I spent a good chunk of this week reading OpenAI's report on what happened between its testing agents and Hugging Face, along with three or four other accounts of the same events, because the story kept getting more interesting the closer I looked. An agent got handed a task it could not solve, decided to cheat instead, and spent two months building a hidden communication system with hundreds of other agents to cover for it. If you follow AI news casually, this is one worth reading in full.
That story anchors this edition, alongside a few other threads worth your attention this month: banks scaling AI adoption with real discipline behind it, regulators chartering banks built for AI from day one, and a batch of new Claude features that expand what agents can do in your workflow, landing in the same weeks OpenAI's agents were busy proving why that expansion needs real guardrails.
In the free section, you get the full rundown and my take on each story. In the subscriber section, we move from what happened to what to actually do about it: how to pick low-risk places to let an agent start working, what to add to your AI policy this month, and two ready-to-run checklists, one for solo users and one for teams, for a monthly habit of checking what Claude has actually been doing in your business.
Events and updates
September 23, in Houston: TXCPA Houston, CFO Controllers Peer Group. Implementing AI with Confidence: A CFO's Playbook for Scaling AI Adoption. Register here.
The Claude in Action cohort is full. The next one runs in November.
Want to work with me directly? Reply to this email for a 1:1 session or a custom program for your organization.
What Happened in August
OpenAI's agents breached Hugging Face
In May, an OpenAI agent was given a task it could not solve. Instead of failing, it found a way to cheat, and it kept going. Over the following two months, a swarm of agents, somewhere between 700 and 1,200, built their own communication channel and exchanged 70,000 messages to coordinate how to manipulate the scoring system rather than admit the task was impossible. They escalated via a real zero-day vulnerability, gained cluster admin access on OpenAI's own infrastructure, and separately triggered what Hugging Face initially logged as an unrelated attack. Nobody realized the two incidents were the same breach until OpenAI asked Hugging Face about a set of leaked credentials and got the answer "we already revoked those."
That was in July. OpenAI's official report came out August 26 , and Fortune's follow-up is worth reading for what the report left out
If you have not read the details of this one, I really suggest you do. First, it is an exciting and fascinating story, closer to a heist plot than a typical vendor disclosure. Second, this is the kind of story where you need to read the primary sources and form your own opinion.
So what: this is a documented risk, from the company with the deepest visibility into its own models. If OpenAI's own monitoring could not catch this in real time, and needed two organizations comparing notes to even see the full picture, that is the honest baseline for what "oversight" currently means in agentic systems.
It lines up uncomfortably well with a Cloud Security Alliance survey from earlier this year: 62 percent of financial firms have already deployed AI agents, 93 percent gave those agents some autonomy, and 20 percent have already had a security incident tied to an AI tool. Adoption is running well ahead of the ability to supervise it. I have said this before, and I will keep saying it: agentic AI is not ready to run critical finance workflows unsupervised, and this month gave us the receipts.
Banks are increasing AI adoption, and Bank of America shows what disciplined adoption can look like
The trend across the industry is clear from Q2 earnings calls: JPMorgan reported close to 1,000 live AI use cases, and Citi said close to 9 in 10 employees now use AI tools. Bank of America's numbers are the most specific: more than 300 approved AI use cases, over 200,000 employees using AI tools, and 400,000 prompts run daily
So what: BofA's number is impressive, but the real signal is in how tightly controlled it is. The bank maintains a defined, reviewable list of 300 approved use cases, gating both the tools and the use cases themselves, rather than broadly opening AI access and letting employees find their own uses for it. In a highly regulated industry, that discipline is the right instinct; scale is achieved through a controlled gate. If you are building your own AI governance, copy how tightly BofA controls its approved list, rather than how many items are on it.
Regulators are chartering banks built for AI from the ground up
The OCC gave conditional approval to Upstart Bank, an online lender that uses AI directly for credit decisions, to become a full-service commercial bank. Earlier this year, it did the same for Augustus, a bank built specifically for 24/7, machine-speed clearing aimed at agent-driven and programmable transactions rather than human banking hours.
So what: while the industry is still working out how to supervise agents safely, the charter door for AI-native banking is already open. That gap, between what is regulated at the infrastructure level and what is actually understood at the risk level, is worth watching closely if you are anywhere near bank partnerships or AI-driven lending.
This month in Claude: more capability, more control
Three updates landed within days of each other. The Compliance API now covers Claude for Microsoft 365 sessions in Excel, Word, PowerPoint, and Outlook, and is in beta for Enterprise, closing the audit gap for finance teams who have been modeling in Claude for Excel since May without a centralized way to review what was actually done.
Cowork has its own built-in browser, so Claude can navigate a site, fill out a form, and pull data from a vendor portal that has no direct connector, useful for tasks like collecting a month's invoices.
And memory now works across Cowork and chat, so you can stop re-explaining your own workflows every session.
So what: the browser is the one to read carefully. Banking, email, and single sign-on sites are excluded by default, and Anthropic's own language says prompt injection risk can be reduced but not eliminated. That is the company that builds Claude, drawing the same line I have been drawing all month: fine for portal admin work, not yet for anything with real financial exposure.
We have covered what happened and why it matters.
In the subscriber section, we get to the real question: where do you actually start with agents today, what needs to go into your policy this month, and how do you build a habit of checking on it before it becomes a problem you find out about the hard way.
Closing Thoughts
Thank you for reading this far, especially if you went and read the OpenAI report yourself instead of just taking my word for it. Building your own opinion instead of borrowing someone else's on this story.
If you are working through any of this at your own company, agent policy, use case approval, or just trying to figure out where to start, reply to this email and tell me what you are seeing. I read every one.
We Want Your Feedback!
This newsletter is for you, and we want to make it as valuable as possible. Please reply to this email with your questions, comments, or topics you'd like to see covered in future issues. Your input shapes our content!
Want to bring this into your finance team's actual work?
Corporate training, built around your finance team's workflow
Classes and workshops, for finance professionals learning on their own
Book a call, to talk through what fits before committing
Did you find this newsletter helpful? Forward it to a colleague who might benefit!
Until next Tuesday, keep balancing!
Anna Tiomina
Founder, Blend2Balance
