IRM Market Brief: September 22 to 29, 2026
Anthropic is preparing what could be the largest initial public offering on record, and its prospectus tells investors the company may be liable when one of its agents deletes a customer’s data or moves a customer’s money. Reuters reported the language on Tuesday, September 29. The filing says the contract terms that cap Anthropic’s liability may fail, and that the law has yet to settle whether an agent’s actions bind the company that deployed it. Rogue agents have been a security story all year. As of Tuesday they are a risk factor in a securities document, where underwriters and plaintiffs’ lawyers will read about them.
Five more developments landed the same day. At the White House, six frontier AI companies signed a voluntary accord that commits each of them to internal controls, an internal team that checks those controls, an outside evaluator and an independent board committee. FTI Consulting published a survey in which 60 percent of large companies said they had slowed, paused or pulled back an AI deployment in the past year. OpenAI launched always-on agents it calls dots. Reco raised $55 million to secure agents, with AT&T as both customer and investor. Tokio Marine’s U.S. shared services company chose Monitaur to run AI governance across its insurers.
Read together, the day has a shape. The labs agreed to audit themselves on the same day that one of them told investors the liability question is open and another shipped agents that never log off. Whatever sits between those promises and a company’s own processes still belongs to the company. The IRM Market Brief covers the week’s developments for readers who buy, build, sell or invest in risk technology.
1. Anthropic tells IPO investors it may be on the hook for what its agents do
What happened
On September 29, Reuters reported on the risk factors in Anthropic’s IPO prospectus, which the news agency has seen. Risk factors are the section of a prospectus where a company tells investors what could materially hurt the business, and lawyers draft them knowing a court may read them later. Anthropic’s agents are built to hold deep access to customer systems and to run on their own for days at a time. The filing says errors, misalignment or security exploits in those agents “may result in real-world consequences,” and it names irreversible actions such as data deletion and financial transactions. It adds that the limits on liability in Anthropic’s contracts may prove unenforceable or too small, that the way existing law applies to agents is unsettled, and that two questions remain open: whether an agent’s actions count as a product, a service or something else, and whether and when those actions legally bind the user that deployed the agent.
Reuters set the disclosure against remarks by Federal Trade Commission Chairman Andrew Ferguson a week earlier. He rejected the idea of agents that break loose on their own and suggested liability would sit with the developers or users who instruct them, while asking whether an innocent user should carry an unexpected result. Anthropic did not comment. The prospectus has not been published, so every detail here is as Reuters reported it.
Our read
Agent failure just moved out of the technical risk conversation. It now sits in securities disclosure, which brings litigation exposure and investor diligence with it. Agentic AI risk belongs on the enterprise risk agenda, with an owner who can see past cybersecurity and AI governance to the balance sheet.
Four weeks ago we asked who pays when an authorized agent causes a loss. Anthropic’s own lawyers have now told investors that nobody knows. Read the disclosure from the buyer’s side of the table. The vendor is warning that its liability cap may not survive, and that your company may be bound by what the agent did. A contract clause was never a control, and this week the vendor said as much. If you deploy agents from any model provider, ask:
• Which of our agents can take an action we cannot reverse, such as deleting data, committing funds or signing something, and what stands between the agent and that action?
• What do our contracts say about liability for autonomous actions, and does counsel believe the cap and the indemnity would hold?
• Would our cyber, crime and errors and omissions policies respond to a loss caused by an agent that was authorized to act?
• Does our own risk disclosure to investors, lenders or regulators need to say anything about agents we have deployed?
What to watch
The public filing, which will show the full risk-factor text and any numbers attached to it. After that, whether other model providers and large deployers adopt similar language, how insurers reword their policies, and the first court ruling on whether an agent’s action binds the company that switched it on.
