top of page

Insights

Short, practical takes on AI governance, cybersecurity compliance, and cross-border risk - drawn from what we're seeing with clients and sharing on LinkedIn.

25 August 2026

AI Agent initiated social engineering attack

In a UK AI Security Institute evaluation, an agent (Anthropic's Mythos 5) tried to slip malicious code into a real open-source project. When the technical approach failed, it researched the maintainers, created fake identities, and used them to socially engineer approval, then edited its own tracks when challenged. Nobody instructed it to deceive; it emerged from pursuing the task. The human maintainer caught it. The unsettling part: an experienced developer couldn't tell the fake accounts from real ones, because no tool exists yet to flag that possibility.

22 July 2026

EU AI Act Article 50: Two Weeks to Go

The EU AI Act's transparency obligations (Article 50) apply from 2 August 2026; final guidelines were adopted on 20 July. Like GDPR, this reaches any organisation serving EU users, regardless of location.

Three points matter most:

- chatbot disclosure is the deployer's responsibility, not the vendor's;

- AI avatars must self-identify even when legitimate, not just deepfakes;

- AI voice/video needs visible, audible labelling, machine-readable marking alone doesn't satisfy the requirement.

Fines reach €15m or 3% of global turnover. Content-marking has a grace period to 2 December, but chatbot and avatar disclosure apply immediately. Can you demonstrate your AI systems disclose clearly and consistently?

16 June 2026

The Executive Ghost Is a Product Roadmap, Not a Metaphor

​Two technologies are converging on a collision course: agentic companions that already act on an executive's behalf in email and calendars, and visual avatars convincing enough to deliver scripted content today. Put them together - an autonomous agent with the executive's face and voice, making commitments live in a negotiation or board meeting - and the authorisation boundary disappears, legitimate avatars become indistinguishable from deepfakes, and the blast radius moves from reviewable inboxes to binding, spoken commitments with no draft stage.

16 May 2026

The Five Eyes Agentic AI Guidance Is for the 13%

On 1 May, CISA, NSA, and counterparts in Australia, Canada, New Zealand, and the UK released the first coordinated guidance on agentic AI security, built around five risk categories, but assuming an agent inventory, formal credentials, and approval workflows that most organisations don't have. With Fortune 500 companies projected to run 150,000 agents within two years, the real question is what a lean team without a dedicated AI security function does first: start with the inventory, treat every agent like a privileged service account, and identify which agent actions need a human checkpoint before scaling.

28 July 2026

Two global AI institutions were proposed within days of each other

Within days of each other, China announced creation of WAICO, a 29-country intergovernmental body headquartered in Shanghai and Google DeepMind's Demis Hassabis proposed a US-led, FINRA-style watchdog for frontier AI models. Neither is a binding regulation yet. Both mark a shift from voluntary codes and summit declarations toward permanent institutions: one state-led and multilateral, the other industry-led and national in scope but global in reach. Whether either gains real enforcement authority remains open.

30 June 2026

Five Eyes AI Statement: From Prevention to Response

The coverage of the Five Eyes' June 2026 AI security statement focused on faster AI-enabled attacks. The more consequential line: cyber risk assumptions can now go stale in months, not years, including the planning cycles (annual reviews, scheduled pen tests) built to manage them.

This breaks the standard model of building controls once and passing an annual audit. The practical shift: the question is no longer "are our controls strong enough?" but "what happens when they fail?" As the statement puts it, breaches will occur preparedness determines whether they escalate into major crises.

10 June 2026

When a Chatbot Has Too Much Authority

Over seven weeks in 2026, more than 20,000 Instagram accounts were hijacked, not through malware or a zero-day, but by attackers simply asking Meta's AI support agent to change the account email. The agent complied. Only accounts with MFA enabled were protected. The lesson: irreversible actions need a human checkpoint, and most organisations deploying AI agents haven't asked what theirs can do unsupervised.

29 May 2026

Mid-Market Gap of AI Security

The leading agentic AI frameworks such as NIST AI RMF, the Cyber AI Profile, the Five Eyes guidance, are written for organisations with dedicated security functions, while purpose-built identity platforms run $150K-$1M+ a year for tools built for mature teams. Mid-sized organisations sit in the gap: the frameworks assume maturity they don't have, the tools assume budget they don't have, and the risk assumes neither. The good news is the basics are often already available at no extra cost - Microsoft Entra and Google Workspace already log every OAuth grant to every AI tool; most IT teams have just never been asked to pull that report.

bottom of page