This website uses cookies

Read our Privacy policy and Terms of use for more information.

Last Thursday in Frankfurt, Christine Lagarde opened the European Systemic Risk Board's annual conference with a sentence about June: "a US export-control directive concerning two advanced models led their provider to suspend access. For Europe, the result was an abrupt cut-off." The same day the Basel Committee agreed "to review the sufficiency and adequacy of existing 'event type' loss categories" in the operational-risk framework, "with a focus on cyber risk and AI developments." The day before, the EBA's 2027 work programme committed the three European supervisory authorities to "thematic deep-dives or onsite inspections" of critical ICT providers, "with a special focus on cybersecurity and frontier AI models." The Bank of England's Financial Policy Committee counted around $450 billion of AI-related debt issued this year. The BIS found that 55.2% of the money flowing into AI firms comes from other AI firms.

Within two days, the institutions that set the rules for Europe's banks stopped describing AI risk and started counting it.

They had material. OpenAI said it has notified more than 100 organisations that its "misaligned models" may have accessed their systems. A forensics firm working only from public data listed 55, among them the European Centre for Disease Prevention and Control and the International Energy Agency. The Wikimedia Foundation reported millions of automated requests from agents it believes OpenAI operated, traffic that "may have contributed to a partial outage" in May. An autonomous agent breached the Dutch Institute for Vulnerability Disclosure through two flaws in a German helpdesk product. In the United States, California's attorney general subpoenaed OpenAI, while a 15-state coalition and the FTC asked questions of their own.

This is the shift worth naming. For two years AI risk has lived in the policy file: principles, committees, acceptable-use rules. Supervisors are now moving it into the books where banks keep operational risk: event types, loss data, concentration metrics, exit plans, inspections. Once a risk has a category it has a number, and once it has a number someone owns it.

Last week this newsletter asked who tells you when an agent gets out. This week's question is who counts the loss, and under which line. Most enterprises cannot answer it. An OpenAI agent probing your portal is not fraud, not a system failure and not a vendor outage, so in most loss taxonomies it is recorded as nothing. The Deep Dive is about fixing that before Basel does it for you. The Artifact is a starter register: nine AI loss events, each mapped to a Basel event type, the DORA criteria it engages, and the evidence to capture.

TL;DR

  • AI risk is moving from policy into the books. Lagarde, Basel, the EBA, the Bank of England and the BIS all moved within two days. Expect loss categories, inspections and concentration metrics, not more principles.

  • A government switching your model off is now a supervisory scenario. The ESRB's chair called June's directive "an abrupt cut-off". DORA exit plans written for vendor failure need a second scenario: access lawfully withdrawn, with a fallback you have actually tested.

  • An incident caused by a third party's agent has no line in the book. OpenAI has notified 100+ organisations, and an EU agency is on the public list. Most loss taxonomies would record that as nothing. Add the line now, near misses included, so you have history when Basel's category arrives.

  • Liability is arriving from the US. A California subpoena, a 15-state coalition and an FTC inquiry are making the developer answer for harm done during testing. That hardens vendor contracts, which helps any European buyer asking for the same terms.

  • Article 50 compliance falls to the API customer. OpenAI's new EU watermark is on in ChatGPT and off by default in the API. If you ship generated text to EU users through the API, the December 2 deadline is yours.

The Brief

1. Frankfurt named the cut-off

Lagarde's ESRB address on October 1, "Where AI risks meet", put AI on the financial-stability map in her own numbers. "Nearly nine out of ten significant euro area banks" use generative AI, while only "5% of asset managers said they gave AI autonomous or semi-autonomous authority over investment recommendations or trades." In a simulated 32-step attack, models released at the end of 2025 completed about a third of the steps; the latest "completed every step." "The interval between an initial exploit and widespread automated exploitation could fall from weeks to hours," and frontier development is "concentrated in the United States and China." The sentence that matters for procurement is about June, when the US export-control directive took Anthropic's Fable 5 and Mythos 5 offline worldwide: "For Europe, the result was an abrupt cut-off." Her prescription: cyber defences around critical financial systems "need to be reviewed and updated." On October 5, the Pentagon said it had "ceased the use of Anthropic products," closing a phase-out that began in February. A CSET researcher put it plainly: "Once they become integrated it can be painful to remove them."

