GRC Report Staff

BIS Warns Frontier AI Is Giving Cyber Attackers a Cheaper Way In

Anthropic’s Mythos did not merely find a weakness in a computer network. In testing, it followed the weakness through. The frontier artificial intelligence model identified vulnerabilities, developed exploits and carried an attack across multiple stages, adjusting its approach with limited human oversight. In some attempts, it completed a full network takeover. OpenAI’s GPT-5.5, released weeks later, showed similar capabilities and performed slightly better on a benchmark of expert-level cybersecurity tasks.

EY Sanctioned Over Made.com Audit Failures as FRC Cites Weak Challenge of Management Forecasts

The UK's audit watchdog has fined Ernst & Young £1,197,000 after concluding the firm failed to obtain sufficient audit evidence in critical areas of its 2021 audit of online furniture retailer Made.com Group, shortcomings the regulator said stemmed from an inadequate challenge of management's forecasts.

MAS & Singapore Banks Form AI Taskforce as Frontier Models Redraw the Cyber Threat Landscape

Since May, regulators, banks and financial infrastructure operators in Singapore have been sitting around the same table, confronting a problem that is becoming harder to dismiss with each new generation of artificial intelligence. On Tuesday, that quiet collaboration acquired a name. The Monetary Authority of Singapore (MAS) and the Association of Banks in Singapore (ABS) formally launched the AI-Driven Cyber and Technology Risk Taskforce, or ACT, an industry-wide initiative intended to strengthen the financial sector's defenses against threats created by frontier AI models.

Harvey Norman, Latitude Ordered to Pay $35.9 Million Over Misleading Interest-Free Finance Campaign

On Tuesday, the Australian Federal Court ordered Harvey Norman Holdings and Latitude Finance Australia to pay a combined $35.9 million (AUD $55 million) after finding they engaged in misleading conduct and made false or misleading representations in a nationwide advertising campaign that ran between January 2020 and August 2021. Harvey Norman was ordered to pay $22.8 million (AUD $35 million), while Latitude was ordered to pay $13.1 million (AUD $20 million). According to the Australian Securities and Investments Commission (ASIC), the combined penalty is among the largest it has secured in a case involving misleading conduct related to financial products and services.

ECB Expands Climate Risk Framework to Corporate Credit Claims

The European Central Bank has spent the past year teaching its collateral framework a new habit. First it learned to look at corporate bonds through the lens of climate-related transition risk. Now it will do the same for a broader class of assets that sit behind the Eurosystem's lending operations.

Italy Fines Lusha €2 Million, Says Data Broker's Business Crossed Into GDPR Monitoring

The Italian Data Protection Authority imposed a €2 million fine on Lusha, the U.S.-based data broker, ordering it to stop processing the personal data of individuals in Italy while deleting the data it already holds. Read closely, the ruling is less about the existence of a commercial contact database than about what happens when that database is continuously refreshed, expanded and monetized over time.

Polish Watchdog Says Condo Hotel Promises May Have Hidden the Hardest Part of the Investment

The President of the Office of Competition and Consumer Protection (UOKiK) has opened proceedings against several companies involved in condo hotel developments, alleging they misled consumers about investment returns while failing to explain the costs and risks that could emerge long after the brochures had been put away. The investigations also challenge contract terms that, according to the regulator, deprived owners of meaningful control over properties they had purchased and punished those who tried to exercise it.