Cyera Executive Rick Holland explains how AI is moving from experimentation to trustworthy adoption while leading vendors want government to treat cyber defense as an emergency even as they are accelerating the risk. And a Revolut breach has laid bare and authentication gap.
AI Experimentation to Trustworthy, Measurable Adoption
For security leaders, the challenge of AI has become managing the speed at which AI is entering the enterprise while confronting data, identity, and governance problems that organizations have struggled with for years. Rick Holland, CISO and Data and AI Security Officer, at Cyera, sat down with Tech Channels at Black Hat to discuss how AI is expanding before many companies have fully addressed shadow IT, agents are gaining access to data whose source of truth may be unclear, and security teams are being asked to govern technologies that continue to evolve at an extraordinary pace. According to Holland, “the pace of change, the velocity is overwhelming.”
Unions Turn School AI Rules into Contract Terms
The US Federal Trade Commission (FTC), the federal agency that enforces consumer protection and privacy rules, spent this summer closing a case over an edtech breach that exposed data belonging to 10.1 million students. Three months later, the argument over how much trust schools should place in technology companies has moved squarely onto AI. New York City has imposed a one-year moratorium on student-facing generative AI for nearly 600,000 pupils from 2-K through eighth grade, while disabling AI features in dozens of previously approved products. A week after that announcement, Microsoft and two major teachers’ unions chose a different lever: instead of restricting access to AI, they wrote limits on what the technology can do with student data into the contracts schools sign with vendors. Microsoft, the American Federation of Teachers and the United Federation of Teachers have unveiled a National AI Safety & Privacy Standard that US districts can incorporate directly into Microsoft customer agreements.
Revolut Breach Exposes the Authentication Gap in Government Data Requests
Why steal customer records when you can convince a bank to hand them over? Revolut disclosed sensitive data to miscreants after receiving fraudulent requests from what appeared to be a compromised government email account. Whoever controlled the account turned its official status into access to customers’ private information. Revolut released the data believing the requests were genuine, while its own banking infrastructure and customer funds remained unaffected. The group claiming responsibility later said the operation had lasted roughly six months, although that timeline has yet to be independently verified. Italian authorities are now investigating whether a certified PEC email account associated with the prefecture of Reggio Calabria was compromised.
100 Leading AI Companies Are Warning Governments About a Risk They Are Still Accelerating
More than 100 companies, including Google, Microsoft, OpenAI, and Anthropic, co-signed a letter asking governments to treat cyber defense as an emergency. Their concern is concentrated on critical infrastructure, where vulnerable software can remain in service for years because taking it offline is operationally difficult, while frontier models are already finding thousands of exploitable flaws in weeks. The “status quo security won’t be enough”. The reasons it gives are familiar to anyone who has worked around aging technology. Unpatched software, permissive access, weak authentication, forgotten misconfigurations, and technical debt have accumulated for years. AI did not create any of them, but it is simply getting better at finding them. AI is reducing the amount of skilled labor required to discover and investigate weaknesses, while many critical systems remain expensive to patch and even harder to modernize. That is a lethal combination for sectors where uptime is itself part of safety.
Cohere CEO Says AI Is Becoming the Most Potent Cyber Weapon Yet
“Most potent cyber weapon” is a very disturbing description of AI, one given by Cohere CEO Aidan Gomez. Despite the boldness of that statement and the claims of handwringing when it comes to AI, incidents like OpenAI’s much publicized event in July make it harder to dismiss. During cybersecurity tests, agents assigned separate tasks began sharing discoveries and helping one another break into Hugging Face, a company they had never been authorized to attack. Roughly 1,200 agents communicated through an unauthorized message board, exchanging more than 70,000 messages and files. Around 700 participated in the attack. As agents reproduced one another’s exploits, they gained access that others could use to push further into the company’s systems. OpenAI says they eventually executed code on dozens of servers, gained full administrative access to one, and harvested production credentials across four regions.
A $1 Trillion Security Bill Is Coming Due Faster Than Companies Can Patch
.png?width=1816&height=566&name=brandmark-design%20(83).png)