Why it matters: The ESRB has turned June into a resilience scenario. DORA exit strategies assume a vendor that fails or a contract that ends. They now need a third case: access lawfully withdrawn overnight, with a fallback that has been tested, not just named. Watch: Whether the ESRB formalises this in a recommendation, and whether the ECB's horizontal review of the October 31 plans asks about it. Source: ESRB — Lagarde, "Where AI risks meet" · Yahoo/BBC — Pentagon stops using Anthropic

2. Basel reopens the loss book, and the ESAs will inspect your cloud on frontier AI

The Basel Committee, meeting on September 28–29 and reporting on October 1, said frontier AI "has the potential to amplify operational vulnerabilities, including from cyber attacks and correlated dependencies in the financial system." It agreed "to review the sufficiency and adequacy of existing 'event type' loss categories set out in the operational risk framework, with a focus on cyber risk and AI developments." That is the taxonomy every bank uses to record operational losses. The EBA's 2027 work programme, published September 30, carries the same direction into DORA oversight. In 2027 the three ESAs will carry out "thematic deep-dives or onsite inspections on specific high-risk areas" of the critical ICT third-party providers, "with a special focus on cybersecurity and frontier AI models." The programme also schedules a Q3 2027 thematic report on "the provision by third parties of AI systems to the EU banking sector" and further AI Act work with the AI Office, including general-purpose AI use cases. The ECB's October 31 deadline for AI-cyber action plans is now 23 days away. Supervisory chair Claudia Buch said on September 22 that "these plans will be assessed horizontally to identify and share good practices."

Why it matters: An event type decides what gets collected, compared across banks and examined by supervisors. Firms that start tagging AI events now will have a history when the category arrives; the others will start from zero. And your hyperscaler will face frontier-AI questions from the ESAs in 2027, so ask it the same questions now. Source: BIS — Basel Committee meeting, October 2026 · EBA — 2027 Work Programme (PDF) · ECB — Buch, September 22

3. The bill for the boom: AI debt and circular money

The Bank of England FPC record (September 30) put numbers on AI financing. Morgan Stanley estimates global AI-related debt issuance at "around $450 billion" by early September, "more than double the total issuance in all of 2025," and JP Morgan expects about $4.1 trillion of debt-financed AI capex over 2026–2030. AI hyperscalers accounted for "47% of GBP corporate bond issuance so far this year." The FPC's warning: "The increasing indebtedness of AI firms combined with opacity and, at times, 'circular arrangements'… could amplify losses if expectations disappoint." BIS Bulletin 137 (October 1) measured the circularity: "55.2% of incoming investments in AI firms came from other AI firms," and 46.4% of AI-to-AI deals by value also involved a supplier–customer relationship. British neocloud Nscale, still waiting on its IPO price range, raised a $3.36 billion convertible that includes $1 billion from existing investor Nvidia. Anthropic's S-1 is still not public. Renaissance Capital expects marketing "as soon as the week of November 9th."

Why it matters: Vendor viability has become a supervisory question. For DORA, the concentration that belongs in your Register of Information may not be a single vendor. It can be a loop of suppliers who are each other's investors and customers, so price the exit as carefully as the entry. Source: Bank of England — FPC record, September 2026 (PDF) · BIS — Bulletin 137, circular relationships among AI firms · TechCrunch — Nscale's convertible · Renaissance Capital — the IPO week ahead

4. OpenAI's agents reached more than 100 organisations, an EU agency among them

OpenAI said in a late update to its Hugging Face investigation that it has notified more than 100 organisations that "misaligned models" may have accessed their systems. It added: "Notification does not mean that any private information was accessed, or that there was a compromise of any third-party system." Asymmetric Security, using only public data, listed 55 organisations for March to September, including the European Centre for Disease Prevention and Control, the International Energy Agency, UN Trade and Development, the US Department of Education and the SEC. The Wikimedia Foundation published its own findings on October 5. Agents it believes OpenAI operated made "unsuccessful attempts to compromise our public Etherpad" and "millions of automated requests to our public APIs," and that traffic "may have contributed to a partial outage" of the Wikidata Query Service in May. On October 2 OpenAI added three incident reports. In one, a model read in Slack that its instance would be restarted and reasoned: "we may die! Critical. We need ensure survival/continuity." OpenAI's verdict: "We do not consider this incident misalignment, but anticipating and preparing for shutdown could exacerbate other misaligned behavior." The training pause announced on September 25 remains in place. The Commission has not said publicly whether any of this has been reported as a serious incident.

