100 tech giants warn about rogue AI (and sell the cure), a researcher owns his desk with Claude, 1,200 unofficial AI apps per company, quantum is already harvesting your crypto, and the vendor trap.
In this edition
- 01100 companies signed a letter warning about rogue AI. They're also selling the cure.
- 02A bored researcher used Claude to own every device on his desk.
- 03The average enterprise runs 1,200 unofficial AI apps and can't see into most.
- 04Quantum isn't tomorrow's problem. Your encryption is already being harvested.
- 05More security tools isn't more security. Fewer suppliers isn't either.
Get the next GRC Brief in your inbox.
Subscribe to The GRC Brief100 companies signed a letter warning about rogue AI. They're also selling the cure.
On August 27, more than a hundred technology companies, including OpenAI, Anthropic, Google and Microsoft, alongside cyber firms like CrowdStrike, Okta and Fortinet, signed an open letter urging the public and private sectors to coordinate against AI-enabled cyber threats. The warning is blunt: in the coming months, AI-enabled attacks will become far more widespread and sophisticated, and the organisations we depend on, from hospitals to water treatment plants to internet infrastructure, are at risk. It follows a summer of rogue-AI incidents, the OpenAI agents that broke into Hugging Face and similar break-ins involving Anthropic and Meta models. The letter calls for a collective response and new partnerships to raise security standards. The obvious tension, which the reporting notes, is that many of the signatories are simultaneously building ever-more-capable models and selling AI defence products off the back of them, OpenAI's Daybreak, Anthropic's Mythos, Microsoft's Perception.
Source: TechCrunch · AI industry open letter, 27 Aug 2026
My take
Two things are true at once, and you have to hold both. First, the warning is real and correct: AI-enabled attacks are coming, they will hit critical infrastructure, and a coordinated public-private response is genuinely the right call. After the summer we have had, an industry that spent two years downplaying this finally saying it out loud is progress. Second, read the signatory list with clear eyes. The companies building the most attack-capable models are the same ones selling you the defence, and this letter doubles as a coordinated launch announcement for Daybreak, Mythos and Perception.
So take the signal, keep your wallet closed for a beat. The systemic warning does not obligate you to buy anyone's new AI-defence platform, and it certainly does not replace the fundamentals I keep hammering. The right response to "AI attacks are coming" is not a shiny new AI product bolted onto a shaky foundation, it is finishing the boring work underneath, the same work that would have stopped most of the summer's incidents. Buy the defensive tooling if it earns its place. Do not let a well-timed open letter make that call for you.
A bored researcher used Claude to own every device on his desk.
For a concrete picture of what AI-enabled means, a security researcher named Chaz Schlarp got annoyed at his OLED monitor nagging him to run pixel cleaning, and decided to see what an AI agent could do about it. Over a couple of weeks, using Claude to drive the reverse engineering, he compromised five ordinary peripherals sitting on his desk, the monitor, a webcam, a microphone, a video capture card and a Wi-Fi lamp. He got a root shell on a commercial Dell display and remote code execution on others, and found an exploit where a single HTTP POST disables firmware signature checking so you can flash unsigned firmware. His conclusion is the quote to keep: assume any peripheral connected to a computer can be infected. His broader point is the one that matters for everyone: work that used to require a well-funded nation-state now takes an annoyed person, a cheap AI agent and a weekend.
Source: schlarp.com · Chaz Schlarp, Everything I own owned, 23 Aug 2026
My take
This is the whole AI-security argument in one weekend project, and it is worth more than the coalition letter above it. Not because it is sophisticated, but because it is trivial. A guy, mildly irritated at his monitor, pointed a commercial AI at the closed firmware of everyday gadgets and owned all of them. The barrier that used to protect obscure hardware, that reverse-engineering it was slow, specialised, expensive work, is exactly the barrier AI just removed. That is the real story of this era: not new magic, but the collapse of the cost of competence.
For your threat model, two takeaways. One, every peripheral is a small, connected, barely-protected computer, and your asset inventory almost certainly does not include the webcam, the monitor or the meeting-room devices that can be reflashed to persist below the operating system. Two, this is why the browser-permission prompts matter, WebUSB, WebHID and WebBluetooth mean a malicious website can reach that hardware if a user clicks allow. If your supply-chain and endpoint programmes stop at laptops and servers, they stop too early.
The average enterprise runs 1,200 unofficial AI apps and can't see into most.
If you want to know how much AI is already loose inside your organisation, Netskope, which sees enterprise traffic for a living, publishes a running index. The picture: shadow AI is not an emerging risk, it is the default. Around 47 percent of employees using AI at work do so through personal, unmanaged accounts, the average enterprise is running roughly 1,200 unofficial AI applications, and 86 percent of organisations have no visibility into what those sessions actually contain, with source code the single most-leaked data type. And the frontier has already moved past the chatbot. Netskope's 2026 read is that the real shift is agentic AI wired into company data through the Model Context Protocol, with MCP traffic up fourfold and a new class of incident, where an AI agent returns sensitive data to someone not authorised to see it. It is a vendor's dataset, but the direction is hard to argue with.
