TechChannels Blog News

In Case You Missed It: Island’s Field CTO Says AI Has Raised Stakes While Sophos’ Chris Yule Says It’s Breaking Traditional Behavioral Assumptions and Banks Rewrite Rules for AI Agents Spending Money

Written by Teri Robinson | Oct 2, 2026, 6:00:00 PM

A couple of months before Island hit $6.4 billion valuation Field CTO Michael Leland described AI agents as a new class of “virtual knowledge worker,” while Chris Yule, Senior Director of the Sophos Counter Threat Unit, contends fully AI-driven attacks are not yet a widespread threat in the wild. And six global banks establish a set of principles needed to guide trusted agentic commerce,

Island Field CTO Michael Leland, From Vibe Coding to Agentic AI: Securing the New Enterprise Workspace

In a recent interview with Tech Channels, Michael Leland, Field CTO at Island, which just hit the $6.4 billion valuation mark this week, says agentic AI has raised the stakes further. Leland describes agents as a new class of “virtual knowledge worker”—one that may be entrusted with enterprise data and systems without going through anything resembling the onboarding, compliance training and acceptable-use requirements applied to human employees. Organizations therefore face a fundamental question: How do they extend identity, data protection, least privilege, visibility and governance to AI systems that increasingly act on a user's behalf?

Sophos’s Yule: AI Breaks Behavioral Assumptions, Turns AI Economics Into Defensive Advantage

The conversation around AI and cybersecurity is often dominated by predictions about autonomous attacks, rapidly evolving threat actors, and entirely new categories of risk. But the reality on the ground is more nuanced. While attackers are experimenting with AI and using it to accelerate familiar activities, Chris Yule, Senior Director of the Sophos Counter Threat Unit, told Tech Channels that fully AI-driven attacks are not yet a widespread threat in the wild. For now, both attackers and defenders are exploring the technology's capabilities, creating what he describes as “a bit of an arms race from a defense point of view.” That experimentation is already beginning to reshape security.

AI Is Pushing Third-Party Risk Beyond the Annual Review

Suppliers change faster than the paperwork used to assess them. Plenty of that paperwork is out there: EY’s 2025 survey found that companies using multiple control assessments sent suppliers an average of 55 questionnaires, most with more than 100 questions. The difficulty comes afterwards, when a supplier introduces an AI tool or changes how it handles customer data, and the answers on file no longer describe the service being delivered. Operational risk is now the most common factor companies consider when monitoring subcontractors, cited by 57% of respondents, up from 40% in 2023. Business continuity and resilience also rose to identify critical suppliers, from 14% to 23% over the same period. Companies are responding more aggressively when something looks wrong.

Banks Start Writing the Rules for AI Agents That Spend Money

Agentic commerce is rapidly moving from a speculative AI use case toward a payments-governance problem where, if software agents can choose products and initiate purchases, banks need clearer ways to establish security, customer intent, privacy, and interoperability. That new reality was recently exemplified by a joint publication by six global banks including ASB Bank, Bank of America, Capital One, Commonwealth Bank of Australia, ING Group and NatWest Group. The publication establishes a set of principles needed to guide trusted agentic commerce, where AI agents go beyond simply recommending products to selecting, ordering and potentially initiating payment on a customer’s behalf.

China’s Geespace Trial Puts Satellite IoT Economics Under Pressure

China’s Ministry of Industry and Information Technology has now given Geespace two years to prove that model commercially. The August approval allows the Geely-backed company to sell satellite IoT services using the first phase of its LEO constellation. It follows a similar approval for Beijing Guodian High-Tech in May. 64 satellites. 340 million communication sessions a day. Up to 20 million users. And no more than 1,900 bytes in a single transmission. Those numbers describe Geespace’s current GEESATCOM network. The most interesting number here may be 1,900 bytes. That is enough for a location update, equipment reading or short operational message. It also says plenty about the economics. Satellite IoT does not need broadband pricing to work. It needs millions of devices sending tiny messages often enough to justify keeping them connected.

Ransomware Recovery Costs Hit $1.7 Million, Which Backups Are Missing?

Boards should ask when a critical service was last restored using the people, access, and infrastructure likely to remain available after an attack. The answer should include what failed and how long the business would have been unable to operate. Without that evidence, a recovery target is an estimate that may already be shaping decisions as though it were a guarantee. Object First and Omdia surveyed 700 leaders and found that just 39% of organizations recovered at least three-quarters of their affected data, compared with 57% in its 2024 research. For most respondents, the damage also exceeded what they had planned for: 76% lost more data than their recovery targets allowed, and 64% took longer to restore operations than expected.