Business & Technology
Who let the agents in?
EVGENY ZARETSKOV
Group Chief Information Security Officer
SOFTSWISS
Every enterprise security leader is living through the same experiment right now, whether they chose it or not. Over the past year, AI agents have moved from chat windows into the machinery of the business itself. They open pull requests, query production databases, draft and send emails, and reach into internal tools through frameworks like the Model Context Protocol, which has become the standard way of wiring language models into corporate systems. Cisco’s State of AI Security 2026 research captures the scale of this shift: 83% of organisations surveyed planned to deploy agentic AI capabilities into their business functions, yet only 29% felt truly prepared to do so securely. That gap between ambition and readiness is where the next generation of breaches will come from.
Earlier this year, SOFTSWISS outlined its vision of AI becoming embedded across the organisation rather than existing as a standalone productivity tool. The deeper AI becomes integrated into everyday workflows, the more important it becomes to treat AI identities with the same discipline as human ones to prevent a shadow identity crisis. We have spent the past decade building identity and access management around the assumption that the entities touching our systems are either people or well-understood service accounts, both of which can be vetted, trained, and monitored. However, AI agents completely break that premise.
Give an AI agent a task, and it walks away with API keys, database credentials, and standing access to internal tools, which often amount to much more than what we would hand a human contractor on day one. It is the equivalent of giving a new temp the master key, the finance password, and the customer files before they have filled out a single form. No interview, no reference check, no ninety-day period where someone watches how it handles judgment calls.We have effectively hired a new class of worker and skipped every control we built for exactly this purpose.
What makes this especially dangerous is the mechanism called indirect prompt injection, which deserves more attention from boards than it currently gets. Unlike a phishing email that targets a person’s judgment, this attack hides malicious instructions inside the content an agent is already trusted to process: a support ticket, a webpage, a code comment, an email in an inbox the agent has been asked to summarize. The agent cannot reliably tell the difference between an instruction from its legitimate user and one smuggled in through the data it is reading.
Security researchers have already documented this moving from theory into practice. A Model Context Protocol server connected to GitHub was manipulated through a malicious issue that hijacked an agent’s behavior and triggered the exfiltration of data from private repositories. That is precisely why indirect prompt injection should be viewed as a governance issue, rather than just a technical one.
What should concern security leaders most is the blast radius. Traditional software vulnerabilities tend to have boundaries. A flaw in one application does not usually hand an attacker access to the email system, the finance database, and the customer support queue simultaneously. Agentic AI is designed to erase those boundaries by intention, because the entire value proposition is an agent that can browse, query, write, and act across many systems on our behalf. That same design that makes agents useful is what makes a single successful injection so costly. One compromised agent with broad tool access does not produce one bad outcome. It produces a cascade of authorized-looking actions across every system that agent was trusted to touch, and the industry’s own data breach research shows the cost of that exposure landing well into the millions when access controls are absent.
There is also a newer wrinkle that most Zero Trust conversations have not caught up to yet: agents increasingly talk to other agents, not just to humans. A research agent that has been poisoned can pass tainted output downstream to a financial or operational agent, which then acts on instructions it never should have trusted. The identity threat is no longer confined to human credentials and service accounts. It now includes the implicit trust agents extend to one another, often without any human in the loop to catch the handoff going wrong.
None of this is an argument against deploying AI agents. In an industry like ours, where real money moves in real time across jurisdictions and there is no such thing as a quiet shift, the operational case for automation is not going away, and it should not. The argument is that we cannot keep treating agents as trusted employees while withholding the controls we would never skip for an actual employee.
Zero Trust was built on the principle that trust is never assumed and always verified, continuously, regardless of where a request originates. That principle has to extend to non-human identities with the same rigor: least-privilege access scoped tightly to what a given task requires, credentials that expire rather than persist indefinitely, behavioral monitoring that flags an agent acting outside its normal pattern, and clear ownership for every agent’s lifecycle from provisioning to retirement, the same way we would track a departing employee’s access.
None of this means slowing AI adoption down. It means treating agent identity with the same seriousness that we assign human identity, rather than simply bolting it onto an IAM program that was never built for a workforce that runs around the clock. We are handing these agents access because they make us faster. Whether that access ends up working for us or against us comes down to whether anyone is watching closely enough.
Business & Technology
Shirtless intruder wakes couple in Travelodge hotel room
Kim Hutchison, 60, and Harry Grieve, 57, were staying in a Travelodge in Dundee when the early morning incident happened last month.
Ms Hutchison said she was “petrified” before the man – wearing just shorts – left after about a minute of arguing over who was actually in the wrong room.
READ MORE: MP meets Travelodge bosses following room key assault case
Travelodge, which has headquarters in Thame, apologised to the couple and said room access security policies were not correctly followed.
Earlier this year, a man was jailed for sexually assaulting a woman in her hotel bed after Travelodge staff gave him a key card and her room number.
Kyran Smith had gone to the reception of the Maidenhead branch of the hotel chain in the early hours in December 2022 and said he was the woman’s boyfriend.
He was jailed for seven-and-a-half years following the assault.
