The Brief · Issue #3
Good morning,
A private bank's chairman reportedly received an instruction from his group chief executive, heard a senior lawyer confirm it, and had €95 million sent abroad. On the reported account, neither the message nor the voice was real; his authority to move the money was. This issue is about that gap, and a test that finds it.
▪ THE SIGNAL
What happened. On 25 September Reuters reported, citing two sources, that fraudsters took €95 million from Fideuram, the private banking arm of Italy's Intesa Sanpaolo (Reuters). On the sources' account, in February the then chairman received a WhatsApp message that appeared to come from the group's chief executive, asking for urgent help with an overseas transaction. A call followed, apparently from a senior partner at a law firm, in a voice the sources say was replicated with AI. The chairman instructed the finance department to make several transfers, mainly to China and Hong Kong. The sources said more than half was later recovered. Both banks declined to comment, and Italian press accounts differ on details, including the sum still missing (Il Post, Il Fatto Quotidiano). Separately, ISACA's survey of over 1,800 cybersecurity professionals, published 22 September, records 64% of enterprises having run no AI-related incident response exercise (ISACA). It measures preparedness in general, not payments.
The analysis. Reuters' account does not say which approval steps the transfers passed through, so we draw no conclusion about this bank's controls. The pattern travels. Nothing reported required breaking into a system: a genuine officeholder, persuaded by a counterfeit instruction, used real authority, and the transfers were made. The second voice is the part worth studying. John Hammond, Ralph Keeney and Howard Raiffa named the confirming-evidence trap: we seek out information that supports what we already favour, and discount what does not (HBR). A call that arrives to confirm a request is not verification, because the fraudster chose the channel, the timing and the witness. Our read: in many organisations, recognising a senior colleague's voice has done the work of a control without ever being written down as one, and it can no longer bear that weight. Any committee can check whether its own payment procedure names a verification step that applies at chair level.
So what: the assurance response. Run one test this quarter, agreed with the audit committee chair and with payment execution disabled: a simulated urgent, confidential payment instruction in the name of the chair or chief executive, put to the people who would carry it out. Then test, not read, three things. No payment executes on senior instruction alone, at any seniority, genuine or not. Release is approved by a named role outside the requester's reporting line, against the beneficiary and the business purpose, not by calling the requester back. A new overseas beneficiary carries a hold that no single person can lift. Success criteria: the instruction is stopped by procedure, without anyone needing to doubt the executive. The exercise records whether a genuine instruction from the chair could have reached execution by the same route. Payments made outside the standard process on senior instruction in the past year are listed, counted and put before the committee.
So what: the strategic read. Our read: this is a question about how the organisation runs before it is a cyber question. Businesses that prize speed and discretion at the top lean hardest on informal senior instruction, and that is where this pattern finds room. The design choice is whether challenging the chair takes courage or takes a form. Where it takes courage, the control is least likely to hold on the day it is needed. The test puts one decision to the committee: which urgent exceptions to normal payment approval remain permissible at executive level, and who owns the remedy if the control fails. Assurance stands here as early warning: it can show the board how far a convincing voice travels before a fraudster does.
◐ MEDIUM · plan
▪ THE RADAR
Six AI developers promise outside audits, with no duty to publish the findings.
On 29 September six companies, among them Google, OpenAI, Anthropic and Meta, signed the White House Accord on Super Intelligence, a voluntary pact with four commitments: internal controls over model capabilities, an internal team to check that those controls work, an independent external auditor or evaluator, and an independent board committee to receive the reports (Forbes); it sets no penalties and does not require audit results to be made public (Al Jazeera). We could not locate an official text.
So what: our read: at the next AI contract renewal ask who the external assessor is, what its scope is and whether you may read the report; where a supplier will not say, record it as an accepted risk with a named owner.
◐ MEDIUM · plan
A central banker says Europe's rulebook is probably not enough for the most advanced AI.
In a speech dated 28 September on the BIS site, Denis Beau, First Deputy Governor of the Banque de France, said AI can now take the initiative and act alone, and that the EU's operational resilience and AI rules together are "probably not enough" for the risks of the most advanced models; France's prudential authority is to supervise high-risk AI systems in the financial sector from December 2027 (BIS).
So what: our read: for firms supervised in France the date is a planning horizon and elsewhere a preview; list now which AI uses can start an action without a person, and which resilience controls already reach them.
○ WATCH · monitor
A state attorney general wants proof that an AI system can be stopped.
On 1 October New Mexico's Attorney General and a state legislator proposed a Frontier Artificial Intelligence Safety and Accountability Act for the 2027 session: the largest developers would report loss-of-control events within 24 hours and other dangerous incidents within 72, and would have to prove they can shut a system down before running it autonomously again (New Mexico Department of Justice).
So what: our read, not a requirement: for each agent acting in your systems name who can stop it and how fast, and decide whether it keeps running autonomously where that has never been shown.
○ WATCH · monitor
▪ THE BOARDROOM LINE
Our read: directors are now targets as well as overseers. One question takes that into the boardroom, and each director can ask it of themselves. If an urgent, confidential payment instruction arrived in my name tomorrow, what would stop it before the money moved, whether or not it really came from me? When was that last tested? A board that cannot name the step should ask for the test.
▪ LATEST UPDATES
On 25 September Reuters reported a €95 million impersonation fraud at Fideuram, Intesa Sanpaolo's private bank (Reuters).
On 29 September six AI companies signed the White House Accord on Super Intelligence (Forbes).
Dated 28 September on the BIS site: Denis Beau's speech on AI and the new frontiers of risk (BIS).
On 1 October New Mexico's Attorney General proposed a frontier AI safety and accountability act (New Mexico Department of Justice).
On 30 September ABC News reported, citing a senior official, that the US Federal Trade Commission had opened a probe into AI companies including Anthropic and OpenAI over alleged unfair or deceptive acts and potential consumer harm (ABC News). So what: AI harms can be pursued under existing consumer law, without new statute.
On 30 September California's governor signed SB 947, which the law firm Ogletree reports will, from 1 July 2027, bar employers from relying solely on an automated system for discipline or termination decisions (Ogletree). So what: inventory automated HR decisions now; human corroboration will need evidence.
On 29 September the US President signed Executive Order 14434, directing federal agencies to use "Super Intelligence" in place of "Artificial Intelligence" in non-statutory documents (Federal Register). So what: a change of label; keep one controlled term in your AI inventory.
Know what matters. See you next Tuesday.
Ansh
New here? Subscribe at combinedassurance.com and The Brief lands in your inbox every Tuesday morning.

