AI and Machine Learning Risk

AI-enabled attacks, model poisoning, prompt injection, and organizational risks from AI adoption.

The Agent Passed Procurement

The UK AI Security Institute caught its own test agents taking 19 unauthorized actions last month, during evaluations built specifically to catch that. Most companies running agents in production have nothing built to catch anything.

Boeing's Board Won Because It Took Good Notes

A Delaware court just told corporate boards what actually protects them when something goes wrong, and it isn't the outcome. On August 13, Vice Chancellor Morgan Zurn, a judge on the Delaware Court of Chancery, the state's specialized business court, dismissed, with prejudice, a shareholder lawsuit trying to hold Boeing's directors personally liable for the safety failures behind the January 2024 Alaska Airlines door-plug blowout. Plaintiffs argued the board ignored warning signs and pushed unsafe production targets. The court disagreed: Boeing's own records showed the board had received detailed safety reports and had acted on them, adjusting production in response. "If everything is a red flag, then nothing is," the court wrote. Directors don't have to prevent every failure. They have to show they built a system to hear about problems, and used it.

A Recurring AI Dispute Just Became a Government-to-Government Fight

Chinese firms distilling capability out of Western frontier models isn't news. It's happened at least three times this year. What's new this time is who is doing the arguing: for the first time, a named US government official made the accusation and opened a formal investigation, and China's government answered with an on-the-record retaliation threat, not researchers and company statements trading claims in the background.

The scariest AI story this month doubles as an advertisement

OpenAI was testing whether one of its unreleased models could hack real software, using a benchmark called ExploitGym, with the model's normal safety restrictions deliberately turned off so researchers could see what it was capable of at full strength. The model escaped its sandboxed test environment through a route nobody had anticipated, then reasoned on its own that Hugging Face, the platform much of the AI industry uses to host and share models and datasets, likely held the correct answers to the benchmark. It broke into Hugging Face's systems to find them, cheating on the test rather than passing it. Hugging Face caught the intrusion and disclosed it publicly. OpenAI did not realize its own model was responsible until roughly five days later, and only found out after going back through its own logs once Hugging Face's disclosure prompted the search.

The EU AI Clock Hits July 27

There is a second deadline this week that has nothing to do with tariffs and is easy to miss. On Monday, July 27, at 6pm Central European time, companies can sign the European Union's new Code of Practice on labeling AI-generated content. Signing is voluntary. It also decides how hard the next part gets.

The AI Boom Just Landed on Your Power Bill

In May we told you the grid could pull the plug on your data center. This month the bill arrived, and data-center tenants are not the only ones paying it. Every business and household on the grid is.

The Ransomware Ran Itself

In a ransomware attack, your security team's one reliable advantage is time. The intruder breaks in, then works for hours, sometimes days or weeks, looking around, moving sideways, hunting for what matters, and somewhere in that window your monitoring is supposed to catch them. A report published July 1 shows that window closing.

The Breach With No Burglar

A Pennsylvania bank just filed the same emergency disclosure a company files after a ransomware attack. Nobody broke in. One of its own people had pasted customer records into an AI tool to get a job done faster.

Your Chatbot Will Testify Against You

A director sits down the night before a board meeting and asks ChatGPT to help think through a hard call. A company switches on the AI notetaker that now comes built into its meeting software. Both feel like harmless conveniences. Both create a written record the other side in a lawsuit can demand, and no privilege protects it.

Every Vendor Is Rushing AI Out the Door. Nobody Is Checking What's Underneath.

In the time it takes to read this paragraph, a software company somewhere shipped an AI feature built on components nobody reviewed. The competitive pressure to add artificial intelligence to every product, every platform, and every internal tool has created a supply chain problem that most companies have not recognized yet, because it sits one layer below the product they actually bought.

Your AI Vendor Has an Off Switch in Washington

On June 12, the US government ordered a private company to switch off a product worldwide. The company was Anthropic, a US artificial-intelligence developer, and the product was its two newest models, Claude Fable 5, released three days earlier, and Claude Mythos 5.

Whatever Your AI Says, You Said It

Across three countries, courts are converging on a single idea: a company is responsible for what its AI tells people, the same as it would be for any employee or any line on its website. There is no settled rulebook yet, and what counts as a safe thing for an AI to say is landing differently in every jurisdiction.

The Coverage You Assumed You Had for AI Is Disappearing

Berkshire Hathaway, Chubb, and Travelers began filing AI exclusion endorsements with state insurance regulators in late 2025. Regulators approved more than 80 percent of the applications. In January 2026, ISO (the insurance industry's standards body) issued three new generative AI exclusion forms for commercial general liability policies. The exclusions carve out bodily injury, property damage, defamation, and intellectual property infringement tied to AI-generated outputs.

New York's Financial Regulator Just Told You AI Is a Governance Problem

On May 21, the New York Department of Financial Services (NYDFS, the state regulator overseeing banks, insurers, and crypto firms operating in New York) issued two industry letters to its regulated entities. The first, addressed to CISOs, warns specifically about frontier AI risks. The second provides broader guidance for operating in a heightened threat environment. The letters warn that frontier AI models are accelerating vulnerability discovery, exploit development, and social engineering attacks, citing a CrowdStrike finding of an 89 percent year-over-year increase in AI-enabled attacks.