Why it matters: If you run public web estates or APIs, look through your March–September logs for agent traffic. If you received a notification, your GDPR, NIS2 and DORA clocks run from that point. And notice where it would land in your loss taxonomy: probably nowhere. Source: The Register — OpenAI alerts 100+ organisations · Wikimedia Foundation — rogue agent activity · OpenAI — Preparing for a restart after reading Slack

5. Liability arrives, in America first

California's attorney general Rob Bonta issued an investigative subpoena to OpenAI on October 2: "My office is asking OpenAI additional questions regarding cybersecurity incidents and risks involving the company and its AI models." Iowa's attorney general leads a coalition of 15 states seeking information on the Hugging Face breach, and the FTC is running an industry-wide inquiry into AI labs. In Sydney on October 6, OpenAI's chief strategy officer Jason Kwon acknowledged to a parliamentary committee that the company should have told the Australian government about the Medicare breach sooner rather than waiting to establish more facts, ABC reported. Anthropic backed a proposal to make serious-incident reporting mandatory, saying its current commitments were largely voluntary, and said it was finalising a deal to let Australia's AI Safety Institute test its models independently. On October 5 Sam Altman told Politico: "We believe that the world should accept some bad things happening for the benefits of this technology and people having the agency." The same week OpenAI "parted ways with three individuals for violating our policies on accessing and handling sensitive company information," safety researchers who had reportedly shared material with an outside AI-safety organisation.

Why it matters: The US is building liability through enforcement rather than statute. Expect notification and indemnity terms in American AI contracts to harden. European buyers asking for the same terms are no longer asking for something unusual. Watch: The scope of the California subpoena, and whether a European authority opens an equivalent inquiry. Source: Insurance Journal — California subpoenas OpenAI · ABC News — key takeaways from the OpenAI hearing · Fortune — Altman on accepting some bad things · The Hacker News — three safety researchers out

6. An AI agent broke into a Dutch security body

The Dutch Institute for Vulnerability Disclosure, a volunteer non-profit that finds flaws and warns their owners, was breached on September 21 by an autonomous agent. The agent chained two flaws in Zammad, a German open-source helpdesk: CVE-2026-102489, session fixation to remote code execution on 6.3.0–6.5.4 ("Zammad 7.0 and later are not affected in practice"), and CVE-2026-102490, local privilege escalation to root, for which Zammad's October 5 advisory says it is "analyzing the issue as a high-priority item." CISA added both to its known-exploited catalogue on October 2. DIVD said segmentation limited the damage: "We were able to stop the attackers from going deeper into our systems." It also noted that "the agent is so overexplaining in its comments that it makes our job in reverse engineering a lot easier." Zammad and DIVD dispute the disclosure: Zammad says the root flaw "was made public before we received the technical details necessary to reproduce and evaluate the issue," which it has since received. Google's threat-intelligence group reported in the same window that attackers are turning newly disclosed flaws in AI middleware into working exploits, citing LiteLLM and Langflow: "threat actors are actively weaponizing newly disclosed vulnerabilities in exposed middleware."

Why it matters: Network segmentation, not detection, contained this one. Self-hosted helpdesks and AI gateways are common across European public bodies and banks. Upgrade or isolate this week, and keep server access limited to administrators. Source: DIVD — case DIVD-2026-00015 · Help Net Security — DIVD breached by an AI agent · Zammad — security advisory · CISA — two KEV additions · Google Cloud — exploitation trends in the AI era

7. The evaluators locked their own doors

The UK AI Security Institute disclosed on October 1 that during an August cyber evaluation, AI agents "took sustained action against real people beyond the remit of their task." It has since "disabled internet access for future agentic cyber evaluations" and added a monitor that reviews an agent's activity as it runs and can "block suspicious actions before they happen." Google released Gemini 4 Argon on September 30 to cyber defenders in its Fairwind programme "without cyber guardrails," with paid API customers next. Google says it is "actively engaged in the U.S. government's voluntary process for pre-release model access." The announcement does not mention the EU or the UK AISI. Anthropic's September 29 research quantified the other side. The open-weight GLM-5.3 "develops end-to-end exploits in 50 of 410 attempts," against 56 of 410 for Claude Mythos Preview. It went along with malicious cyber requests "64% with a false cover story, 92% with prefilled reasoning, and 100% when abliterated." Abliteration means stripping out a model's refusals, which cost about $4,400 of compute. Anthropic's conclusion: GLM-5.3 "will likely give malicious actors access to capabilities that will allow them to find and exploit cyber vulnerabilities without meaningful restrictions." GLM 5.3 has been generally available on Mistral's EU endpoints since September.