The chain’s chief executive Jo Boydell apologised to the victim and said changes would ensure additional or replacement keys were only issued with permission from the person staying in the room.
In the latest incident, Ms Hutchison and Mr Grieve had been visiting relatives in Dundee and had gone to bed at the Strathmore Avenue branch of Travelodge, before they were disturbed at 2am on July 11.
“I just woke up, I had heard the door click, and sat up in bed,” Hutchison told the BBC.
“Here was a guy at the bottom of the bed, just standing with shorts on. He had something in his hand which I took to be the key card for the room.”
It is understood that the man had made a mistake regarding the room number, believing he was in room 316 not 313.
Mr Grieve, who works in Aberdeenshire, got dressed and went down to reception to try to find out what had happened and “get some answers” about why a stranger had been able to get into their room.
Following their complaint, the couple were given a room refund, as well as a £100 Travelodge voucher – which Mr Grieve said he doubted they would use.
The couple decided to publicise their case after becoming aware of the Maidenhead assault.
In April, Freddie van Mierlo, Liberal Democrat MP for Henley and Thame, met the senior leadership team at Travelodge’s headquarters in Thame to discuss guest and employee safety following serious concerns about hotel room security.
Henley and Thame MP Frieddie van Mierlo (Image: Contributed)
Travelodge said it was “very sorry” for what had happened, and that customer safety and security was a priority.
“Any case of an unauthorised person entering a guest’s room is a significant cause for concern and we want to be clear that this should not have happened,” a statement said.
“Our updated room access security policies were not correctly followed in this instance, which is not acceptable.
“We have retrained the team at our Dundee Strathmore Avenue hotel on our updated room security and check-in procedures, and would like to apologise again to Mr Grieve and Ms Hutchison for their experience with us.”
The previously-announced Travelodge safety review remains ongoing.
Business & Technology
Orbital Industries signs BASF deal to speed research
JOSEPH GABRIEL LAGONSIN
News Editor
Orbital Industries has signed an agreement with BASF Environmental Catalyst and Metal Solutions to license its CurieOS materials discovery platform, bringing the software into catalyst research for automotive emissions applications.
BASF’s Environmental Catalyst and Metal Solutions unit, known as ECMS, supplies aftertreatment systems and catalytic products to the automotive market. Under the agreement, the division will use CurieOS in its catalyst research and development work.
The deal expands Orbital Industries beyond its existing work in data centres, where it has used the same platform to develop a PFAS-free cooling material for its Orbital IT brand. CurieOS is designed to help researchers identify promising materials before producing laboratory samples.
Materials discovery in industrial settings often involves long testing cycles, as candidate substances must be synthesised, characterised and assessed under operating conditions. CurieOS is intended to shorten that process by combining literature review, data analysis and simulation in a single scientist-directed workflow.
At the centre of CurieOS is Orb, the company’s atomistic simulation model. Orbital Industries says the model can predict the properties of new materials and give researchers what it describes as a virtual laboratory for evaluating candidates computationally before committing to physical testing.
Orb can simulate 100,000 atoms on a single graphics processing unit, according to Orbital Industries, which also says the model runs faster than competing systems from large technology groups and academic teams. It cited independent benchmark results in support of those claims.
Automotive pressure
The BASF unit is entering the agreement as carmakers and suppliers face continued pressure to adapt emissions technologies to tighter regulation, changing powertrain designs, alternative fuels and cost constraints. Those factors have kept catalyst development a priority across the automotive supply chain.
Saeed Alerasool, Senior Vice President and Chief Technology Officer for ECMS at BASF, said this backdrop had made faster development more important.
“The agreement comes at a critical time for the automotive sector. The development of mobile emissions catalyst technologies continues to be driven by tightening emissions regulations, evolving powertrain technologies and alternative fuels, as well as growing cost pressure. At BASF ECMS, we continuously explore new approaches to accelerate development and further improve R&D and application efficiency. Through this agreement, we look forward to leveraging emerging AI technologies to enhance our ability to deliver leading solutions and help address evolving customer and market needs,” Alerasool said.
Research tool
Orbital Industries describes CurieOS as an AI research system that can follow goal-based instructions from scientists across several steps, including reviewing published work, analysing experimental results and running simulations to generate new hypotheses. It says this approach can reduce the number of physical experiments needed in the earliest stages of a programme.
That matters in catalysis because the field involves interactions at material surfaces that can be difficult to model accurately with lower-cost methods. Larger, more detailed simulations can help researchers narrow which candidates should move to laboratory testing.
James Gin-Pollock, Chief Technology Officer at Orbital Industries, said the technical demands of catalyst work made it a useful proving ground for the software.
“Catalysis is a brutal test for any simulation model – you’re dealing with complex surfaces, large systems, and subtle interactions that cheaper methods miss. Orb was built for exactly this: it can simulate systems of a scale and complexity that were previously out of reach, fast enough that scientists can actually iterate. That’s what makes it valuable for real industrial workflows rather than just a research demo,” Gin-Pollock said.
Jonathan Godwin, Chief Executive Officer of Orbital Industries, said the BASF agreement was a practical application of the company’s work in industrial materials development.
