> daily_signal(2026_08_04)

IBM counted the AI breaches and found the model was almost never the way in. Interpol, Deel, and a legal-AI startup each proved the same point from a different angle this week.

PickBits Daily Signal · Tuesday, August 4, 2026

By Mark Pickering · 9 min read · August 4, 2026

// tl;dr

Four stories, and not one of them is really about the model. We have watched this enterprise-security story build for weeks: the Five Eyes warning in June, the agent that walked into Thailand's Finance Ministry last Monday. This week IBM finally counted it, and the number is blunt. The model was almost never the way in. The ungoverned access around it was. Interpol then says AI now drives more than half the cybercrime it tracked. Deel paid up to fifty million dollars because it can no longer assume a job candidate is a real person. And a legal-AI company gave away the plumbing so small firms can build what they could never license. The ChatGPT-in-court disasters are what made that last one click for me: the fix nobody funds is verification. Four different companies, one dull lesson, which is that the danger this week sat in what people left unlocked around the AI, not in the AI.

The model was rarely the problem this week; what sat around it was.

1. IBM counted the AI breaches, and 92% of them came through the door, not the model.

The expensive part of enterprise AI turns out to be everything you left unlocked around it.

IBM's Cost of a Data Breach Report 2026, run with the Ponemon Institute across 602 organizations, found that among firms that suffered an AI-related security incident, 92 percent had inadequate access controls on their AI systems. The part that actually matters is simpler than the headline: the model itself was rarely the entry point. In about one in five affected companies, the way in was a compromised API, a connected application, or a misconfigured cloud service, the connective tissue around the model, not the model. Whether a company ran an open-source or proprietary model made almost no difference. The money tracks the gap exactly: an AI-related breach averaged $5.33 million, against $4.70 million for breaches without an AI component, climbing to $6.04 million when the attackers themselves used AI, while the global average across all breaches rose 12 percent to a record $4.99 million.

We have watched this build all summer, and now it is measured. In June the Five Eyes agencies issued a joint warning about AI-assisted intrusion; last Monday an autonomous agent breached Thailand's Finance Ministry through exactly this kind of ungoverned access. And yes, a vendor selling zero-trust has every reason to wave a scary number around, and I held the report at arm's length for exactly that. But the finding cuts against IBM's own upsell. It points away from the expensive, model-centric fixes and toward the cheap governance most teams keep deferring. And the controls that would have stopped most of these are ones every IT team already knows how to deploy, which is the part that stings.

Screenshot of The Decoder's August 3, 2026 report on IBM's Cost of a Data Breach 2026 finding
the-decoder.com · August 3, 2026
Why this matters: Ninety-two percent of the companies breached through their AI had left it without basic access controls, which means the fix on your side is governance you already know how to do, not a new model you have to buy. The report moves the whole question from "is our model safe" to "who and what can reach it," and that second one is the part you can actually act on: it points you at the identity and integration layer first, where the cheap wins are. Action this week: Inventory every service, key, and connected app that can touch your AI systems and data, then put least-privilege and MFA on each one. My own read, after watching this arc build since June, is that the access layer is where the wins hide. About one in five of these breaches came in through a compromised API or a misconfigured cloud service, not the model. Get one question answered in writing before your next AI launch: who and what can reach this system, and can every one of them prove least privilege and a second factor. That single answer would have closed most of these.

the-decoder.com: IBM finds 92% of companies hit by AI security breaches lacked basic access controls (August 3, 2026)

2. Interpol says more than half the cybercrime it tracked now runs on AI, and 600,000 deepfake extortions prove it.

The scam machinery is industrial now, and the same tooling lands on Americans as sextortion and romance fraud.

Interpol's African Cyberthreat Assessment 2026, published this week on data from 36 countries, found AI involved in 55 percent of reported cybercrime and financial losses of $484 million in 2025, more than double the $192 million recorded in 2024. The assessment logged roughly 600,000 digital-extortion cases involving deepfakes. Neal Jetton, head of Interpol's cybercrime directorate, put it plainly: "AI is automating every stage of a cyberattack from reconnaissance and phishing to extortion and evasion." The report is regional, which puts it a step from a US-immediate story. But the tooling it documents is exactly what reaches Americans as deepfake sextortion, romance scams, and pig-butchering investment fraud.

We covered this build in June, when Google sued a China-based network for weaponizing Gemini to automate scams, and again in a July survey that put AI or deepfakes in 12 percent of successful scams. The response is scaling too, just slower than the crime: Interpol-coordinated operations across 2025 and 2026 produced more than 1,500 arrests and over $100 million seized. The new part is the scale: reconnaissance-to-extortion running as a pipeline, at a size that used to be out of reach for anyone but organized crime.

Screenshot of The Decoder's August 3, 2026 report on Interpol's African Cyberthreat Assessment 2026
the-decoder.com · August 3, 2026
Why this matters: There is now a real chance the next unexpected video or voice from someone you trust, a boss, a relative, a match you have been talking to, is an AI fake built to pull money or intimate images out of you. Interpol's numbers are the clearest public confirmation yet that this is mass-produced, not a rare scam you would spot a mile off. Action this week: Verify any surprise request for money or explicit images on a separate channel you already trust. Call the person back on a number you have, not the one that reached you. When I have watched these cases, speed is the only thing that ever claws money back, so report AI-enabled fraud to the FBI at ic3.gov and your bank the same day. And lock your kids' photos behind private accounts, because the raw material for a deepfake is the pictures already public. Share this one with the person in your life who would swear it could never be them.

the-decoder.com: Interpol says AI has become the core operational driver of cybercrime across Africa (August 3, 2026)

3. Deel paid up to $50 million to answer one question: is this job candidate a real human?

Confirming a new hire is a real person is becoming a line item in HR security.