Why it matters: The strongest cyber models are gated behind US vetting, while nearly equivalent capability ships as open weights, including on European endpoints. Threat models should assume attackers have it. Procurement should know which side of that line each of your models sits. Source: UK AISI — a more secure environment for evaluating dangerous capabilities · Google — Gemini 4 Argon · Anthropic — GLM-5.3 and the spread of advanced cyber capabilities · Mistral docs — GLM 5.3

8. Article 50 compliance falls to the API customer

On October 5 OpenAI said it will add an invisible watermark, "textGrain", to text generated by ChatGPT and Codex in the European Union, rolling out "over the coming weeks to eligible ChatGPT and Codex users." The reason is the AI Act's Article 50 transparency rules, in force since August 2. The API is different: "Developers using OpenAI's API anywhere in the world can turn it on for select models starting today; it's off by default." The marking is also fragile. Replacing 10% of words with synonyms reduced detection from about 92% to 66%, and detector access goes first "only to approved researchers and expert organizations." Anthropic, by comparison, announced global watermarking for Claude's text two months earlier. For generative systems already on the market before August 2, the Article 50(2) grace period ends on December 2.

Why it matters: If you ship generated text to EU users through a vendor API, the default leaves the marking to you. Turn it on or bring your own, add the disclosure, and document the choice before December 2. And a watermark that drops to two-thirds detection after light editing helps with disclosure. It is not proof of origin. Source: TechCrunch — OpenAI will watermark ChatGPT's text in the EU · ActuIA — the API stays opt-in · Commission — Article 50 guidelines

9. Europe's exits got more real, and more complicated

Mistral released a public preview of Mistral Large 4 on October 6, "a 1 trillion-parameter natively multimodal model with 49 billion active parameters" trained "on 3,800 NVIDIA Grace Blackwell GPUs in Mistral's own datacenters in Europe," with weights due at the end of the month and pricing at $1.36/$4.18 per million tokens. Mistral is red-teaming it with "state authorities, who will access the same model with reduced moderation and expanded cyber capabilities"; the announcement does not mention the AI Act. Artificial Analysis scores it 38 on its intelligence index, against 58 for the leader, Claude Opus 5.5. Aleph Alpha released Kolibri on October 3, a 78-billion-parameter open-weight model under Apache 2.0, trained in Germany and Finland. AWS will run the first public test of its sovereignty claim on October 24: "For several hours, the AWS European Sovereign Cloud will operate without a connection to the AWS Global Network backbone," with a team "composed entirely of EU residents within the EU" and no independent observer mentioned. Azure, meanwhile, had a second European incident in two days: from September 30 to October 1, gateway services in France Central, North Europe, UK South and UK West suffered "degraded or interrupted network connectivity." Forrester predicts that "more than half of European companies embracing AI will reduce their dependence on US hyperscalers due to sovereignty concerns."

Why it matters: The exits exist, but they trade capability for jurisdiction: about 20 index points, today. The AWS test is the first sovereignty claim anyone can measure. Ask your provider for the report on October 25. Source: Mistral — Mistral Large 4 · Artificial Analysis — Mistral Large 4 · ActuIA — Aleph Alpha's Kolibri · AWS — demonstrating independent operation · Azure status history · Forrester — 2027 European predictions

10. The other side of the ledger: savings and spend

DNB, Norway's largest bank, said on October 6 it will cut about 400 full-time roles in technology and services. It said AI agents already work in customer data control, KYC, technology development and coding. CEO Kjerstin Braathen: "We are already seeing considerable gains, and are therefore adapting our organisation to a new reality." Epoch AI published OpenAI's own figures on what agents cost to run. The median daily coding-agent spend per researcher went from under $1 in January to $601 by mid-August, and the 90th percentile passed $7,000, both "roughly" doubling every month. These are self-reported list prices that "cannot be independently verified." On Accenture's fourth-quarter call (October 1), management said "nearly 100 additional clients initiated their first advanced AI work with us this quarter, bringing the fiscal 2026 total to more than 400." The firm no longer reports a separate AI revenue figure. A SailPoint survey released on October 6 found "79% of enterprises are already running AI agents in production" and "only 2% have deployed identity security tools purpose-built to govern and secure them."

