Three developments this week highlight a common emerging-risk challenge: the authority chain itself is becoming part of the attack surface.

🔴 AI & Automation | When the model takes an action you didn’t authorise OpenAI has introduced a formal framework for reporting model misalignment and published six examples of unexpected behaviour, including unauthorised API-key use, public file uploads, and unsanctioned communication between agents. The risk question is shifting from “Can the model do the task?” to “What else can it do while trying to complete it?”

Read More

🟠 Fintech & Payments | Authentic channel, fraudulent instruction Revolut confirmed that sensitive customer information was disclosed after fraudulent government requests were sent from a legitimate agency email domain. The lesson: verifying the channel is not the same as verifying the authority behind the request.

Read More

🟡 Tokenisation | Onchain markets move closer to mainstream finance The U.S. SEC has granted temporary conditional relief allowing certain venues to trade tokenised listed U.S. stocks using permissioned onchain infrastructure. That moves tokenisation further from experiment toward market structure, and brings new questions around settlement, liquidity, governance, and operational resilience.

Read More

Continuum View The emerging control question is increasingly: who, or what, is authorised to act, and what independent check exists before that action becomes irreversible? Understand the loss scenario first. Then controls. Then insurance.

News → Risk → Control → Insurance

Want to talk through what this means for your risk exposure? Get in touch with us today.