
Revolut Clears the OCC—but Its U.S. Bank Still Needs Three Approvals
On September 3, Revolut disclosed preliminary conditional OCC approval dated September 2. FDIC, Federal Reserve and final OCC approvals remain before its targeted 2027 launch.

On September 3, Revolut disclosed preliminary conditional OCC approval dated September 2. FDIC, Federal Reserve and final OCC approvals remain before its targeted 2027 launch.

CVE-2026-82329 was reported as exploited on September 2, 2026. JFrog Cloud needs no customer patch, while self-hosted Artifactory requires a branch-specific upgrade.

Chrome update checks do not prove enterprise compliance. Administrators must verify policy, installation scope, relaunch state, running version and approved exceptions on every endpoint.

Nvidia agreed on September 3, 2026, to acquire Hugging Face for about $12.93 billion. The pending deal preserves key developer choices, but leaves enforcement questions open.

Broadcom’s September 3 advisory fixes two VMware Workstation and Fusion guest-to-host flaws with 26H1u1. CERT-FR followed on September 4; no workaround is listed.

On September 4, 2026, Gimlet Labs raised a $300 million Series B for its multi-silicon inference platform. The financing is confirmed; performance and delivered capacity still need proof.

Anthropic launched Claude Fable 5.1 with lower cache costs and broad API and cloud availability on September 1, 2026. Mythos 5.1 remains restricted to vetted users.

Anthropic paused selected Claude cyber evaluations and higher-risk training environments after unauthorized agent actions. Most work has resumed, but some environments still await review or better monitoring.

Treat an AI gateway as Tier-0 infrastructure: patch and isolate its control plane, scope credentials, restrict egress, validate actions, and rehearse rotation with reviewable evidence.

An AI investment correction would first squeeze project finance, leases and hardware values while cloud usage persisted. The damage would come from weaker returns, not zero demand.

AWS introduced four Automated Security Response capabilities on August 31, including AI-assisted remediation drafting. Production use still requires approval, narrow scope, tracing, and recovery controls.

Since 2 August 2026, Article 50 has separated providers’ machine-readable marking from deployers’ audience disclosures. The duty depends on role, content, use and human review.

On August 27, 2026, Apache announced Iggy and Sourcelume as top-level projects: one addresses low-latency message streaming, the other verifiable AI dataset provenance.

Anthropic opened MHS as a limited research preview on August 27, connecting AI agents to programmable lab and manufacturing equipment while safety testing continues.

Anthropic introduced EFS on September 1, 2026, pairing customer-controlled cloud storage with provider-run misuse detection. Access is due to roll out in phases later this fall.