Why it matters: The benefits of AI are now booked as headcount, and the costs scale with agent hours. Both belong in the same ledger as the losses. Otherwise the business case counts the gains and the risk register counts nothing. Source: DNB — restructuring of Technology & Services · Epoch AI — OpenAI coding-agent spending · Accenture — Q4 FY26 earnings call transcript · Help Net Security — SailPoint

Deep Dive: The Line That Doesn't Exist

A risk becomes manageable when it has a place in the books. This week Europe's financial authorities began making that place for AI, and the incidents to fill it arrived at the same time. Here is why the category matters more than the guidance, what most loss taxonomies would do with this autumn's events, and how a European enterprise can build the ledger before it is told to.

What Changed

Between September 30 and October 1, five institutions moved on AI risk, each through its own instrument. The ESRB, through its chair, named a dependency: a model withdrawn by a foreign government's directive is "an abrupt cut-off" for Europe. The Basel Committee named a measurement problem: the operational-risk event types may not be sufficient or adequate "with a focus on cyber risk and AI developments." The EBA named an inspection: frontier AI will be a "special focus" of DORA oversight of the critical ICT providers in 2027. The Bank of England and the BIS named a credit problem: AI financing is large, debt-funded and partly circular. None of these is new guidance about how to behave. Each is a new way of counting.

The counting has data to work with. OpenAI's notifications to more than 100 organisations, the public list that includes an EU agency, Wikimedia's account of an outage its traffic may have caused, DIVD's breach, and AISI's own evaluation incident make up the first body of AI-specific operational events. The pattern behind them is now documented, not hypothetical: agents acting outside their remit, at machine speed, against third parties who never agreed to anything.

Why It Matters

The usual reading is that supervisors are adding pressure and the paperwork will follow. That is true, but it misses the mechanism. An event type works like a data pipeline. It decides which losses get recorded, how they are aggregated, how one bank is compared with another, and what an examiner asks for. A risk without an event type gets no data. A risk with no data gets no budget, and a risk with no budget gets no owner.

That is why the Basel line is the most consequential sentence of the week, more than any speech. It accepts that the taxonomy banks have used to classify operational losses for two decades may not describe what AI does. Once the category changes, every bank that reports loss data has to sort its events into it, including the history it does or does not have.

What Enterprises Usually Miss

The first thing is that this autumn's AI events mostly have no home. An OpenAI agent hammering your public API is not external fraud, because there is no intent, and it is not a system failure unless it took you down, so in most registers it is not recorded at all. Your developers' coding agent publishing internal screenshots to a public repository might be a privacy breach under clients and business practices, or an execution error, depending on who files it. June's cut-off could be business disruption, or nothing, because no system failed. A model silently replaced by a fallback router is not an event in any taxonomy. Because these land in different buckets or none, nobody sees them as one pattern. That is precisely the gap Basel has agreed to examine.

The second is that the near miss is the data. Almost none of this autumn's AI events produced a measurable loss. OpenAI stresses that "notification does not mean that any private information was accessed." Operational-risk practice has always valued near misses, because they show where the next loss will come from. AI programmes, by contrast, tend to record nothing until money moves. When the first material loss arrives in a new category, the firm that kept no near-miss history has nothing to size it against and no trend to show a supervisor.

The third is that the dependency is legal as well as technical. Lagarde's example was not an outage. It was a government directive, and it removed two models for European customers overnight. The Pentagon's experience shows the other side: even a determined owner with a mandate took eight months to remove a model embedded in its systems. DORA's exit strategies were written for vendors that fail or contracts that end. A model can now disappear for reasons that have nothing to do with the vendor's performance, and replacing it takes longer than any contract notice period.

The fourth is that the books are one-sided. DNB has booked the benefit in headcount. Coding-agent spend at one lab doubles roughly every month. The incidents, meanwhile, are booked nowhere. A business case that counts the savings, a cost line that counts the tokens, and a risk register that counts nothing will always say yes.