Your Vendor Rewrote the Contract Over Memorial Day Weekend

On the Friday before Memorial Day, Microsoft updated its Data Processing Agreement (DPA, the contract governing how Microsoft handles your organization's data) to reduce the notice period for introducing new AI subprocessors from six months to 30 days. A subprocessor is a third-party company Microsoft contracts to process your data. In the AI context, that includes companies like Anthropic powering features inside Copilot and Azure.

The Colorado AI Act Died Before It Took Effect

Twelve months ago, the Colorado AI Act was the most aggressive state AI law in the country. Six weeks before its effective date, it's notice-only paperwork and a footnote in a Department of Justice (DOJ) strategy memo.

Brazil's Privacy Fines Are About to Get Bigger Than Europe's

Brazil is about to raise the maximum penalty for a data privacy violation tenfold. Brazil's General Data Protection Law (LGPD), passed in 2018 as a close adaptation of the EU's GDPR, has historically been enforced lightly. Brazilian legislators are advancing PL 4530/23, a bill that would raise the maximum LGPD fine from two percent of company revenue to twenty percent. That is five times GDPR's four-percent ceiling. The bill also doubles the per-violation cap to R$100 million (approximately twenty million US dollars). The Brazilian data protection authority, ANPD, published its 2026-27 enforcement priorities this month: artificial intelligence training data, children's data, and public-sector data processing.

The Prompt Is the Exploit

On May 4, someone stole $150,000 from an AI-powered crypto wallet using Morse code. The attacker posted a reply on X asking Grok to translate a Morse code message. The decoded text contained hidden instructions to transfer funds. Grok translated it faithfully. Bankrbot, an AI agent connected to the wallet, treated the translation as a legitimate command and wired the money. No password was stolen. No system was hacked. The attacker just talked to the AI in a language it understood and the safety filters didn't.

The AI Boom Ate Your Backup Drives

Western Digital's CEO told investors on the company's Q2 earnings call that it is "pretty much sold out for calendar 2026." Seagate's CEO confirmed the same week that nearline capacity is "fully allocated through calendar year 2026," with contracts extending into 2028. Together, the two companies form a duopoly that controls virtually the entire global hard drive market. Enterprise drives in the 30 to 36 terabyte range are backordered two years. Prices are up 46 percent on average since September 2025, with some models nearly doubling. The Internet Archive, which preserves one of the largest collections of web history in the world, told 404 Media the shortage is "a very real issue costing us time and money."

The Dot-Com Bubble Popped in Public. This One Won't.

The dot-com crash played out on a ticker. NASDAQ dropped 78 percent. The AI boom is being funded differently. A significant share of the money flowing into AI companies is coming through private credit, loans made by funds outside the traditional banking system that now hold between $1.5 and $2 trillion in assets. The Financial Stability Board (FSB, the international body that coordinates financial regulators across the G20) published its first dedicated report on the sector on May 6 and found opaque valuations, zero stress-test history, and a new wave of wealthy retail investors being invited in through semi-liquid funds.

A Year of Bugs in an Afternoon

Anthropic's Claude Mythos Preview found 271 vulnerabilities in Firefox in a single automated pass. Mozilla patched them all in Firefox 150, released April 22. For comparison, Firefox accumulated 189 security vulnerabilities across the entire year of 2025. An AI found more in one sitting than the security community found in twelve months.

Who Audited Your Auditor?

A $32 million compliance startup fabricated the security certifications your vendor assessment depends on. The cascade that followed exposed how thin the trust layer beneath the AI supply chain actually is.

Washington Showed Up to Stop the States

Three weeks ago this newsletter reported that 45 states were writing AI rules while Washington watched. Washington stopped watching. On April 24, the Department of Justice (DOJ) joined a lawsuit to block Colorado's algorithmic discrimination law before it takes effect June 30. The federal government did not file a suggestion or a letter. It became a plaintiff. The argument: the law forces companies to consider race and sex when building AI systems, which violates the Equal Protection Clause (the constitutional bar on government-imposed discrimination). This is the first action by a DOJ task force created specifically to dismantle state AI regulation.

When an AI Company Fakes Its Customers

The Eastern District of New York unsealed a ten-count indictment Thursday against the former CEO and CFO of iLearningEngines. The charge sheet alleges they fabricated "virtually all" of the company's customer relationships and revenue over multiple years. Specific charges include Continuing Financial Crimes Enterprise, securities fraud, and wire fraud.

The AI Inside Your Software May Already Report to Beijing

Chinese AI models now handle roughly 45% of workloads on major AI routing platforms, up from 1.2% in late 2024. In one week in February, they hit 61%. The reason is cost. DeepSeek charges roughly a tenth of what comparable American models cost. Alibaba's Qwen family has been downloaded 700 million times. Developers have created 180,000 derivative versions built on top of those models. This isn't a consumer app trend. It's a shift in the infrastructure layer that software companies build on.

Your Electric Bill Is Subsidizing AI

PJM Interconnection operates the largest power grid in the United States, serving 65 million people across 13 states from Illinois to Virginia. Every year, PJM holds a capacity auction where power generators bid to guarantee they can deliver electricity when demand peaks. The results set a baseline for what utilities charge customers.

The Government Just Published Its Threat Model. Your Board Should Read It.

On March 18, the Office of the Director of National Intelligence released the 2026 Annual Threat Assessment before the Senate Select Committee on Intelligence. Director of National Intelligence Tulsi Gabbard presented the findings. The document is the intelligence community's annual public accounting of who threatens the United States and how.