One numbered series. Intelligence Briefs cover regulatory and governance developments and fast-moving threat and control signals alike. The Watchlist is preliminary monitoring, not a published issue. Newest first. The framework these briefs feed into is set out on the AI agent risk reference page.
Latest · Published
Control model
Issue No. 3 · August 10, 2026
When the boundary fails.
Four documented boundary failures in three weeks — one boundary broken by novel exploitation, one that never existed outside a prompt, a supplier environment nobody could see into, and an agent doing exactly what its permissions allowed. Primary-sourced throughout, and the control model financial institutions should take from them.
What you'll get: four labelled findings, an explicit note on the limits of the evidence, and one question for the board this quarter.
Published
Threat model shift
Issue No. 2 · August 7, 2026
When the attacker is a machine.
A language model ran a full ransomware operation end to end, and attackers were caught spending stolen enterprise AI credentials to fund their own compute. Two primary-sourced cases, neither at a financial institution — and why that is cold comfort for one.
What you'll get: four labelled findings, an explicit note on what could not be verified, and one question for the board this quarter.
Published
Threat level: Elevated
Issue No. 1 · July 16, 2026
Financial AI governance moves from principles to operating expectations.
Three fresh primary-source signals — the FCA's landmark retail-AI review, the FSB's responsible-adoption consultation, and Japan FSA's frontier-AI threat measures — converge on one mechanism: delegation under rising supervisory and adversarial pressure.
What you'll get: immediate, 30-day, and 90-day actions for CROs and CISOs.
Watchlist — not a published issue
Watchlist — Rolling 002
Control expectations are moving deeper into live workflows while tokenized and stablecoin-linked infrastructure is gaining legitimacy faster than governance evidence, dependency visibility, and operating control maturity are catching up.
What you'll get: three signal clusters under active monitoring — no conclusions drawn yet.
Status: Watchlist — preliminary monitoring, pending editorial approval
Audience: finance, payments, risk, compliance, audit
Signal clusterWorkflow-level AI supervisionFINRA's prompt-injection guidance reinforces that prompt integrity, tool use, and workflow discipline are now practical control and evidence issues, not abstract model-risk debates.
Signal clusterDisclosure versus executionCFPB pressure around Wise reinforces the same operational lesson: payment experiences still fail where customer-facing disclosure and real execution behavior stop matching.
Signal clusterInfrastructure dependency pressureStablecoin-linked cards, tokenized-finance trust layers, and market-structure debate are all pushing external infrastructure closer to the operational core.
What this meansThe financial operating perimeter is getting harder to supervise at exactly the moment institutions are adding more dynamic infrastructure and workflow complexity.
- Prompts are becoming part of supervised workflow accountability.
- Disclosure failures still emerge where execution chains drift apart.
- Tokenized and stablecoin-linked systems increase dependency and control-interpretation pressure.
- The connection points are where oversight becomes fragile.
Workflow integrityWhen autonomous behavior breaks review assumptions
How prompt manipulation, weak traceability, and tool execution opacity turn into governance and assurance problems.
Category — current and future issues.
Disclosure integrityWhen customer-facing claims diverge from production behavior
Why quote logic, fee disclosure, escalation handling, and execution systems still fail at the control layer first.
Category — issues forthcoming.
Dependency pressureWhere third-party concentration quietly expands
Infrastructure, model providers, orchestration layers, and connected payment rails can create hidden concentration and resilience problems.
Category — issues forthcoming.