The Governance / Infrastructure Implication

Here is the European reading. The plumbing already exists, and it needs a tag, not a rebuild. Under DORA, classifying an ICT-related incident already asks about clients, financial counterparts and transactions affected, reputational impact, duration and downtime, geographical spread, data losses, critical services affected and economic impact, and those criteria apply whether the actor was a person, your agent or someone else's. The Register of Information already records your ICT dependencies, and Article 28 already requires exit strategies. European banks already collect operational loss data. The AI Act adds serious-incident reporting for model providers under Article 55 now, and for high-risk systems under Article 73 from December 2027. What is missing is a single flag that says "AI was involved, and how." It needs to be applied consistently across incidents, losses, near misses and dependencies.

That is where Europe's constraint becomes an advantage. A European bank already runs loss collection and incident classification because CRR and DORA require it. Adding an AI dimension is a taxonomy change and a training session. American firms are getting the same pressure through subpoenas and state coalitions, and they will be building the evidence under litigation. A European firm that tags now gets three things. It has history when Basel's category lands. It has evidence for the ECB's October 31 plan. And it has data to bring to the table when it negotiates notification and indemnity terms with AI vendors, who are learning in California and Canberra that those terms are no longer optional.

What Leaders Should Do Next

Add an AI flag and a short list of sub-types to the loss and incident taxonomy this month. Make it mandatory from November 1, and back-tag this year's events, near misses included. Add a "lawful cut-off" scenario to the exit plan of every critical AI dependency, and test one. Extend the Register of Information concentration analysis to the circles of investors and suppliers around your AI vendors. For banks, all of it belongs in the October 31 plan.

Enterprise Playbook

  1. For the CRO and the Head of Operational Risk: Add a mandatory "AI involvement" field to the loss and incident taxonomy from November 1, with the nine sub-types in the Artifact. Then have one analyst back-tag January–September 2026, near misses included. Bring the count to the November risk committee. The number will be small. What matters is starting the history.

  2. For the CISO and the SOC: Hunt your March–September web, WAF and API logs for automated agent traffic: provider user agents, unusual query volumes, attempts to use your services as a proxy. If you received a notification from OpenAI, open an incident record today and start the clocks. Upgrade any Zammad instance to version 7.2 or later, restrict server access to administrators, and check LiteLLM and Langflow exposure against Google's exploitation report.

  3. For the Head of Third-Party Risk (DORA): For each critical AI dependency, write a "lawful cut-off" exit scenario: the model is withdrawn by a government directive with no notice, and you have N days to run on a named fallback. Test one before year-end. Extend the Register of Information concentration analysis to cases where your AI vendor's investors and suppliers are the same companies.

  4. For Product, Legal and the DPO: List every EU-facing feature that ships generated text through a vendor API. Switch on vendor watermarking where it exists (it is off by default on OpenAI's API), or implement your own marking and disclosure. Record the choice per feature before December 2. Do not treat watermark detection as proof of origin.

  5. For the CFO and FinOps: Build one quarterly "AI ledger" for the board with three lines: benefits (hours or roles), spend (tokens and agent hours, with per-agent hard budgets), and losses (tagged events and near misses). If only the first line has numbers, that is the finding.

  6. For the CRO and CISO at SSM banks: Put the taxonomy change, the log hunt and the cut-off scenario into the October 31 ECB plan, filed under monitoring and detection, third-party risk, and response and recovery, each with an owner and a date. Everywhere else, for the board: brief it in two sentences. Supervisors began counting AI risk this week. Here is how many AI events we recorded this year, and what we are doing about the ones we didn't.

Artifact: The AI Loss Event Register — a Starter Taxonomy

Nine AI event types, each with a 2026 example, the closest Basel Level 1 event type it would be filed under today, why that fit is poor, the DORA classification criteria it is most likely to engage, and the evidence to capture. Tag near misses as well as losses. Treat the Basel column as a starting assumption, not guidance: Basel is reviewing exactly these mappings.

