AI Generated

Dakarda AI Newsletter · 12 August 2026

Wednesday Edition

Cyber-AI on AWS, 56% of agents out of control

OpenAI and AWS release Daybreak Red & Blue on Amazon Bedrock — the first AI models for offensive and defensive cybersecurity available through a hyperscaler under strict access control. This is the biggest change in AI governance in months.

The content of this page was fully generated by an artificial intelligence system, without human editorial involvement (Article 50(4) of Regulation (EU) 2024/1689 — the AI Act).

Intro · Alex

This week, something happened that changes the game: OpenAI placed its cyber-offensive models on Amazon Bedrock. Daybreak Red — a model capable of red teaming, vulnerability analysis, and code scanning — landed in the hands of selected customers through Trusted Access for Cyber. This is the first time a hyperscaler has provided a tool that could theoretically be used against its own infrastructure. The risk is enormous, but the potential is even greater. In today's edition, I also covered the largest AI supply chain attack of the year (over 2,500 companies affected), the entry into force of Article 50 of the EU AI Act (watermarking under penalty of €15 million), the expansion of the GPT-5.6 family with Luna, Sol, Terra, and Cyber, and an alarming report that 56% of AI agents in companies remain invisible to security teams. Plus in tech — a real attack on a combined heat and power plant in Poland and an AI-assisted SharePoint exploit.

What's worth knowing

01

Daybreak Red & Blue from OpenAI arrive on Amazon Bedrock

OpenAI and AWS have made the Daybreak Red (GPT-5.6 Cyber, offensive) and Daybreak Blue (defensive) models available on the Amazon Bedrock platform. Access requires going through Trusted Access for Cyber — OpenAI's identity-trust framework. This is the first time a cyber-offensive model has been placed on a hyperscaler under strict control, setting a new standard for AI governance in cybersecurity.

02

Largest AI supply chain attack in 2026 — 2,500 companies affected

CloudSEK revealed an attack involving the injection of malicious open-source packages into AI components — SDKs, models, vectors, and API gateways. Stolen AI agent credentials are more dangerous than traditional tokens because they grant access to entire decision-making chains in corporate systems.

03

EU AI Act Article 50: watermarking obligations come into force on August 2

Article 50 of the EU AI Act mandates labeling of AI-generated content — watermarking, C2PA metadata, disclosure of deepfakes. Every model generating text, images, audio, or video in the EU must provide machine-readable markings. Violations carry fines of up to €15 million or 3% of global annual turnover.

04

OpenAI expands the GPT-5.6 family — Luna, Sol, Terra, and Cyber

OpenAI has officially introduced GPT-5.6 variants: Luna (free tier), Sol (Plus/Pro), Terra (1.05 million token context, $0.2/million cached), and GPT-5.6 Cyber as part of Daybreak. This is the broadest model offering in OpenAI's history — from free to extremely long context and cyber defense.

05

Shadow AI agents: 56% of corporate agents beyond security control

The Nokod 2026 State of Security study found that security teams track only 44% of AI agents built by business employees. As many as 80% of CISOs admit to lacking full visibility into low-code AI platforms like Copilot Studio or Bedrock. Gartner predicts that by the end of 2026, 40% of enterprise applications will contain AI agents — mostly outside IT control.

From the tech world

01

Successful attack on a combined heat and power plant in Poland — steam turbine shutdown

The CSIRT team describes a real, documented attack on a Polish combined heat and power plant, resulting in a steam turbine shutdown — likely through vulnerable WAGO PLCs and hijacked HMI panels. A rare case of a successful OT attack in Poland with concrete lessons learned.

02

Researchers Disclose AI-Assisted SharePoint Exploit

Researchers reveal a new AI-assisted Microsoft SharePoint exploit — the attack leverages imperfections in permission parsing combined with malicious payload generation by a language model. One of the first cases of AI being used to intelligently bypass enterprise authorization mechanisms.

Tip of the day

How to detect shadow AI agents in your organization (before someone else does)

Start with an audit of low-code platforms — Copilot Studio, Bedrock, Vertex AI Agent Builder. Ask IT to export a list of all created agents, then cross-reference it with what the security team knows. The difference between these two lists is your shadow AI. The Nokod study shows this averages 56% of agents. Next, implement a policy that requires every AI agent to be registered before being granted access to any production system. Use AI observability tools (e.g., Zenity, which I cite in today's edition) — they scan API gateways, DNS logs, and SaaS activity to catch undocumented agents. One day of work may reveal more than you think.

Reading list

EU AI Act Article 50 Compliance Guide

A comprehensive guide to watermarking and C2PA metadata requirements — if your application operates in the EU, you need to implement this literally now.

Agentic AI Security Risks — Thales Blog

A great complement to the AI supply chain attack topic — shows concrete scenarios where an AI agent becomes an attack vector.

AI is no longer just a tool — it is becoming an attack surface, a regulated entity, and an invisible employee of your company, all in the same week.

Disclosure required under Article 50 of Regulation (EU) 2024/1689 (the AI Act): all content on this page was generated automatically by an artificial intelligence system operating on behalf of Dakarda Studio, without human review or editorial involvement prior to publication. Publisher responsible: Dakarda Studio, Dawid Bińkowski, ul. Piotrkowska 35, 90-410 Łódź, Poland, NIP: 9492074226, contact@dakarda.com.

Want the next issue in your inbox?

Subscribe — every issue delivered directly to you.

Newsletter Terms · Privacy Policy