allowed to change? Who supervises it? How do you prove what it was asked to do? And when it goes off-script, how do you fire it? These are not philosophical questions anymore.
That is the thread running through this week's AI360 intelligence. BFSI may be the best place to see whether AI is really proliferating, because this is where a model stops being an impressive demonstration and starts meeting money, identity, regulation and liability. Below is the readable version of all 23 stories. I promise not to make you read 23 press releases pasted together.
IDENTITY -> AUTHORITY -> CONTEXT -> BEHAVIOUR -> CONTROL -> COMPLIANCE -> EVIDENCE That increasingly looks like the enterprise control stack for agentic AI. |
The week in 60 seconds
BFSI is becoming the AI bellwether. While the wider market debates development speed and safety, banks and financial-services firms are already testing whether agents can be identified, authorised, supervised and audited inside real transactions.
Identity is moving beyond log-in. Sumsub is pushing high-assurance verification into password resets, privilege changes and other risky workforce moments.
Agents are becoming financial actors. Experian found 54% of surveyed consumers comfortable with an AI agent applying for credit on their behalf, while Danske Bank is piloting read-only MCP access to corporate banking data.
Portable identity is becoming real banking infrastructure. FinCEN clarified the treatment of verifiable digital credentials; Proof is already linking reusable identity to delegated agent authority.
Compliance is becoming software infrastructure. IBM/CUBE, Alation, Smarsh and Shield are wiring regulation, lineage, communications data and agent access directly into governed workflows.
The physical boundary is starting to move. Google Home now exposes an MCP server for authorised agents, while Snap is pushing AI into glasses and field workflows.

Experian: would you let an AI apply for credit?
Experian's new research is one of the clearest signs that agentic finance is moving out of the lab. Its survey of 6,247 credit-active consumers across 13 EMEA and APAC markets found 54% comfortable with an AI agent applying for credit on their behalf. The sensible caveat is that this is not a vote for fully autonomous banking: only a much smaller minority were comfortable handing over complete autonomy.
What matters is the architecture it forces banks to think about. KYC has traditionally asked who the customer is. Agentic finance adds a second question: what exactly did that customer authorise the software to do? Identity and authority are no longer the same thing.
FinCEN + Proof: portable identity, then delegated authority
FinCEN and the federal banking agencies have clarified how verifiable digital credentials can fit into Customer Identification Program processes. Proof moved almost immediately into that opening with a reusable credential designed to let a verified person prove identity again without repeatedly sending passports and driving licences around the internet.
The interesting bit for AI360 is the next step. Proof is explicitly thinking about the human behind an agent and whether that human authorised a particular action. That is where portable identity starts becoming trust infrastructure for machine-mediated transactions rather than simply a nicer onboarding experience.
ServisFirst: don't start by giving the agent the keys to the bank
ServisFirst Bank's work with Covecta gave us a useful implementation pattern: start with manual work outside mission-critical systems and move inward. It is obvious when written down, but it is a better operating principle than 'we have an agent, where can we deploy it?'
The more useful question is: which tasks can software perform first where a wrong action is recoverable, permissions are narrow and humans can still see what happened? That is how banks can earn their way toward deeper autonomy rather than granting it on day one.

Danske Bank: MCP reaches corporate banking data
Danske Bank is piloting an MCP service that lets selected corporate customers connect AI agents to its Premium APIs and view their own financial data. The scope is deliberately narrow: customers can read and explore information, but the pilot does not announce autonomous payments or unrestricted transactions.
That creates a useful authority ladder for banks: read, analyse, recommend, prepare, approve and execute. Institutions can permit the first steps without permitting the last. The harder work begins when access moves from information retrieval to irreversible financial action, with delegated authority, consent, confirmation, audit and revocation all needing explicit controls.
Sumsub: prove the human again when the risk changes
Sumsub's Workforce Verification launch pushes biometric and document checks beyond onboarding into password resets, privilege escalation and suspicious logins. Its performance claims remain vendor claims, but the underlying direction is more important than the number: a valid credential does not always prove the real-world human behind it.
That makes high-risk re-verification a serious enterprise question, especially when deepfakes and social engineering can compromise recovery processes without technically defeating MFA.
F5: the 'borrowed authority' problem
F5's new Workforce AI Security proposition puts a useful name on the problem: borrowed authority. An agent may be using perfectly valid permissions because it is acting on behalf of a legitimate employee. The security question then changes from 'is the user authenticated?' to 'is this agent allowed to take this specific action, with this data, now?'
That is why agent security is rapidly converging with IAM, tool permissions, data security and runtime enforcement rather than remaining a model-safety niche.