“The hardest part of materials discovery is knowing where to look. CurieOS gives scientists a way to explore and test ideas computationally before committing time in the lab, which means more of their effort goes into the candidates that matter. ECMS hosts exactly the kind of demanding, real-world materials development we built this for,” Godwin said.
The agreement places Orbital Industries in a segment of the industrial software market where chemical and materials companies are increasingly testing artificial intelligence tools against established laboratory processes. For BASF ECMS, the immediate use case is catalyst development for emissions systems, an area where small gains in material performance can carry commercial and regulatory significance.
Business & Technology
Why some tax transformation projects succeed while others struggle
RUSSELL GAMMON
Chief Innovation Officer
Alphatax
As professionals across the industry will be all too aware, the tax function is experiencing one of the most significant periods of change seen for many years. Whether the priority is to address broader reporting and compliance obligations or respond to more demanding business expectations, teams are under significant pressure.
To deal with these challenges, many organisations have turned to digital transformation, with an increasing number accelerating their move to cloud-based technology to modernise legacy systems and automate manual processes. Progress, however, is far from consistent, with some tax teams moving extremely quickly while others continue to rely on desktop software, manual methods and spreadsheet-based workflows. Indeed, organisations operating in similar markets often achieve very different outcomes.
So what’s happening, and why are some making rapid progress while others continue to struggle? At the heart of the matter is digital maturity, or in other words, how well an organisation uses digital capabilities to achieve its strategic goals.
Organisations that can be categorised as having higher digital maturity already have the foundations needed to modernise successfully. They typically have connected systems, robust data governance, standardised processes and infrastructure that can support modern applications, whether deployed in the cloud or on-premise. In these environments, introducing new tax technology becomes an extension of existing capabilities rather than a wholesale overhaul. By contrast, organisations with lower digital maturity often find that new platforms expose existing weaknesses rather than resolving them, limiting the value they ultimately deliver.
This explains why organisations investing in similar technologies can experience very different outcomes. One may accelerate transformation, while another struggles to realise the benefits it is hoping for.
Getting the foundations right
The challenge rarely lies just with the software itself. The bigger obstacle is the environment in which it has to operate. For example, moving tax applications into the cloud does not automatically solve fragmented data. If tax information originates from multiple business systems and is inconsistent or difficult to access, cloud implementations simply expose those issues more quickly.
Then there are the challenges associated with data quality, which should be addressed before implementation begins rather than treated as something that can be corrected after the fact. The objective should be that changes made in one area flow consistently across the overall tax function, minimising the need for manual intervention and improving confidence in the information used. This also means that tax teams spend less time resolving data issues and more time focusing on higher-value activities.
Many transformation projects fail because organisations concentrate on selecting technology before understanding the processes it needs to support. The approach taken to data, for example, is key and strongly indicative of whether a transformation strategy is set up to succeed. In practical terms, organisations with higher digital maturity can work from a shared data foundation rather than maintaining multiple versions of the same information across different processes.
Existing processes also play a major role. If workflows are inefficient or poorly defined (even if they have been considered fit for purpose for many years), digital transformation rarely produces the desired improvements. Success also depends on the wider organisation being ready to support new ways of working, rather than viewing implementation as simply replacing one software platform or legacy process with something new.
Reaping the benefits
Building digital maturity allows organisations to move away from the tendency many have to adopt disconnected point solutions towards a more integrated tax operating model.
Consistency also makes it easier to identify issues or errors earlier in the process, when they are generally quicker and less costly to resolve. The cumulative effect is greater control, rather than simply a faster way of completing existing tasks.
The underlying point is that digital maturity should not be viewed as a destination that organisations eventually reach. It is an ongoing capability that becomes increasingly valuable as processes need to change or there are new opportunities for improvement.
This is crucial because future tax obligations, from reporting to compliance and everything in between, are becoming even more demanding, making it more important than ever to build an operating model that can adapt without requiring fundamental redesign every time priorities change. Organisations that continue investing in those underlying capabilities will be better placed to take advantage of future technologies because the conditions needed to support them already exist.
Ultimately, successful modernisation is about more than adopting cloud technology. Organisations that invest in the right digital foundations will be far better positioned to realise the full value of cloud and take advantage of future innovations, including AI, as the demands on the tax function continue to evolve.
-
Business & Technology3 weeks agoHSBC UK & Visa test AI shopping with live payments
-
Business & Technology4 weeks agoMouser warns against viral hacks to cool overheating phones
-
Business & Technology3 weeks agoValarian lands USD $50 million backing for sovereign AI
-
Oxford News4 weeks agoNew romantasy bookshop attracts queues of customers
-
Business & Technology4 weeks agoSNP & Palantir launch AI tools for SAP transformations
-
Business & Technology4 weeks agoKane tops England influencer rankings after Mexico win
-
Traffic & Transport4 weeks ago‘I felt my spine and body split’: the woman who was hit by a child on a Lime bike – and denied compensation | Ebikes
-
Oxford News4 weeks agoDWP now checking bank accounts for Universal Credit and Pension Credit