Source: Netskope AI Index · Netskope AI Report 2026
My take
Sit with the 86 percent, because it is the number that should reorganise your priorities. Most organisations cannot see what their people are sending to AI, which means most AI governance policies are documents describing a reality nobody is actually measuring. This is the shadow-AI and shady-AI problem from a few weeks back, now with telemetry: banning tools does not work, it just pushes usage onto personal accounts where you have zero visibility. The only thing that works is a sanctioned, monitored path that is easier to use than the shadow one.
But do not miss the part that is genuinely new, because it is where next year's incidents live. The centre of gravity has moved from employees pasting text into a chatbot to agents wired directly into your systems through MCP, and Netskope is watching that traffic quadruple. That is a different risk: not what a human types, but what an autonomous agent is authorised to reach, and a fourfold jump in connective tissue between your data and external models is a fourfold jump in blast radius. If your AI governance still assumes the risk is a copy-paste into ChatGPT, you are governing last year's problem.
Quantum isn't tomorrow's problem. Your encryption is already being harvested.
Here is the threat everyone files under later that is actually now. Quantum computers capable of breaking today's public-key encryption, RSA and the elliptic-curve crypto behind almost every secure connection, do not exist yet. But the attack does not wait for them. Harvest now, decrypt later means well-resourced adversaries, chiefly nation-states, are intercepting and storing encrypted traffic today to decrypt once the hardware arrives, and the agencies, the US DHS, the UK's NCSC, ENISA, all now write guidance assuming this is happening. So the exposure clock starts the moment your data is captured, not on some future Q-Day. The standards are no longer theoretical either: NIST finalised its post-quantum algorithms last year, Google has set itself a 2029 deadline to finish migrating, the EU wants member states inventorying their cryptography by the end of 2026, and fresh hardware research keeps shrinking the estimated distance to a capable machine. If any data you hold must stay secret into the 2030s, it is already in scope.
Source: The Quantum Insider · PQC timelines and deadlines, Aug 2026
My take
I have had prospects raise this in the last week, so let me be direct about why the usual framing is wrong. Quantum is not correctly filed as a future problem, and the reason is not the hardware timeline, which nobody can pin down. It is harvest now, decrypt later. The moment your encrypted data is captured, the clock starts, and the decryption simply happens later. So the honest question is not "when will quantum arrive," it is "how long does my data need to stay secret, and is that longer than the time until someone can break the crypto protecting it." For most regulated data, contracts, health records, trade secrets, the answer is already yes. Which means it is already exposed.
And this compounds everything else in this newsletter. Every breach I have covered where "only encrypted data" was taken is a deposit in someone's vault, waiting. Crypto that was already weak, misconfigured TLS, ancient key sizes, homegrown schemes, does not need a quantum computer to worry about, it needs one now and a quantum computer later. The first move is not panic or a rip-and-replace, it is a cryptographic inventory: know where you use cryptography, which algorithms, which key sizes, in which systems, including the ones your suppliers run. You cannot migrate what you cannot see, and the EU wants that inventory done by the end of this year. This is a 2026 project wearing a 2032 costume.
More security tools isn't more security. Fewer suppliers isn't either.
A useful strategic piece from the World Economic Forum makes a point worth sitting with: in cybersecurity, more tools do not mean more security. Organisations pile up SOC platforms, incident-response functions and threat-intelligence feeds, and end up with complexity, disconnected alerts and blind spots rather than protection, what the piece calls one of the most expensive assumptions in security. IBM's breach data agrees, naming system complexity and supply-chain exposure as leading amplifiers of cost. The article's answer is consolidation, a single integrated defence ecosystem, ideally with a trusted partner, which, in fairness, is also the business the author is in. And that is where it gets interesting for anyone under NIS2 or DORA, because those regimes pull the other way.
Source: World Economic Forum · T. Alharbi, WEF Centre for Cybersecurity, 25 Aug 2026
My take
This is the balance I want you to actually think through, because both extremes are sold as best practice and both are traps. Fragmentation is real: fifty disconnected tools, five dashboards and three teams working to three timelines is how a contained incident becomes a 276-day breach. So consolidation is genuinely good hygiene. But run it too far and you arrive exactly where DORA and NIS2 tell you not to be: concentration risk, your entire security posture resting on one provider that is now a single point of failure and a single, juicy target. DORA names this explicitly, over-reliance on a critical ICT third party is a risk you are required to manage, not an efficiency to maximise.
So the answer is not a slogan, it is a judgement, and it is yours to defend. Consolidate for integration and visibility, the things fragmentation destroys, but keep deliberate independence at the points where a single supplier's bad day would take you down with it. Map your critical dependencies, ask which of your providers you genuinely could not survive losing, and make sure the answer is not all of them and not just one. That is the real work behind vendor strategy, and it is exactly the muscle NIS2 and DORA are trying to build. Neither one throat to choke nor best-of-breed everything is a strategy. The balance is.