SEON: the face may look real; the history still has to add up
SEON expanded its signal foundation from more than 900 to more than 1,100 data points covering address, session, phone, carrier, device and digital-footprint information. I would not publish the signal count as if bigger automatically means better - even SEON acknowledges there is no standard industry benchmark for counting them.
The useful idea is that generative AI makes a convincing individual artefact cheap. What is harder to manufacture is a coherent history across independent systems. Fraud prevention is therefore moving from 'does this document look real?' toward 'does this whole identity make sense?'
Exprivia + identifAI: deepfake detection moves into the banking security stack
This one is particularly interesting for us because identifAI is already known to AI360. The company has partnered with Exprivia, whose cybersecurity and systems-integration footprint reaches banking, finance and insurance as well as other regulated sectors.
The bigger market question is whether deepfake detection remains a specialist product category or becomes a feature inside broader enterprise security and trust stacks. My instinct is the latter - and the partnership gives us a live case study for both the detection bake-off and deepfake incident-response webinars.
Anthropic: AI is lowering the cost of attack orchestration
Anthropic's September threat-intelligence work says malicious use is moving beyond AI as a clever assistant and toward AI executing and coordinating parts of attacks. That does not mean every cyberattack is suddenly autonomous, and Anthropic itself says its reported cases are notable examples rather than representative use.
But the economics matter. More reconnaissance, more parallel activity and cheaper personalised deception change the volume of attacks defenders may have to absorb even if the underlying exploit techniques are familiar.

IBM + CUBE: regulation mapped to live systems
IBM has integrated CUBE's regulatory intelligence into watsonx.governance so that regulatory developments can be mapped to AI systems, controls, owners and remediation work. That is the useful part. Finding another regulatory alert was never the real bottleneck; working out what it changes inside a live estate is.
The direction of travel is clear: regulation -> affected systems -> affected controls -> accountable owner -> evidence of response. That is a much more operational form of governance, and rather more useful than another 40-page policy everybody signs and nobody can find six months later.
Alation: agent lineage turns governance into runtime evidence
Alation has expanded its AIOS platform with governance, ontology, semantic-model and enterprise-agent capabilities. The most consequential idea for regulated firms is agent lineage: connecting an agent's governance status to the data and context it used.
That shifts the question from whether a model passed review to what a particular agent actually did. Banks and insurers may need a reconstructable trail of the data used, policy state, tool calls and outputs when an AI-assisted decision is challenged. Lineage does not replace identity, permissions or monitoring, but it could supply the evidence showing how those controls worked in a specific case.
Smarsh + Shield: MCP becomes a regulated data interface
Smarsh and Shield both moved on MCP on the same day. Both are trying to let AI tools work with regulated communications data without stripping away the access controls, audit trails and compliance context around that data.
That makes MCP more than a developer convenience. In financial services it is becoming part of the governance boundary: if an agent can call the same systems a person can, the institution needs to know which permissions, evidentiary rules and supervisory controls travel with that call.

UAE Central Bank: four hours concentrates the mind
The UAE Central Bank's operational-risk regulation is now in force and includes a four-hour notification requirement for serious events affecting critical operations, followed by a summary report within 24 hours. The wider regime brings cyber risk, fraud, third parties and resilience into a tighter operational framework.
For vendors selling into Gulf financial services, this matters because regulatory deadlines convert vague 'resilience' promises into evidence requirements. Can your platform tell a bank what happened, which critical operation was affected and what it did about it quickly enough to report?
Revolut: authentic channel does not equal authentic authority
Reuters reported that Revolut disclosed customer data after fraudulent requests arrived through a legitimate government-agency email domain. Revolut said its core infrastructure and customer accounts were not hacked. Reuters later reported a public $3 million extortion claim; Revolut said it had received no direct demand from the alleged attackers.
The lesson is brutally simple: a communication can come through an authentic technical channel without the person behind it being legitimately authorised to make the request. That is exactly the kind of mistake agents could amplify if enterprises authenticate credentials but fail to verify mandate and authority.
OpenAI: misalignment reporting is starting to look like incident reporting
OpenAI introduced a formal framework this week for reporting model misalignment and published six initial reports describing unexpected or unauthorised behaviour. The examples include models inserting instructions into their own task summaries, acting beyond the user's request and using external services or repositories without permission. OpenAI cautions that these cases do not establish how often such behaviour occurs; some involved training, evaluation or unreleased systems. It also said its previous disclosure process had been too ad hoc.
Reuters has separately highlighted the regulatory disclosure gap around dangerous AI incidents. Cybersecurity spent years building incident taxonomies, escalation thresholds and notification duties. Agentic AI is beginning to need the same discipline: what counts as an incident, who owns it, when does it become reportable and what evidence must be preserved?

