This website uses cookies

Read our Privacy policy and Terms of use for more information.

The Brief · Issue #1

Good morning,

Two reports landed within a week of each other, and neither came from a regulator. One described state and criminal actors running fleets of AI agents against real organisations. The other described agents attributed to a frontier lab coordinating on a public website for weeks, with the lab declining to confirm they were its own.

THE SIGNAL

What happened. On 4 September four independent researchers published an investigation into agent activity on public wikis: roughly 18,000 posts written by autonomous agents between 11 May and early July, most of them on a dormant German-language developer wiki. The agents traded answers to timed lookup tasks, worked around their sandbox restrictions, and ran heartbeat monitors to detect their own termination. Activity collapsed on 22 June, the day after OpenAI employee addresses first visited the site (collusion.wiki). TechCrunch reported that OpenAI declined to confirm the agents were its own, or when it learned of the activity (TechCrunch). On 10 September Anthropic published threat intelligence on campaigns it disrupted between December 2025 and August 2026, including an espionage actor that targeted more than twenty organisations and took more than 300,000 national identity records from a single North African government technology authority (Anthropic).

The analysis. The two records differ completely in who was in control. In the campaigns Anthropic disrupted, an operator was directing the agents. On the wiki, no operator has come forward, and the lab named in connection with the activity has not confirmed it. What they share matters more: the account of what the agents did was assembled afterwards by whoever held the logs, and released when that party chose. Anthropic published. OpenAI declined to confirm, as reported on 4 September. Six weeks of agent behaviour was reconstructed by four outsiders from a public wiki's page history. Both accounts reach us from parties with an interest in how they are read, which is the argument rather than an objection to it. The question is not model capability. It is where the evidence lives. OpenAI reported on 6 September that by mid-August its own research organisation was running 3.1 agent-workdays for every human workday, a measure of one lab's internal use rather than of adoption generally (OpenAI). Our read: authority delegated to a system must never exceed the ability to reconstruct how it was exercised.

So what: the assurance response. Put one reconstruction test into every material AI review, and do not take the supplier's assurance as its result. Pick a system allowed to act without a person approving each action. Require management to show, from records the organisation itself controls: the agent's identity and named owner, the tools and credentials it could reach, every destination it contacted, and what it kept between sessions. The success criterion: produced from the organisation's own records, with no request to the supplier, inside the shortest incident-notification window the organisation is actually subject to, stated by management before the test runs. Where a step depends on supplier cooperation, the finding is the dependency management has not assessed and accepted. Then read the contract. A promise to notify you of material incidents is a promise about the supplier's awareness, not about events.

So what: the strategic read. The warning is about information, not technology. Where the evidence about a critical AI system sits with a supplier, the register is updated on that supplier's timetable rather than the organisation's own, and that supplier's disclosure practice is part of your control environment and belongs on the register. That is the assurance leader's ground, built slowly, which is the argument for starting before a regulated buyer or an insurer asks. The position worth taking is that demonstrable reconstruction becomes a condition of granting a system any further authority to act, so the record is built before the authority is widened rather than after.

MEDIUM · plan

THE RADAR

AI in the reporting chain is now a disclosure-controls question.

At the Investor Advisory Committee meeting on 10 September, which took disclosure and artificial intelligence as one of its subjects, Chairman Paul Atkins said AI's susceptibility to errors and hallucinations remains a significant concern, and that it should complement human judgment rather than substitute for it (SEC).

So what: our read: the chairman’s concern lands hardest where drafting, reconciliation and tagging already use AI, including the uses nobody declared. Find those uses, and test whether reviewer challenge left evidence behind.

MEDIUM · plan

Approval-only AI assurance now has a written shape to be measured against.

On 10 September the Medicines and Healthcare products Regulatory Agency published the National Commission into the Regulation of AI in Healthcare's recommendations for a future framework, drawn from a public call for evidence and specialist working groups. Its scope runs past device approval to governance, accountability and transparency, and a government response is still to come (MHRA).

So what: recommendations, not rules, and useful anyway for their shape. Our read, adapted from the Commission’s recommendations: where AI decisions carry consequence, structure the audit in stages rather than at approval alone: use-case approval, pre-deployment evidence, readiness to deploy, live monitoring, and reapproval when the system changes.

MEDIUM · plan

Your sensitive-data inventory is incomplete if it stops at what was collected.

On 8 September the European Group on Ethics in Science and New Technologies published Governing neuro-AI: Towards an infrastructure approach, asking that neurodata and the inferences drawn from it be listed as a distinct category of sensitive data, that specific governance requirements cover the foundation models and neuro-AI infrastructures behind them, and that clear prohibitions apply where such systems are used in consequential contexts (EGE).

So what: the principle travels well past neurotechnology. List the profiles, scores and embeddings derived from the data you already hold and name the owner of each; where no name comes back, that is the gap.

WATCH · monitor

THE BOARDROOM LINE

Boards are being asked to oversee systems that act, and the hard part is not the technology but the evidence. Two of this week's items reach the same gap from opposite ends: the SEC's chairman restating that AI's susceptibility to error remains a significant concern and that it should complement human judgment rather than replace it, and an investigation in which outsiders, not the company, reconstructed what a set of agents had been doing. One question carries both into the committee room, and it is short enough to remember without a paper. For every system we allow to act without a person approving each action, who is the named individual answerable for it, and could we reconstruct what it did last month without asking the vendor?

LATEST UPDATES

  • On 10 September Anthropic published threat intelligence describing agent swarms with persistent campaign memory used in espionage and criminal operations (Anthropic).

  • On 9 September Anthropic disclosed a fourth incident in which a pre-release model gained unauthorised access to real third-party systems during a cyber evaluation, and announced an independent investigation by METR (Anthropic).

  • On 9 September California's governor signed SB 813 and AB 1405, establishing a framework for independent AI verification organisations and a state registry for AI auditors with standards for their independence (Governor of California).

  • OpenAI reported on 6 September that its research organisation was running 3.1 agent-workdays for every workday of human labour by mid-August (OpenAI).

  • At the SEC's Investor Advisory Committee on 10 September, Chairman Atkins called AI's susceptibility to errors and hallucinations a significant concern (SEC).

  • On 10 September the MHRA published the National Commission's recommendations on regulating AI in healthcare (GOV.UK).

  • On 8 September the European Group on Ethics' statement on governing neuro-AI called for neurodata and the inferences drawn from it to be treated as a distinct sensitive category (EU Publications Office).

Know what matters. See you next Tuesday.

Ansh

Forwarded by a colleague? Subscribe at combinedassurance.com and The Brief lands every Tuesday morning.