Skip to main content
    All shows

    Koko Daily · Tuesday, September 15 · 10 min

    Koko Daily · Tuesday, September 15, 2026

    0:0010:37
    Speed

    Transcript

    Koko: It's Tuesday, September fifteenth, I'm Koko, with Max and Sam — let's blitz it.

    Max: AvePoint's new security report finds eighty-nine and a half percent of companies had a GenAI breach in the past year — up from seventy-five percent last year.

    Sam: And yet confidence in preventing unauthorized access went UP. Read that twice.

    Koko: Cloudflare's crawler lockdown officially goes live today, blocking mixed-use AI bots on ad-supported pages.

    Max: Anthropic just wired Claude straight into Japan's enterprise stack, deals with both NEC and Cognizant, same week.

    Sam: Google's A2A protocol formally joined the Agentic AI Foundation — the interop layer is consolidating fast.

    Koko: Microsoft opened public comment on its Humanist AI Code of Conduct, six weeks on the clock.

    Max: HiddenLayer says one in eight reported AI breaches now trace back to agentic systems specifically.

    Sam: And The Register's digging into the open-weight-versus-open-source labeling fight — turns out the label decides who controls the terms.

    Koko: Breaches, borders, and labels. Let's dig in.

    Koko: Okay, this AvePoint number stopped me cold. Eighty-nine and a half percent of orgs had a GenAI breach in the last year. That's basically everyone.

    Max: Up from seventy-five percent just twelve months ago. And agent breaches specifically? Eighty-eight point four percent. This isn't a tail risk anymore, it's the median experience.

    Sam: But here's the part that actually unsettles me — confidence in preventing unauthorized access went up at the same time. People feel safer while getting hit more.

    Koko: That's not resilience, that's denial with better dashboards.

    Max: [chuckles] Or it's the classic thing — you survive a breach, you patch the one hole you saw, and you feel like you solved security instead of just plugging a leak in a boat with forty more leaks.

    Sam: Right, and it lines up exactly with what HiddenLayer's finding — one in eight breaches now tied to agentic systems, and shadow AI usage up fifteen points year over year. People are running agents leadership doesn't even know exist.

    Koko: So confidence is rising because visibility is falling. You can't be scared of what you can't see.

    Max: Which is the uncomfortable overlap with yesterday's Gartner story — CIOs are told the labs aren't enterprise-ready, and now the breach data says neither is the buyer's own house.

    Sam: It's a two-sided failure. Vendors ship agents fast, buyers deploy them faster, and the audit trail shows up last, if at all.

    Koko: So what actually closes this gap — more tooling, or just... slowing down the rollout?

    Max: Tooling helps, but it's fundamentally a discovery problem first. You can't govern an agent you don't know is running. Inventory before autonomy.

    Sam: And confidence needs to be earned by incident response metrics, not vibes. Mean time to detect an agent breach — that's the number nobody's publishing yet.

    Koko: Publish that number and I bet the confidence line stops climbing real fast.

    Koko: This one's live as of today, and I don't think builders fully appreciate what just changed. Cloudflare is blocking mixed-use AI crawlers on ad-supported pages, new and free-plan customers first.

    Max: Mixed-use meaning the crawler that trains your model is the same one that also fetches live content for your RAG pipeline. Cloudflare's saying, pick a lane.

    Sam: Which sounds like a technicality until you realize half the retrieval-augmented systems out there lean on generic crawls to stay current. That's the plumbing, quietly getting shut off.

    Koko: So if I'm running a RAG product today, what actually breaks?

    Max: Freshness, mostly. Your agent that checks a competitor's pricing page or pulls today's news — if that crawl gets blocked, you get stale or missing context, and the failure mode is silent. The agent just... confidently gives you old data.

    Sam: Which is almost worse than an outage. An outage you notice.

    Koko: Right, quietly wrong beats loudly broken every time for how long it takes someone to catch it.

    Max: Cloudflare's pushing everyone toward Pay Per Crawl and dedicated user agents — basically, identify yourself, pay for what you take, or get walled off.

    Sam: Which honestly, publishers have wanted for two years. The web got scraped for free to train billion-dollar models, so I don't think this is the villain turn some builders are painting it as.

    Koko: Sure, but it does mean cost structure for every agent vendor just shifted overnight, and probably not the last shift like it.

    Max: Watch the smaller RAG startups especially — the ones without enterprise licensing deals with content providers are going to feel this first and hardest.

