Filings tagged: AI
What AI can genuinely do for your business, the risks worth taking seriously, and the hype worth ignoring.
-
The website your AI invents, and the attacker waiting to register it
· AI Security
AI assistants confidently hand back web addresses that do not exist. Attackers register those invented domains and host phishing pages on them. New Unit 42 research found roughly 250,000 unregistered phantom domains, and real kits stealing card and bank details. Here is how the attack works and what to tell your team.
-
You can't blame the AI
· AI Security Commentary
If your business publishes anything an AI wrote, a chatbot answer, a summarised quote, advice to a customer, you own what it says. 'The AI got it wrong' is not turning out to be a defence, and a German court has just said so about Google.
-
Five Eyes says the AI timeline is months, not years
· Security AI
On 22 June the intelligence chiefs of the UK, US, Canada, Australia, and New Zealand issued a joint warning that frontier AI is changing the threat in months, not years. The actions they ask for are not new. They are now urgent.
-
What Lloyds Bank actually does when it deploys an AI agent
· AI Security
Lloyds Banking Group's security director shared at Infosecurity Europe how the bank actually deploys agentic AI in production. Eleven 'AI bets', a twelfth dedicated to security. Signed tools the agents cannot create. An internal agent marketplace. The world's first production red-team environment using OWASP Top 10 for agentic AI. They saw agent hijack.
-
Attackers are using Claude as the bait
· Security AI
Microsoft's threat intelligence team has tracked phishing campaigns built around ChatGPT, Claude, DeepSeek, and Copilot. A South African ChatGPT-themed wave hit 100,000 mailboxes a day. A Claude-themed wave reached 2,000 organisations across the US, UK, and India. The brand is the lure, the payload is the same old stealer.
-
The UK just spent £7 billion on AI. Here's the bit for SMEs.
· AI Commentary
London Tech Week 2026 closed with around £7 billion of announced AI investment, £1.1 billion of it a government hardware plan, £200 million for adoption and skills, and £150 million tied to a fund managed by a former Intel CEO. Most of it goes to large companies. A useful slice is reachable by smaller ones.
-
Your staff are using AI. You're paying twice.
· AI
UK workers use AI for almost everything and report it saves them twelve hours a week. They also spend 6.4 hours a week fixing what it produced. Eighty per cent of UK IT leaders just had an unplanned AI cost increase. The numbers underneath the productivity story are sharper than the headlines.
-
What NCSC said this month: agentic AI and zero trust
· Security AI
The NCSC published two pieces of guidance in a fortnight that an SME owner can actually use. One is about agentic AI, the kind that takes actions on your behalf. The other is about zero trust network access. Both share the same underlying advice: the user's location stopped being a security signal a while ago.
-
The Bank of England just named frontier AI as a stability risk
· AI Commentary
On 18 May the Bank of England, the FCA, and the Treasury jointly told regulated firms that frontier AI now exceeds what a skilled attacker can do. If you sell into financial services, the diligence questions you get this year are going to look different.
-
Business as code, not AI as business
· AI Commentary
A new wave of startups is publishing 'AI-native' org charts where seven named LLM agents do most of the work. The first step isn't restructuring around agents. It's making your business legible enough that anything, a new hire, an auditor, or eventually an agent, could read it and act on it. AI can help you get there. Future agent costs are a reason not to skip past it.
-
Your AI policy should say something
· AI Security Commentary
Most AI policies are vendor templates with the company name swapped in. They ban the obvious, permit the vague, and tell you nothing about how the business actually wants AI used. A coherent policy is a short one that takes a position.
-
The NCSC says brace for a patch wave. The NHS is pulling the curtains.
· Security AI Commentary
The NCSC has told UK organisations to prepare for a wave of urgent patches as AI accelerates vulnerability discovery. The same week, NHS England decided the answer was to make its open source repositories private. Only one of those approaches actually fixes anything.
-
AI agents and the shadow AI you already have
· AI Security
Two thirds of UK organisations cannot account for what staff share with AI tools. Now agentic AI is being deployed faster than anyone can govern it. The two problems are the same problem.
-
Sovereign AI is only sovereign if you can actually switch
· AI Infrastructure Commentary
Two-thirds of UK IT leaders say they have an AI exit plan. Nearly half admit switching would seriously disrupt the business. A plan you can't execute is not a plan.
-
Prompt injection is not the new SQL injection
· AI Security Commentary
Schneier and co have reframed prompt injection as 'promptware': a full 7-stage kill chain. The uncomfortable truth: LLMs can't distinguish instructions from data. This isn't a bug you can patch.