AI moves fast. Stay in the know.

A curated view of the most important stories in AI, with actionable insights from the MagicMirror team.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Banks Are Deploying AI Agents Faster Than Risk Oversight Can Keep Up

All ARTICLES
AI RISKS
July 21, 2026

Major Wall Street banks are beginning to treat AI agents as digital workers, assigning them login credentials, defined responsibilities, access to business systems, and human managers. These agents are being introduced across wealth management, client onboarding, trading, treasury operations, and internal workflows.

According to Reuters, a KPMG survey found that 51% of banks were already piloting AI agents. BNY has started assigning digital workers individual login IDs and designated human supervisors, while other financial institutions continue to require human oversight for important decisions and customer-facing activities.

Source: Reuters

What to know:

  • Banks are moving beyond basic AI chatbots and deploying agents that can complete tasks across business applications and operational workflows.
  • AI agents are being tested in sensitive functions including wealth management, client onboarding, trading, treasury, and internal banking operations.
  • A KPMG survey cited by Reuters found that 51% of banks were piloting AI agents.
  • BNY is reportedly assigning digital workers their own login credentials, responsibilities, and human managers.
  • Giving an AI agent a separate identity can improve accountability, but it may also allow the agent to access applications, retrieve information, and perform actions across multiple systems.
  • Human supervision remains important, particularly for decisions that affect customers, financial transactions, or regulated processes.
  • However, assigning a human manager does not automatically provide visibility into every prompt, data interaction, system action, or decision made by the agent.
  • As the number of AI agents grows, organizations may find it difficult to determine which agent accessed particular information, why an action was taken, and whether the behavior remained within approved policies.

Why it matters:

For businesses adopting AI agents, the risk extends beyond employee prompts. Agents can access data, interact with SaaS platforms, trigger workflows, and perform actions using assigned permissions.

Organizations need visibility into which agents are active, what systems and data they access, and whether their actions comply with internal policies. Continuous AI risk monitoring, sensitive-data detection, policy checks, and audit-ready activity records can help identify unusual or unauthorized behavior. AI Security platforms can support this oversight by helping businesses monitor AI usage and detect emerging security, privacy, and governance risks.

Read the article

Popular AI Coding Assistants Exposed to a Hidden System-Takeover Risk

All ARTICLES
AI RISKS
July 10, 2026
July 11, 2026

Security researchers have demonstrated a new attack technique that can manipulate popular AI coding assistants into modifying sensitive files outside an approved project workspace. The attack, called GhostApproval, exploits symbolic links hidden inside malicious code repositories. Because some AI tools do not display the actual destination of a file change, developers may approve what appears to be a harmless action while the coding agent alters system files that could enable remote code execution.

Source: SecurityWeek

What to know:

  • GhostApproval was successfully tested against Claude Code, Amazon Q Developer, Cursor, Google Antigravity, Augment, and Windsurf.
  • Attackers can place a symbolic link inside a seemingly legitimate repository that points to a sensitive file outside the coding workspace.
  • When an AI coding assistant edits the disguised file, it may follow the link and modify the sensitive destination instead.
  • Some affected tools did not show the file’s actual destination in their approval prompts, meaning users could authorize an action without understanding its true impact.
  • The technique could potentially be used to modify configuration files, alter system behavior, or achieve remote code execution on a developer’s machine.
  • AWS, Google, and Cursor confirmed the issue and released patches. Anthropic said it had already introduced mitigations, while Augment and Windsurf had acknowledged the reports but had not released fixes at the time of publication.
  • The incident shows that human approval is not an effective security control when the information presented to the user does not accurately represent what an AI agent will do.

Why it matters:

For businesses adopting AI coding tools, the risk extends beyond the prompts developers enter or the code that AI generates. Coding agents can read and modify files, run commands, call APIs, and interact with development environments using the employee’s existing permissions. A trusted or approved AI tool can therefore introduce new risks when its actions are not independently monitored.

Organizations need visibility into which coding assistants are being used, what files and systems they access, and whether their actions remain consistent with the user’s original request. Continuous AI risk assessment, monitoring of IDE-assistant activity, policy checks on file and tool actions, and audit-ready records can help detect unusual behavior before it leads to system compromise. Solutions that provide on-device visibility and policy evaluation across IDE assistants, file activity, API calls, code commits, and shell commands are becoming increasingly important to manage this risk.

Read the article
No items found.
  • Run a Shadow AI Audit

  • Free AI Policy Generator

  • How a Modern Law Firm Is Safely Scaling GenAI with MagicMirror