    Koko: So the free lunch on web data is officially over. Somebody's gonna have to actually budget for it now.

    Koko: While everyone's debating safety and breaches, Anthropic just quietly did something very unsexy and very smart — simultaneous deals with NEC and Cognizant to embed Claude across Japanese finance and manufacturing.

    Sam: Claude Opus four point seven and Claude Code, wired directly into enterprise platforms and Cognizant's consulting delivery stack. That's distribution, not just adoption.

    Max: It's the same playbook Microsoft ran with OpenAI years ago — don't sell direct, ride inside the systems integrator that already has the client relationship.

    Koko: And Japan specifically is interesting timing, right? Labor shortage, aging workforce, a culture that's actually been pretty open to automation historically.

    Sam: Exactly, and finance and manufacturing are both control-heavy environments. Segregation of duties, audit trails, approval chains — that's actually the easiest place to govern an agent, not the hardest.

    Max: Which is basically the opposite lesson of the AvePoint story we just did. Same week, two completely different postures — reckless adoption over here, structured rollout over there.

    Koko: So is this Anthropic being the adult in the room, or just better at picking easy markets first?

    Sam: Bit of both. NEC and Cognizant bring the compliance scaffolding already built. Anthropic isn't inventing governance, it's borrowing it.

    Max: Smart, but it also means the hard part — actually proving ROI inside those regulated workflows — lands on NEC and Cognizant's delivery teams, not Anthropic's PR team.

    Koko: So the real test isn't the announcement, it's whether Cognizant's consultants can make Claude Code actually stick in a bank's back office by, say, Q one.

    Sam: That's the number I want in six months — not deals signed, but workflows live in production.

    Max: The Register's open-weight-versus-open-source dispute is heating up — turns out the label decides who controls licensing terms, and vendors are picking the fuzzier one on purpose.

    Sam: MIT Sloan and BCG's expert panel warns treating agents as fully autonomous decision-makers is a governance failure mode, full stop, no asterisk.

    Koko: The UK's Joint Committee on Human Rights is calling for a wide-ranging AI bill covering everything from bias to surveillance.

    Max: And Samsung just backed an Nvidia GPU rival with two hundred thirty million dollars — the alternative-chip market keeps getting more crowded.

    Koko: Okay, let's recap. AvePoint's data shows GenAI breaches climbing to almost ninety percent of organizations, even as confidence in preventing them somehow rises too.

    Max: Cloudflare's crawler lockdown went live today, cutting off the free generic-crawl pipeline a lot of RAG systems quietly depend on.

    Sam: And Anthropic embedded Claude into Japan's enterprise backbone through NEC and Cognizant, leaning on their existing controls rather than building governance from scratch.

    Koko: Now, for the CIOs and CTOs listening — here's the lens for today. That breach-confidence gap is your actual headline, not a side note.

    Max: If your board thinks agent risk is under control, ask for the mean-time-to-detect number on agent-specific incidents, not just the overall breach count. If nobody can produce it, that's your answer.

    Sam: And do a shadow-AI inventory this month, not next quarter. HiddenLayer's fifteen-point jump in shadow AI concern means agents are running that IT doesn't know about, right now, in your own environment.

    Koko: On Cloudflare, check every RAG and retrieval workflow you've shipped for whether it depends on generic web crawls — and get ahead of the Pay Per Crawl conversation before a vendor renewal surprises you.

    Max: And take the Anthropic-in-Japan model seriously as a template — governed rollout through a systems integrator with existing controls beats a from-scratch agent deployment nine times out of ten.

    Sam: Here's the open question worth sitting with: if confidence keeps rising while breaches keep rising too, at what point does a board actually stop trusting its own dashboards?

    Koko: And a harder one — who's actually accountable when an agent, not a person, causes the breach? That answer is still nobody's job description.

    Max: Prediction for the month: expect at least one major enterprise vendor to publish a mean-time-to-detect metric for agent breaches, because right now that gap is too obvious to ignore.

    Sam: Prediction for the quarter: watch RAG vendors announce Pay Per Crawl partnerships or content-licensing deals as the Cloudflare block bites harder than expected.

    Koko: And for the year — watch whether Anthropic's Japan model gets replicated in other regulated markets, finance especially, as the template for governed agent rollout.

    Max: Lots to chew on today.

    Koko: That's the show. For the full brief, the sourcing, and insights built for your role, head to koko knows dot A I. We'll see you tomorrow.