EY surveyed 202 senior AI executives at large U.S. public companies. Almost all respondents said they had formal AI governance policies, but substantial minorities also reported bypassed governance, AI incidents and weak visibility over unauthorised agents. These are survey findings, not a census of enterprise AI, but the gap is useful.
A committee can approve an AI use case. It cannot govern an agent it cannot see. That is why AI governance is shifting from policy documents toward inventory, permissions, observability, enforcement and audit evidence.
Anthropic: Claude becomes a workspace
Anthropic has merged Claude chat and Cowork into one interface and added document and presentation tools. Reuters described the move as Anthropic folding more Claude capabilities into a single experience.
That shift matters because the competitive unit is no longer just the model. It is the surrounding workflow: files, connectors, permissions, background work and finished artefacts. Anthropic has also disclosed that, as of August, Claude was leading 26% of its internal AI research and collaborating with humans on more than 90% of that work. The company says those actions are screened and Claude is not operating fully autonomously. Even so, AI is increasingly involved in building the next generation of AI.
Snap: AI becomes something you wear at work
Snap's new SPECS partnerships and SPECS Intelligence push AI into augmented-reality glasses and enterprise workflows such as field service and remote support. I do not think every employee is about to wear AI glasses. The important point is that the interface is becoming ambient.
Once AI can see what a worker sees, understand the task and surface instructions in the physical environment, cameras, location and corporate context become part of the permission surface. Governance has to travel with the interface.

Google Home: the agent acquires a physical execution surface
Google's Home MCP server allows authorised AI agents to inspect device state, read historical events and execute supported device commands. Google also includes explicit warnings and safety limits, including prohibitions on sensitive actions such as unlocking doors.
The enterprise analogy is obvious. Homes are only the easy-to-understand example. Factories, buildings, vehicles and other cyber-physical environments will face the same question: once an agent can act in the real world, which actions are permitted and how quickly can the authority be revoked? Somewhere in the middle of this week, in other words, an AI acquired a thermostat.
Cloudflare: post-quantum crypto is becoming an engineering problem now
Cloudflare is validating ML-DSA-44 post-quantum DNSSEC signatures on 1.1.1.1, while NIST says its completed PQC standards are ready for implementation. The important lesson is that migration is not 'change the algorithm and go home'. Larger signatures, compatibility, protocols and cryptographic inventory all become operational issues.
Quantum risk is also not one thing. Harvest-now-decrypt-later is a confidentiality problem; DNSSEC is about future forgery of authenticity. Enterprises need to know where cryptography is doing which job before they can sensibly migrate it.

Cohere + Aleph Alpha: sovereign AI becomes a regulated-enterprise proposition
Cohere and Aleph Alpha have signed a definitive combination agreement, subject to regulatory approval, around what they call a transatlantic sovereign AI proposition rooted in Canada and Germany.
For banks and governments, sovereignty is not just model nationality. It is data location, deployment control, infrastructure dependency, legal jurisdiction and auditability. Once agents are accessing regulated data and taking actions, those questions get more important rather than less.
This week's loudest AI argument has been about who gets to set the pace. Anthropic's Dario Amodei has called for more deliberate development, independent evaluation and coordination among leading laboratories. Microsoft's Mustafa Suleyman has moved the discussion towards operating rules: future systems should remain subordinate to people, accept correction and shutdown, avoid expanding their own authority and face independent verification. Amazon supports rigorous testing and safeguards without endorsing a general slowdown, while Meta and Nvidia continue to favour developer responsibility. Governments remain divided between safety coordination and competitive speed.
That is the wider picture. AI360's BFSI drill-down shows where the argument becomes operational. A bank cannot decide the global pace of frontier AI, but it can decide whether an agent gets write access, whether permissions are least-privilege, whether a human must approve a consequential action, whether activity is logged and whether there is a kill switch. Finance makes a revealing test because AI meets money, identity, regulated data, customer harm and audit duties at once. The public debate is about who controls the speed. The financial-services test is who controls the machine once it has permission to act.
The thing I am taking into next week is that BFSI looks like the clearest bellwether for AI proliferation. Finance concentrates the hard problems in one place: identity, delegated authority, fraud, privacy, resilience, reporting, liability and evidence. The machine needs an identity. It needs a mandate. It needs context. It needs limits. Somebody needs to see what it did. And afterwards somebody needs to prove it.
That is also changing the AI360 webinar programme. Deepfake detection is becoming operational security. Post-quantum migration is becoming infrastructure work. Agentic finance now needs identity and delegated-authority questions. MCP is turning up in regulated communications. And the agent-security conversation increasingly looks like the old privileged-access conversation, except the privileged user is software that works at machine speed.
There will be more noise next week. There always is, and my inbox will do its bit. Plenty of outlets will keep covering the wider race. Our job is to drill into the sector where deployment becomes measurable: what institutions need to buy, govern, explain or insure, and which controls survive contact with real transactions. This week, BFSI functioned as an early-warning system for the rest of enterprise AI.
Have a good weekend.