Daily Pulse · Tuesday, September 15 · 4 min
Daily Pulse · Tuesday, September 15, 2026
Transcript
Hi, this is Koko from Koko Knows, and today's brief has a number that's going to stick with you: eighty nine point five percent. That's the share of organizations who suffered a GenAI breach in the past year, according to AvePoint's new State of AI report, up from seventy five point one percent just a year ago. Eighty eight point four percent reported an AI agent breach specifically. And here's the part that should worry you more than the raw numbers: confidence in preventing unauthorized access actually went up over the same period. Enterprises are getting more comfortable with their AI security at the exact moment their AI security is getting worse. That disconnect between rising breaches and rising confidence is basically the theme of everything else happening in AI governance right now, so let's walk through it.
Start with Cloudflare, because this one takes effect today. Its block on mixed-use AI crawlers on ad-supported pages is now live for new customers and anyone on a free plan. If you're running a retrieval pipeline or an agent that depends on generic web crawling for grounding, this is the kind of infrastructure shift that breaks things quietly, weeks after it happens, when nobody remembers to check the crawler logs. Worth watching whether RAG vendors start reporting reliability drops or make a hard pivot toward Cloudflare's Pay Per Crawl and dedicated user agents in the coming weeks.
On the deployment side, Anthropic had a big day in Japan. It struck simultaneous deals with NEC and Cognizant to wire Claude Opus four point seven and Claude Code directly into enterprise and consulting platforms serving finance and manufacturing clients. That's Anthropic going deep into regulated, high-stakes industries at scale, which makes the breach numbers from AvePoint feel less like an abstract statistic and more like a live risk sitting inside real financial infrastructure.
Now, the trends underneath all this tell a pretty consistent story. Deloitte says eighty nine percent of agent pilots fail to make it to production. Teradata found seventy eight percent of enterprises are running at least one agent pilot, but only fourteen percent have scaled anything organization-wide. That lines up with Gartner's enterprise-readiness warning from just a day earlier. Everyone's experimenting, almost nobody's actually operationalized it safely.
Then there's shadow AI. HiddenLayer found that one in eight reported AI breaches now ties back to agentic systems, and seventy six percent of organizations say shadow AI is a probable problem for them, up fifteen points from last year. Combine that with AvePoint's numbers and you get a clear picture: security teams are losing visibility faster than vendors are gaining trust.
There's also a quieter fight brewing over definitions and money. The Register is digging into the open-weight versus open-source labeling dispute, and Accenture flagged a tokenomics visibility gap. Different fights, same root cause. Vendors control the definitions and the metering, and buyers can't fully verify what they're licensing or what they're actually spending. That opacity compounds everything else on today's list.
On the policy side, Trump and House Speaker Mike Johnson both rejected the Amodei-led push for a coordinated AI slowdown. Meanwhile Microsoft opened its own Humanist AI Code of Conduct for public consultation, a six week comment window that could end up either becoming an industry template or a rival framework to whatever OpenAI, Anthropic and Google are talking about. So labs are moving faster on voluntary governance than Washington is moving on anything binding. Keep an eye on that consultation window, it's a real signal of where self-regulation is heading.
On the product front, a few things actually shipped today worth knowing about. OpenAI pushed a ChatGPT healthcare integration live. Anthropic shipped Claude Fable five point one. And Nvidia's RTX platform now brings Perplexity's Portable Computer to Windows.
So here's the through-line for today: adoption is outrunning verification everywhere you look, from breach rates to pilot scaling to crawler access to labeling standards. The tools are shipping. The trust infrastructure around them is not keeping pace.
That's your rundown. Thanks for spending a few minutes with me, this has been Koko from Koko Knows. Come back tomorrow for more.