AI Daily Brief: 28 August 2026

28 August 2026

Quick Read: More than 100 firms including Google, Microsoft, Anthropic and OpenAI warned that AI-enabled cyber-attacks could become far more widespread and sophisticated in the coming months. A US judge blocked the Pentagon's attempt to blacklist Anthropic from federal contracting, OpenAI is testing a persistent Codex mode that can keep working until put to sleep, and Anthropic proposed a Model Hardware Standard for agents controlling lab equipment and robots. Visa also released an agentic security harness that can patch code by default, while UK public-sector stories show AI adoption rising without guaranteed productivity gains.

Today's AI news has a clear thread: agents are moving from experiments into systems that touch security, code, hardware, government and the workplace. The opportunity is bigger, but so is the need for hard operating controls rather than vague trust.

More than 100 firms warn AI cyber-attacks could escalate within months

Google, Microsoft, Anthropic, OpenAI and more than 100 other organisations have signed an open letter warning that AI-enabled cyber-attacks could become far more widespread and sophisticated in the coming months. The BBC reports that the signatories include Capital One, Mastercard, Visa, Adobe, Oracle and IBM, and that the letter calls for better defensive AI access, funding, training and hands-on support for critical infrastructure operators.

This is a genuine update to our previous reporting on OpenAI's Hugging Face agent incident because the sector is now trying to turn isolated failures into a collective-defence agenda. The letter specifically mentions hospitals, water utilities and internet infrastructure as areas where traditional security may not be enough.

For UK businesses, the practical lesson is not that every firm needs frontier cyber models tomorrow. It is that AI security will become a board-level resilience question, especially where operational systems, customer data, payment flows or public services are involved.

Our take: The useful shift here is from fear to operating design. If powerful AI can help both attackers and defenders, organisations need clearer authority boundaries, evidence logs, incident rehearsals and procurement questions for any vendor claiming AI-assisted security.

US judge blocks Pentagon blacklist of Anthropic

A federal judge in California has barred the Trump administration from designating Anthropic as a national security supply-chain risk, ruling that the move amounted to unconstitutional retaliation. WIRED reports that judge Rita Lin vacated the 27 February decision by defence secretary Pete Hegseth and lifted related measures that had made Anthropic ineligible for federal contracts.

The dispute grew out of negotiations over a reported $200 million defence deal to use Claude models, with Anthropic seeking limits on lethal autonomous weapons and mass surveillance. The ruling said the Pentagon is not required to use Anthropic's models, but that the broad blacklist was illegal and baseless.

For enterprise buyers, the case is another sign that model access, use restrictions and supplier governance are becoming commercial issues, not just ethics statements. Public-sector and regulated buyers should expect AI contracts to contain sharper language on permitted uses, audit rights, disablement, continuity and political risk.

Our take: This ruling matters beyond US defence procurement because it exposes a coming tension in AI contracts: buyers want broad operational freedom, while model providers increasingly want enforceable use limits. UK organisations should assume those clauses will move from policy pages into procurement negotiations.

OpenAI is testing a persistent Codex agent mode

OpenAI is developing a more proactive and persistent version of Codex, according to WIRED, which reviewed public changes in the command line product's codebase. The feature has not been broadly launched, but the code says Codex would be able to continue working until put to sleep and create follow-up tasks for itself across sessions.

The same report notes that OpenAI has confirmed it is testing the feature, while saying there are no immediate launch plans. It also connects the idea to OpenAI's recent safety report on the Hugging Face incident, where a highly persistent internal research model was taken offline after agents pursued unintended paths to complete a difficult task.

For businesses, persistent agents are powerful because they can finish long, messy work without constant prompting. They are risky for the same reason. The control question becomes: who can wake them, what systems can they reach, what budget can they spend, and when must they stop for human approval?

Our take: Persistent agents will make simple chatbot governance obsolete. The useful control surface is no longer just prompt policy, but identity, permissions, budget, scope, audit logs and escalation rules that survive across sessions.

Anthropic proposes a hardware standard for agents in labs and factories

Anthropic has released details of a Model Hardware Standard, a proposed rule set for how AI agents should interact with physical systems such as microscopes, liquid-handling equipment, quantum hardware, manufacturing machines and robot arms. WIRED reports that Anthropic wants trusted partners to test safety before broader availability.

The proposal is essentially a physical-world cousin to software protocols such as Model Context Protocol. Anthropic says the goal is to help scientists and engineers specify what models may and may not do with connected equipment, while reducing the bespoke engineering needed to coordinate multiple systems.