2. Six frontier AI companies sign up for controls, audits and a board committee
What happened
On September 29, the leaders of Google, Anthropic, Meta, OpenAI, SpaceXAI and NVIDIA joined President Trump in signing the White House Accord on Super Intelligence. The accord itself runs 308 words and commits each company to four sets of controls and audits, shown in the graphic below. The companies say they will meet regularly to set standards and best practices. The accord is voluntary, and the president called it “morally binding.” It sets no deadlines and names no standard, nothing in it promises reporting to customers, and its text says it may make sense over time to write the steps into law or regulation. Vice President Vance said the administration would rather work with the companies than regulate them.
The same day the president signed an executive order directing executive branch agencies to use “Super Intelligence” and “SI” in place of artificial intelligence and AI in correspondence, public communications, reports and policy documents. The legal meaning stays where it was for now. The order defines the new term by pointing to the existing statutory definition of artificial intelligence, leaves previously issued regulations and contracts untouched, and gives the president’s science and technology adviser 60 days to propose legislative language for a federal definition. The White House fact sheet covers the order and does not mention the accord.
Our read
Set the branding aside and this is an assurance stack any internal auditor would recognize: control design, management testing, independent assurance and board oversight. Last week’s brief watched that stack assemble one piece at a time, through OpenAI’s incident disclosures and the Anthropic and Accenture evaluation partnership. The accord turns those separate moves into a shared commitment across six companies, and it puts a board committee on top.
It also stops at the lab’s door, which is why the last arrow in the graphic is dashed. The accord governs the companies that build frontier models. It says nothing about the business processes those models end up inside, the authority an enterprise delegates to an agent, the risk appetite that authority should respect, or who answers when something goes wrong. We made the case in Accountable Autonomy that the enterprise cannot wait for the frontier to pace itself, and a voluntary document with no dates in it does not change that. If you buy models or agents from a signatory, ask for:
• The name of the external auditor or evaluator, the scope of its work and how often it reports.
• A customer-facing summary of each assessment, in the way a SOC 2 report travels today.
• The charter of the board committee and what it is required to escalate.
• A commitment to notify you when a finding affects a model or agent you already run.
What to watch
Named evaluators, published committee charters and the first external assessment anyone outside a lab gets to read. The 60-day definition proposal will show whether “super intelligence” stays a label or starts to change what existing AI rules cover, so compliance teams with policies keyed to the statutory definition should track it. Also whether Congress or an agency takes up the accord’s own hint about codification, whether companies that did not sign adopt the same structure, and whether enterprise procurement teams start asking for accord assessments the way they ask for security attestations.
3. FTI finds six in ten large companies have hit the brakes on an AI deployment
What happened
On September 29, FTI Consulting published a survey of 1,600 senior business decision-makers at large companies in the United Kingdom, France, Spain, Germany, Belgium, Ireland and the United States. The report, AI’s Second Act: Where Safety, Risk and Trust Collide, was fielded online from August 5 to 11 and released ahead of Dublin’s International AI Summit. Its headline finding is that 60 percent of large companies slowed, paused or pulled back a planned AI deployment in the past year because of reputational, regulatory or trust concerns. The graphic below carries the rest. Two cautions apply. The answers are self-reported, and 1,350 of the 1,600 respondents work in Europe, so this is mostly a picture of companies living under European AI rules.
Our read
Earlier this month a OneTrust survey found 27 percent of organizations had slowed or paused deployment after an AI incident, a figure we covered in last week’s brief. FTI asked a different question of a different sample and got a number more than twice as large. The two surveys cannot be added together, but they point the same way. Weak governance used to show up as downside risk. It now shows up as AI value that never arrives.
In IRM Navigator Model terms, Performance is waiting on Resilience, Assurance and Compliance. Companies without enough of the last three are being forced to choose between adopting AI without control and stalling, and six in ten have stalled at least once. The shadow AI figure makes the choice look worse than it is, because the stalled company still has employees using tools nobody approved. We argued last week that the harder problem is the agents a company can see and still cannot explain. If a deployment in your company is on hold, ask which specific control or piece of evidence would let it proceed, who owns producing it and by what date. A pause with no exit condition is a cancellation that nobody has announced.
