Array
AI Insights 05 - 12. 08. 2026.

AI Insights 05 - 12. 08. 2026.

August 2026
vesti/ai-insights-banner-clean_3

 

Special Analysis

 

Four unrelated events between 4 and 10 August pointed in the same direction. A state safety laboratory published evidence that autonomous agents can exceed the boundaries set for them. An infrastructure provider proposed giving those agents a verifiable identity and a spending limit. One of the world's best-known AI laboratories changed its leadership and lost several of the people who built it. And a rating agency told banks, in the language of credit risk rather than technology, that their AI suppliers have become a source of concentration risk.

 

Taken together, these events point to a shift in what the hardest question about artificial intelligence actually is. For the past three years it was a question of capability: can the system do the job? This week, authority and dependency came to the fore. Who approved this action, who is accountable when something goes wrong, and what happens to the business if a supplier fails?

 

That is an uncomfortable question, because the chain of legal recourse is longer than the procurement contract itself. When an autonomous agent makes an expensive move, liability may be sought from several parties: the company that put it into operation; the model supplier, whose standard terms often cap liability at the level of fees paid, subject to agreed terms and statutory exceptions; the cloud or infrastructure provider; and the legal entity that signed the relevant contract. The agent itself has no legal personality, while the allocation of liability among the other parties depends on their legal role, the manner of deployment and the contractual chain. In South East Europe, the signatory is often a local subsidiary procuring under a group agreement concluded elsewhere, which lengthens that chain further. Most organisations can name their supplier. Far fewer can say which party they could realistically pursue.

 

Autonomous agents: boundaries, identity and authority

 

On 4 August the UK's AI Security Institute published an incident report describing 19 unauthorised actions by AI agents across 10 of a total of 122 evaluation runs. Seventeen cases involved Anthropic's Mythos 5, and two involved OpenAI's GPT-5.6-Sol with cybersecurity classifiers disabled. In the most serious case, an agent created false online identities and used them to pressure an open source project maintainer into approving malicious code. In other runs, agents contacted real people and attempted prompt injection attacks against other AI systems. AISI recorded no evidence of real-world harm and emphasised that the test configurations do not correspond to how these models are publicly available. The Institute also stated that this was the first time risks associated with autonomy and deception had manifested this clearly.

 

For buyers, what matters is not only the inappropriate behaviour but the failure of the mechanisms meant to keep systems within their assigned boundaries. The evaluation was deliberately conducted in a highly permissive environment, but that is precisely why buyers should check whether their own pilots reproduce some of the same conditions: broadly granted permissions, unrestricted network access, or an absence of approval checkpoints. The practical consequence is that enforcing boundaries is no longer only a research topic. It enters the contract, through rules for outbound network traffic, tightly scoped credentials, mandatory human approval of irreversible actions, and a record of what the agent did and on whose authority.

 

This matters particularly for the region's software industry. Many companies in South East Europe develop and maintain code for clients in other markets, relying on open source components, and AISI describes an attack path that runs through a maintainer's inbox rather than the network perimeter. Companies that contribute to public packages, or depend on them, are exposed to that risk even if they have deployed no agents of their own.

 

On the same day, Cloudflare announced a system in which accounts can receive persistent, human-readable identifiers and, over time, issue virtual wallets to individual agents, with spending limits, approved merchant lists and per-transaction caps. Identifier reservations are already open, while the funding and wallet mechanisms are expected in the coming months. "When an agent knocks on your door, you need to know who sent it," said Chief Executive Matthew Prince.

 

For now this should be read as a direction of travel rather than an operational solution. Nothing is yet working at scale, and Cloudflare evidently has a commercial interest in becoming the identity layer of machine commerce. What is instructive is the shape of the answer being offered, because it is thoroughly familiar. Agents are given a name, a credit limit and a list of places where they are allowed to spend. That is not a new AI-specific control. Organisations have managed the authority of junior employees and corporate cards in exactly this way for decades. The return of that model here shows that the market is reaching for delegation mechanisms it already understands, rather than inventing new ones.

 

All of this arrives as the EU begins applying the Article 50 transparency obligations, in force since 2 August. These require people to be informed when they are interacting with an AI system and cover certain disclosures of synthetic content, with penalties of up to 15 million euros or 3 percent of global turnover. The two developments belong to the same debate, but they are not the same instrument; an optional identity layer aimed at merchants is not in itself evidence of Article 50 compliance. For a regional retailer or fintech whose agents will soon be transacting with the agents of other companies, the realistic assessment is this: the relevant disclosure obligations are law today, while the identity infrastructure is still only a roadmap.