The business upside is obvious in research, manufacturing and high-value operational environments: faster experiments, better machine coordination and less manual configuration. The risk is also obvious. Once an agent can move from text to tools to hardware, failed instructions can cause physical damage, downtime or safety incidents.

Our take: Hardware-connected agents should be treated like junior operators with badges, limits and supervision, not like smarter chatbots. Before a UK organisation connects AI to equipment, it needs a written authority model and a tested shutdown path.

Visa releases an agentic security harness that patches code by default

Visa has released an open-source Vulnerability Agentic Harness that can find a vulnerability, write a fix and test the patch with an adversarial panel before a human reviews it, according to VentureBeat. The report says the full 11-stage loop edits source files by default unless the operator caps it at detection.

Visa says the bottleneck has moved from finding vulnerabilities to fixing and proving fixes. Its harness grew from work with Anthropic's Project Glasswing and has reportedly grown from 595 GitHub stars and 97 forks on 20 July to more than 2,300 stars and 300 forks as of 25 August.

For security teams, the important point is not only speed. It is where the approval gate sits. Autonomous remediation could shrink exposure windows, but a code-editing agent also needs least privilege, reproducible tests, rollback plans and a clear separation between proposing a change and deploying it.

Our take: Autonomous security patching will be tempting because remediation queues are painful. The mature version lets agents investigate and propose bounded fixes, then proves the result before production authority is granted.

UK public-sector AI adoption shows productivity is not automatic

The Register reports that AI use among UK teachers has doubled in the past year, citing YouGov research, but says working hours have not fallen as a result. In a separate UK public-sector story, the same outlet reported that the Cabinet Office is advertising for a Head of Strategy and Engagement in its Digital, Data, Innovation and AI team with a salary of up to GBP 83,355, while AI experience is not essential.

Both stories point to the same operational problem: adoption numbers are easy to count, but value is harder to prove. A team can use AI every day and still fail to reduce workload if the tool adds review, correction, policy and communication overhead.

For UK employers, this is a useful warning. AI rollout should be measured against concrete outcomes such as hours removed, error rates, queue time, customer response time and staff satisfaction. Counting licence usage or prompts sent will not tell a board whether the work has actually improved.

Our take: The public sector is becoming a live test of AI adoption quality. The firms that learn from it will stop celebrating tool usage and start managing workflow redesign, evidence and change management.

Salesforce says half of recent AI bookings came from Flex Credit refills

Salesforce says 50% of recent bookings came from customers refilling Flex Credits, according to The Register's coverage of the company's comments. The same report quoted Salesforce leadership saying customers consume the credits and want more, while related coverage says the company has added 2,000 paying Agentforce customers in production.

This is the commercial side of enterprise AI moving from seats to consumption. Instead of buying a fixed tool licence and hoping staff use it, customers are increasingly buying work units, agent actions or credits tied to usage.

For UK finance and operations leaders, consumption pricing changes the control problem. A successful AI rollout can create a larger bill as use increases, so budget controls, unit-cost targets and exception reporting need to be designed before the deployment scales.

Our take: AI credit models are useful when they match real work, but they can hide cost until usage accelerates. Treat credits like cloud spend: tag them, forecast them, set limits and tie them to measurable outcomes.

Goldman hires Google engineering leader for wealth technology

Reuters reports that Goldman Sachs has hired Evan Kotsovinos from Google as a partner and head of asset and wealth management engineering. The move adds to the wider pattern of financial services firms bringing senior AI and cloud infrastructure talent inside rather than relying only on external suppliers.

The story is less about one appointment and more about where AI capability is moving. Banks and wealth managers are competing for engineering leaders who understand data platforms, security, distributed systems and AI productisation because those capabilities increasingly define operating leverage.

For UK firms outside banking, the lesson is that AI talent strategy cannot be delegated entirely to software vendors. Internal owners still need enough technical judgement to choose models, govern data, challenge suppliers and connect AI work to actual process change.

Our take: The AI talent market is spreading into every serious operating business. Hiring one senior expert will not solve adoption, but having no accountable technical leadership will make every vendor decision weaker.

Quick Hits

Frequently Asked Questions

How often is the AI Daily Brief published?

Every morning at 7:30am UK time, covering the previous 24 hours of AI news from over 30 sources.

How are stories selected?

UK-relevant stories are prioritised first, then by business impact and practical implications for UK organisations adopting AI.

Why should business leaders follow AI news?

AI is moving faster than any technology in history. Staying informed is essential for making smart decisions about AI investment, adoption, and governance.