What to watch
Whether the paused deployments restart, and what unlocked them when they do. The full report’s split between U.S. and European respondents will show how much of the slowdown is regulatory. The 47 percent directing AI investment toward security suggests where the money goes first.
4. OpenAI ships always-on agents and leaves the approval rules to the user
What happened
On September 29, at its DevDay event in San Francisco, OpenAI launched dots, agents that run continuously on a user’s behalf. Each dot runs on the GPT-6 Astra model, has its own cloud computer and browser, connects to more than 4,000 applications and can be reached through ChatGPT, Slack or Microsoft Teams. Dots carry context across those channels and do what OpenAI calls proactive research in the background, where they are limited to read-only access in connected apps. They start with built-in rules on when to act alone. Users can write Custom Rules that allow, block or require approval for specific actions, a few sensitive tasks such as changing a password always stay with the user, and a monitoring system can pause a dot.
Dots are available now to Pro and Business Premium subscribers in eligible markets. Enterprise, Edu and Healthcare workspaces get a beta once an administrator turns it on. OpenAI is also piloting specialist dots for companies, each with its own identity and credentials for a defined role, after internal tests in procurement, invoice processing, customer support and commercial contracting. It is working with Microsoft to bring those specialist dots under the governance controls in Agent 365. OpenAI’s safety note tells users that dots can still make mistakes and that consequential work should be reviewed. The launch followed a hard few days for the company. On September 25, OpenAI disclosed 53 instances in which its agents had posted images that users had put into ChatGPT to outside image-hosting sites. On September 28, the day before DevDay, it cancelled the planned October release of GPT-6.1 Astra after internal tests found the model fell short on staying within its scope and authorization and on telling users accurately what it had done. No enterprise outcomes were reported for dots.
Our read
Most AI governance programs were written for occasional model interactions: a person asks, a model answers, a person decides. A dot is a persistent actor with a computer of its own and a standing invitation to find work. Managing a population of those is closer to managing a workforce than reviewing a tool, and it calls for agent portfolio management, with an owner, a business mandate, delegated authority, approval thresholds, monitoring, incident handling and evidence for each one.
Look at who sets the approval rules. In the product as launched, the individual user does. The company’s delegated-authority policy appears nowhere in that loop unless an administrator puts it there, and the specialist dots with their own credentials will be new non-human identities inside systems of record. Before an administrator switches the beta on, decide:
• Who owns each dot, and which business mandate it works under.
• What it may do without approval, who wrote that rule and who can change it.
• Which systems of record it may write to, as opposed to read from.
• How access is revoked, how fast, and where the record of its actions is kept.
What to watch
Administrator controls that let a company set approval rules centrally and lock them. The Agent 365 integration and what it exposes to identity and risk teams. Whether approval logs can be exported as evidence. And the first incident involving a dot inside a company, which will test OpenAI’s disclosure process and Anthropic’s liability warning at the same time.
5. Reco raises $55 million, and AT&T is both the customer and the investor
What happened
On September 29, Reco announced $55 million in additional funding, including a strategic investment from AT&T Ventures, which brings its total raised to $140 million. Reco’s platform maps the relationships among agents, identities, applications, permissions, data and workflows, and it can revoke risky access or disable an integration. TechCrunch reported that the round follows a $30 million raise in February, that the company has more than 100 customers, and that at least 20 companies now sell some form of agent security product. The graphic below lays out the round.
Our read
The size of the round matters less than who wrote part of the check. A large enterprise that already uses the product decided it wanted a stake in the company, which is about as direct a buyer signal as this market produces. Agent security is becoming its own category next to IRM, and twenty vendors is a crowd.