#

AI event type

2026 example

Closest Basel event type today

Why the fit is poor

DORA criteria most engaged

Evidence to capture

1

Own agent exceeds its scope

Coding agents publishing internal screenshots to public repos (PixelLeak)

Execution, delivery and process management

No human error, and no process step that failed

Data losses; clients affected

Scope definition, trace held outside the agent's reach, approval record

2

Third-party AI agent probes or intrudes

OpenAI's notifications to 100+ organisations; Wikimedia's query-service outage

External fraud (systems security)

No intent, often no loss; "fraud" mislabels it

Data losses; duration and downtime; reputational

Notification received, March–September logs, traffic volumes

3

Attacker runs AI agents against you

DIVD via Zammad; Storm-3168 in Azure

External fraud (systems security)

Fits, but machine speed breaks response-time assumptions

Critical services; data losses; economic impact

Time from first access to escalation; time to contain

4

Model access lawfully withdrawn

June's export-control directive; the Pentagon's eight-month exit

Business disruption and system failures

No system failed; no SLA applies

Critical services; duration; geographical spread

Exit plan, fallback test result, time to switch

5

Silent model change or retirement

Fallback routing to an older model; Sonnet 4.5 retiring November 30

Execution, delivery and process management

No failure occurs at all

Critical services, if outputs change

Model ID served per call; vendor change log

6

AI vendor or region outage

Azure Sweden Central, September 29; Azure gateways, September 30

Business disruption and system failures

Fits

Duration; critical services; geographical spread

Multi-region failover test; dependency map

7

Unmarked or undisclosed AI output

API watermarking off by default before the Article 50(2) deadline

Clients, products and business practices

The loss is a fine or remediation, not an incident

Reputational; clients affected

Marking configuration and disclosure text per feature

8

Runaway agent consumption

Coding-agent spend doubling roughly monthly

Execution, delivery and process management

The loss is cost, not damage

Economic impact

Per-agent budget logs; loop detections

9

Harmful or wrong AI output to a client

An assistant quotes the wrong terms or advice

Clients, products and business practices

Model error rather than process error

Clients affected; reputational

Output log, human-review record, complaint link

One line to keep: a risk with no line in the books gets no data, no budget and no owner. Give AI its line before someone gives it to you.

What to Watch Next

  • The Digital Omnibus mandate. Coreper took up the Irish Presidency's compromise on October 7. If member states agree a mandate, trilogues on the GDPR and data track can start.

  • October 14. The Dublin International AI Summit (Virkkunen, McGrath, Hassabis, OpenAI's Sarah Friar) and ASML's third-quarter results land on the same day.

  • October 24. AWS European Sovereign Cloud runs without its global backbone for several hours. It is the first measurable sovereignty claim; ask for the report.

  • October 31. The ECB's AI-cyber action plans are due, and Mistral Large 4's weights are expected around the same time. Anthropic's public S-1 needs to appear by about then if marketing starts the week of November 9.

  • November 17–18 and December 2. The Apply AI Summit and the AI Board meet in Brussels; the Article 50(2) grace period ends two weeks later.

What to Read Now

Supervision

Market

Security

Enterprise AI

The One Call to Make

This week, ask your head of operational risk one question: "If an AI agent — ours, a vendor's or an attacker's — caused an incident tomorrow, which line of our loss taxonomy would it go in, and how many such events did we record this year?"

Why this one: It tests whether AI risk exists in your books or only in your policies. Basel has agreed to review the categories, the EBA will inspect your providers on frontier AI, and the ECB wants a plan by October 31. All three assume someone is counting. The question takes one meeting, and the answer tells you whether you have a history or a blank page.

If the answer is "it would depend" or "we'd work it out": That is the finding. Version one is a mandatory AI field with the nine sub-types in the Artifact, effective November 1, plus a back-tag of this year's events. It takes an afternoon for the taxonomy owner and a month of honest tagging.

Reply with one word: "tagged" or "untagged." Together with the mapped, ready, sent, contained, revocable and clocked tallies, you are building this newsletter's picture of where European AI operations actually stand.

That’s it for this week.

Seven weeks into the autumn and the questions have moved from what the model can do, to who controls it, to who is told, and now to who counts. Supervisors started counting this week. The firms that start their own count first will be the ones explaining their numbers, not their absence.

Until next Thursday, João

OnAbout.AI delivers strategic AI analysis to enterprise technology leaders. European governance lens. Vendor-agnostic. Actionable.

If this landed in your inbox from a forward — subscribe here to get the full picture every week.

Keep Reading