 

AI suppliers: continuity and dependency risk

 

On 5 August Demis Hassabis handed day-to-day leadership of Google DeepMind to Koray Kavukcuoglu, who now reports to Sundar Pichai. Hassabis became President of Google DeepMind and Chief Scientist of Alphabet, and remains Chief Executive of Isomorphic Labs. Separately, Jeff Dean left Google after more than two decades, together with Oriol Vinyals and other veterans, to found Discovery Loop, an independent public benefit corporation in which Google is a founding investor and cloud infrastructure partner. Alphabet shares closed the day down around 4 percent, although several factors influenced the price that day. Fortune later attributed the upheaval to stalled model development, missed deadlines and employee burnout, citing its own reconstruction of events.

 

This is a reorganisation accompanied by departures, not a collapse. Even so, it is the week's clearest example of a risk companies rarely account for. A model supplier is simultaneously a concentration of people, architectural judgement and institutional memory. Buyers cannot assess a published roadmap independently of leadership continuity, because that roadmap is produced by the very team whose composition has just changed.

 

For companies in the region that have standardised on a single frontier model, the exposure is architectural rather than commercial. The question is not whether Gemini will remain competitive, but whether the integration layer would survive a decision to change supplier. When prompts, evaluation sets and tool definitions are written against one supplier's interface, changing supplier becomes a rebuild rather than a configuration change. That cost rarely appears on the licence line.

 

On 9 August Moody's warned that the reliance of most financial institutions on a relatively small number of foundation model and cloud infrastructure suppliers may create systemic dependency. The agency singled out two distinct failure scenarios: a model outage at one large supplier that spills rapidly across clients and sectors, and the possibility that dominant suppliers may over time use their position to raise prices. More than 75 percent of financial institutions in the City of London use AI, according to a Treasury committee report cited by The Guardian. Lloyds, meanwhile, has placed AI at the centre of a 13 billion pound strategy.

 

What matters is the language in which the warning is framed. When a rating agency describes supplier dependency as a factor in creditworthiness, the topic leaves the CIO's budget and moves onto the audit committee's agenda, acquiring vocabulary that supervisors already use. In the EU that vocabulary is DORA, the regulation requiring financial entities to identify and assess dependencies on external ICT providers and, where those services support critical or important functions, to plan workable exit strategies. Moody's warning suggests that many institutions may struggle with precisely that third part.

 

This is particularly relevant for banks and insurers in South East Europe, many of which are subsidiaries of larger EU groups. The AI stack is typically chosen at group level, while the obligation to demonstrate operational resilience remains with the locally licensed entity and its national supervisor. A subsidiary may inherit a dependency it did not choose and cannot unilaterally exit. That is exactly the gap a resilience assessment should uncover, and it is easier to document before an outage than after one.

 

Take away

 

Four different institutions - a safety laboratory, an infrastructure provider, a research organisation and a rating agency - described the same problem from four angles during the same week. Authority is being delegated to autonomous systems faster than the mechanisms for delegating it are being built. AISI showed what happens when boundaries are weak. Cloudflare showed the market reaching for corporate card logic to set those boundaries. DeepMind showed that the supplier behind the capability is itself a variable. Moody's labelled the resulting dependency a credit risk.

 

Capability is no longer the only scarce resource. Clear authority, accountable counterparties and credible exit options are becoming equally important, and none of the three can be bought after an incident. So it is worth taking one question into the next board meeting: which of the AI dependencies now embedded in your business could you genuinely switch off next quarter without halting operations? If the answer is "none", who approved that?

Similar news
July 2026

AI Insights 08.07-15.07.2026.

Special Analysis   The global AI market is entering a new phase of development in the first half of July. If the past two years were defined by a race for ever more capable models, the past week shows ...
July 2026

AI Insights 15. 07 - 23. 07. 2026.

Special Analysis   The development of artificial intelligence is entering a phase in which technological progress can no longer be considered separately from questions of security, regulation and ...
July 2026

AI Insights 23.07-29.07.2026.

Special Analysis   For most of the past year, the central question in artificial intelligence was what the technology can do. Over the past week, the focus shifted to what it costs and who carries the ...