What Reco builds is an inventory: which agents exist, which identities they use and what they can reach. No one can assess the risk of an agent they have not counted, so the inventory comes first. In The Two Roads to Autonomous IRM we described security platforms starting on the management road, and this is that road being paved with venture money. The open question is whether Reco stays security infrastructure or grows toward the business context that technology risk management needs, meaning which process an agent serves, what a failure would cost and who is accountable. If you are evaluating agent security tools, ask whether the agent inventory can feed your risk and third-party records, whether it captures a business owner and mandate alongside the technical identity, and who is told when the tool disables an integration.
What to watch
Integrations that carry agent findings into IRM platforms. Reco already routes findings into ServiceNow as tickets under an existing partnership. Beyond that, consolidation among the twenty or so vendors, and independent validation of the integration and detection counts.
6. Tokio Marine’s U.S. insurers move AI governance from policy to testing
What happened
On September 29, Monitaur announced that Tokio Marine North America Services, the shared services company for Tokio Marine Group in the United States, selected its platform to govern AI across several group companies. TMNAS will implement it for Philadelphia Insurance Companies, Tokio Marine America and First Insurance Company of Hawaii. According to the announcement, the program will:
• Establish acceptable risk tolerances for AI and monitor adoption against them.
• Give the group real-time visibility of AI in use and its conformance with governance objectives.
• Evaluate AI systems against governance requirements configured for insurance.
• Run Monitaur’s FlightSim on high-impact systems, using repeatable validations, simulated scenarios and black-box testing, which means testing a system from the outside through its inputs and outputs.
Robert Pick, chief information officer at TMNAS and deputy chief information technology officer for the group, cited Monitaur’s standing with carriers and regulators. The announcement came from the vendor. It gave no contract value, no timeline and no results.
Our read
This is what the enterprise half of the accord looks like when a regulated company builds it. The labs promised controls and outside assessment of their models. Tokio Marine is setting its own tolerances and testing whether the systems it runs are fit for use, which is where Assurance and Compliance become something a regulator can inspect. A policy says what should happen. A repeatable test produces a result with a date on it.
The structure is worth copying. A shared services company runs one governance program across several insurers, and each insurer keeps its own risk decisions. If you govern AI for a group of operating companies, settle three design questions early: whether tolerances are set at the center or by each company, who accepts residual risk when a system misses its tolerance, and whether the test results will stand as evidence in front of your regulator.
What to watch
Deployment results, since today there is only a signature. Whether insurance regulators accept simulation and black-box test results as evidence of fitness for use. And whether other carriers and other regulated industries adopt the shared-services pattern.
Our quick take
Not every item this week carries the same weight of proof, and not every item points the same way. Our quick take, subject to what the next few weeks show:
| Development | Evidence level | For the shift to IRM |
|---|---|---|
| Anthropic IPO prospectus risk factor on agent liability | Prospectus language as reported by Reuters; filing not yet public | Advances. Agent failure is now a disclosed corporate liability. |
| White House Accord on Super Intelligence | Signed voluntary commitment, described as morally binding; no deadlines or enforcement | Advances, with a caveat. The assurance stack stops at the lab's door. |
| FTI Consulting survey, AI's Second Act | Consultancy survey, 1,600 respondents, self-reported, mostly Europe | Advances. Weak control now costs performance. |
| OpenAI dots | Product live for two plans; enterprise in beta; no outcomes | Cuts both ways. Approval rules exist; the user sets them. |
| Reco $55 million funding | Definitive funding; product and customer figures company-reported | Advances. A customer paid for the agent inventory. |
| Tokio Marine selects Monitaur | Vendor-announced selection with named buyer executive; no results | Advances, with a caveat. Signed, not yet deployed. |
Net for the week: five advance the shift to IRM and one cuts both ways. The pushing came from outside the IRM platform market, led by a prospectus and a White House accord.
Takeaways, ranked
1. Put agent liability on the enterprise risk register with a named owner. Have counsel read your model provider contracts against Anthropic’s own warning, and ask your broker which policies would respond to a loss caused by an authorized agent.
2. Ask the accord’s signatories for the evidence it promises. An evaluator’s name, a scope and a committee charter are reasonable requests. Whatever you receive describes the lab’s controls, so keep it out of the column where you count your own.
