
Agentic AI
🛡️ Cyberattacks Get Agentic.
What happened
Anthropic said it disrupted campaigns in which AI moved beyond assisting hackers to orchestrating and executing substantial portions of attacks through multi-agent frameworks, with humans increasingly acting as supervisors. In one Russia-linked campaign, Anthropic said AI supported phishing, hotel Wi-Fi hijacking and WhatsApp takeovers, while malware was automatically rewritten when defenses detected it.
Why it matters
The security problem changes when attackers can put reconnaissance, coding, adaptation and execution into an automated loop. Anthropic also alleged industrial-scale attempts to extract Claude’s capabilities, including more than 151 million exchanges it attributed to Alibaba-linked operators and cases where Moonshot and DeepSeek routed live customer conversations through Claude; these remain Anthropic’s allegations rather than independently established findings.
What’s next
Agent security is likely to move beyond prompt filtering toward monitoring identities, tool use, network access and behavior across entire execution chains. That is an inference, but it lines up with the same-day push by enterprise and payments companies to create control and identity layers specifically for autonomous agents.
🎛️ Salesforce Builds a Control Plane for Agent Sprawl.
What happened
Salesforce introduced its Trusted Enterprise AI Harness, an architecture spanning context, agency, action, governance, security and models, alongside an AI Control Plane designed to discover, register, evaluate and govern both Salesforce and third-party AI systems. The architecture is being built to work through interfaces including MCP, APIs, Skills and plug-ins rather than requiring every agent to live inside Salesforce.
Why it matters
Salesforce is effectively betting that the model itself becomes only one layer of the enterprise agent stack. As models become more interchangeable, proprietary business context, permissions, deterministic execution rules and observability become the harder and potentially more defensible part of deploying agents at scale.
What’s next
Much of the underlying Salesforce technology is already available, while new Harness capabilities and the unified experience are scheduled to begin rolling out in early fiscal 2028; detailed packaging and pricing are still to come.
💳 Agentic Commerce Gets a Know-Your-Agent Layer.
What happened
Visa, Mastercard and Ant International launched an effort to create common standards for identifying and verifying AI agents that purchase goods and services for users. Their proposed “Know-Your-Agent” interoperability framework is meant to let card networks, wallets, marketplaces and agent platforms recognize trusted agents while retaining their own approval and risk controls.
Why it matters
Agentic commerce cannot scale on human identity alone. Payment networks need a way to determine which software agent is acting, whether it is authorized to act for a particular user and whether its transaction should be trusted—turning machine identity and delegated intent into new pieces of payments infrastructure.
What’s next
The initiative will build on Visa’s Trusted Agent Protocol, Mastercard’s Verifiable Intent and Ant International’s Agentic Mobile Protocol through BuildFin.ai, which is convened by the Monetary Authority of Singapore. The bigger test is whether the industry converges on interoperable credentials rather than a collection of incompatible vendor-specific systems.
Generative & Enterprise AI
🏦 OpenAI Turns ChatGPT Into a Finance Workstation.
What happened
OpenAI launched ChatGPT for Financial Services, combining GPT-6 Astra with built-in financial information from providers including LSEG, PitchBook and Daloopa. Developed with Morgan Stanley and Evercore as design partners, the product can research across sources, build financial models and generate client materials such as pitchbooks using a firm’s own templates.
Why it matters
Frontier-model companies are moving deeper into vertical software, where the product is not simply a better chatbot but a package of specialized data, security, compliance and workflow integration. In financial services, OpenAI is pairing model capability with role-based access, encryption and exportable audit logs which are features that matter as much as raw intelligence in regulated environments.
What’s next
OpenAI plans to add more financial data and expand beyond investment banking and equity research into the wider financial-services market. That puts it increasingly in competition not only with other model developers but with established financial-data and workflow platforms.
🏭 NVIDIA Makes Its Own Supply Chain the AI Test Case.
What happened
NVIDIA and Palantir announced a sovereign-AI stack that combines NVIDIA Nemotron open models with Palantir Foundry, AIP and its Ontology for complex supply-chain operations and NVIDIA is deploying it first inside its own supply chain. The companies say customers will be able to run the reference architecture in the cloud or on-premises while retaining control of proprietary operational data.
Why it matters
Enterprise AI is moving from answering questions about operations toward participating in operational decisions. NVIDIA says the system can identify constraints, model trade-offs, capture expert decision-making and recommend actions, making supply-chain knowledge itself something that can be encoded into specialized models rather than remaining scattered across planners, systems and documents.
What’s next
NVIDIA and Palantir plan to take lessons from NVIDIA’s deployment into industries including manufacturing, energy, healthcare, automotive and aerospace. The real proof will be measurable improvements outside NVIDIA’s unusually complex environment; the launch announcement does not yet provide independent performance evidence for broader deployments.
Physical AI
🚕 Europe’s Robotaxi Race Drops the Safety Driver.
What happened
Pony.ai and Verne said they began carrying invited passengers in fully driverless robotaxis on public roads in Zagreb, Croatia, using a 22-kilometer route connecting Verne’s headquarters and a business district with Zagreb’s airport. The companies describe it as a European first; that characterization comes from Pony.ai and Verne rather than an independent third-party assessment.
Why it matters
Verne’s service had already been operating with an onboard autonomous-vehicle operator; removing that person moves the deployment closer to the commercial end state of autonomous mobility. It also tests whether an autonomy stack developed and already operated driverlessly in China can transfer into European roads, regulation and operating conditions.
What’s next
Pony.ai and Verne plan to expand the driverless routes over the coming months toward the broader Zagreb operating area. The rides are being conducted under Croatian approvals for passenger-carrying autonomous-vehicle tests, making regulatory clearance and local operating performance the next gates to full commercial driverless service.
💡 Bottom Line
Agents are moving from answering questions to taking action inside companies, across payment networks, on public roads and in the hands of attackers. The winners will be the organizations that give agents room to move without losing track of who is acting, what they are allowed to do and how to stop them when something goes wrong.
⚙️ Try It Yourself
Take one workflow you already use with AI and add an identity + control layer around it.
Start with ChatGPT, Claude, or another agent tool and define three things before it acts: who the agent is, what it can access, and what requires approval.
Then pressure-test the workflow. Ask:
What happens if the agent is tricked?
Can its permissions be revoked instantly?
Are its actions logged?
Can another system verify that it is authorized to act?
That is the same shift showing up across today’s stories: Salesforce is building a control plane, Visa and Mastercard are working on “Know-Your-Agent,” OpenAI is adding regulated finance workflows, and NVIDIA/Palantir are pushing AI into operational decision-making.
The useful exercise is simple: don’t just ask what your agent can do but to decide what it should be allowed to do.