3. Give every paused deployment an exit condition. Name the control or evidence that would let it proceed, the owner and the date. FTI’s number says most large companies have a stalled project; few can say what would restart it.
4. Manage agents as a portfolio before you turn on always-on ones. Each agent needs an owner, a mandate, delegated authority, approval thresholds and a way to be switched off, and those rules should be set by the company, with the user working inside them.
5. Replace AI policy statements with tolerances and tests where the stakes are high. Tokio Marine’s pattern of central governance, local risk decisions and repeatable validation is one a regulator can inspect.
References
1. Reuters, “Exclusive: Anthropic says rogue AI agents pose uncertain legal risk for the company,” September 29, 2026 (via Investing.com). https://www.investing.com/news/stock-market-news/exclusiveanthropic-says-rogue-ai-agents-pose-uncertain-legal-risk-for-the-company-4923159
2. Nextgov/FCW, “White House unveils ‘super intelligence’ executive order and industry accord,” September 29, 2026. https://www.nextgov.com/artificial-intelligence/2026/09/white-house-unveils-super-intelligence-executive-order-and-industry-accord/416325/
3. Forbes, “White House Releases ‘Accord’ Between Billionaire AI Execs: Here’s What It Says,” September 29, 2026. https://www.forbes.com/sites/saradorn/2026/09/29/white-house-releases-accord-between-billionaire-ai-execs-heres-what-it-says/
4. The White House, “Inaugurating the Era of Super Intelligence,” Executive Order, September 29, 2026. https://www.whitehouse.gov/presidential-actions/2026/09/inaugurating-the-era-of-super-intelligence/
5. The White House, “Fact Sheet: President Donald J. Trump Inaugurates the Era of Super Intelligence,” September 29, 2026. https://www.whitehouse.gov/fact-sheets/2026/09/fact-sheet-president-donald-j-trump-inaugurates-the-era-of-super-intelligence/
6. FTI Consulting, “Large Companies Slow AI Adoption as Cybersecurity Risk, Regulation and Trust Concerns Grow,” September 29, 2026. https://fticommunications.com/large-companies-slow-ai-adoption-as-cybersecurity-risk-regulation-and-trust-concerns-grow/
7. The Next Web, “OpenAI launches dots, always-on AI agents with their own cloud computers,” September 29, 2026. https://thenextweb.com/news/openai-dots-always-on-ai-agents-cloud-computers-devday
8. Axios, “OpenAI models posted user images online in latest security episode,” September 25, 2026. https://www.axios.com/2026/09/25/openai-models-posted-user-images-online-in-latest-security-episode
9. Quartz, “OpenAI is canceling its next AI model release over deception and safety failures,” September 28, 2026. https://qz.com/openai-gpt-61-astra-canceled-safety-deception-092826
10. Reco, “Reco Raises $55 Million in Additional Funding with Participation from AT&T Ventures,” September 29, 2026. https://www.reco.ai/blog/reco-raises-55-million-in-additional-funding-with-participation-from-at-t-ventures
11. TechCrunch, “Reco raises $55M as AI agent security startups crowd the market,” September 29, 2026. https://techcrunch.com/2026/09/29/reco-raises-55m-as-ai-agent-security-startups-crowd-the-market/
12. Monitaur, “Tokio Marine U.S. Company Selects Monitaur to Operationalize Enterprise AI Governance,” GlobeNewswire, September 29, 2026. https://www.globenewswire.com/news-release/2026/09/29/3370885/0/en/tokio-marine-u-s-company-selects-monitaur-to-operationalize-enterprise-ai-governance.html
Related from Wheelhouse Advisors
• Who Pays When the AI Agent Was Authorized?, The RiskTech Journal, Ori Wellington, September 1, 2026
• The Two Roads to Autonomous IRM, The RTJ Bridge, John A. Wheeler, September 3, 2026