On August 3, Deel, a US-Israeli payroll and HR platform running a $1.5 billion revenue run rate for more than 40,000 businesses across 150-plus countries, acquired Tel Aviv deepfake-detection startup Clarity for an estimated $45–50 million, its 15th acquisition and first in Israel. Clarity, founded in late 2022 by CEO Michael Matias, CTO Natalie Fridman, and CSO Gil Avriel (about $16 million raised from Walden Catalyst and Bessemer), builds AI that detects manipulated faces, cloned voices, forged identity documents, and live deepfake video, so an employer can confirm a candidate is a real person. Deel is embedding those checks across hiring and workforce identity. This is not just a theory: Gartner projects that by 2028, one in four job applications will be fake, and the US State Department and FBI have warned that North Korea runs a network of IT workers posing as other nationals to get hired into Western companies and reach sensitive systems.

My honest read is that this crosses a line the security world has been circling for months. It is the same story as the North Korean intrusions we covered when hackers sat inside South Korea's diplomat-training system for nine months. The question stops being "is this résumé real" and becomes "is this candidate a real human being." Does buying a detection company actually close that gap? Only partway, I think. A synthetic face gets caught at the interview, but a stolen-but-real identity is a harder problem than any single vendor solves. Still, the fact that a payroll company this size decided the threat was worth an acquisition rather than a feature tells you where hiring is heading: toward making "prove you are a real person" just another step in getting hired.

Screenshot of the Times of Israel's August 3, 2026 report on Deel acquiring Clarity to fight fake hires
timesofisrael.com · August 3, 2026
Why this matters: The person who aces your next remote video interview can now be a synthetic face over an invented or stolen identity, and Gartner expects one in four job applications to be fake by 2028. This is not a fringe security concern any more. It is moving into the ordinary hiring pipeline, which is why a payroll giant just paid tens of millions to screen for it. Action this week: Add liveness and deepfake checks to remote interviews and onboarding, and before you sign any verification vendor, get in writing exactly what they inspect (face, voice, live video, documents) and whether they catch a swapped face, not just a stolen name. My own read is that the video call is now necessary but nowhere near sufficient proof, so don't grant a new hire access to anything sensitive until identity clears independently. That gap is the North Korea IT-worker playbook the FBI has flagged, and it turns on exactly this.

timesofisrael.com: US-Israeli payroll unicorn buys Tel Aviv AI cyber startup to combat fake hires (August 3, 2026)

PickBits Daily Signal is free. If it lands in your inbox every day and it is worth something to you, the best way to support it is to forward it to someone who would read it. Subscribe today!

4. A legal-AI company open-sourced the plumbing for pro-grade research, free for the firms that could never afford it.

The tools big firms take for granted just got a free foundation for the clinics and two-lawyer shops that can't.

Descrybe open-sourced the Descrybe Open Connector under an Apache-2.0 license: a Legal Engine Python SDK plus reusable Legal Research Workflows: building a research roadmap, surfacing competing authority, and auditing the citations and quoted language in a brief before it reaches a judge. The company's Legal Engine, built by CEO Kara Peterson and CTO Richard DiBona, supplies structured US primary law, legal-specific retrieval, citation-and-"treatment" intelligence, and source verification. Be precise about what is and isn't free here: the underlying legal-intelligence database and hosted-engine access still require a paid Descrybe license, governed separately by its terms of service. Only the SDK and the workflows are Apache-2.0. This is not free legal research. What is free is the connective code that lets a firm build and own custom tools on top of the engine.

This is the hopeful one of the four, and it answers a problem the others keep circling. The same citation-audit workflow Descrybe just opened goes straight at the courtroom disasters piling up: the lawyers sanctioned for filing hallucinated citations they never checked. We saw a version of this in July, when a Philippine platform put a free AI legal-search tool in front of the public. This is that same push, down in the plumbing this time. The catch is real: the plumbing is open, but the engine underneath still costs money. So I am not sure yet whether clinics actually build on this or the paywall keeps the good part out of reach.

Screenshot of LawSites' July 27, 2026 report on Descrybe open-sourcing its legal-research connector
lawnext.com (LawSites) · July 27, 2026
Why this matters: Professional-grade legal research has always been priced for big firms, and that gap is a real part of why access to justice is so uneven. This week a legal-AI company handed the small firms, clinics, and legal-aid groups on the wrong side of it a free foundation to build on. The catch matters too: the tooling is open, but the data engine underneath is still paid, so this lowers the build cost rather than the whole cost. Action this week: Point your legal-tech or clinic developers at the Open Connector SDK and workflows on Descrybe's repos. They're Apache-2.0, so you can build your own research and citation-audit tooling instead of buying a closed platform, as long as you budget for the hosted-engine license that stays paid. My read is the real test is adoption, not the license: watch whether actual clinics ship something on this in the next few months, or whether the paywall underneath keeps it out of reach. If you know someone doing access-to-justice work, send it their way.

lawnext.com (LawSites): Descrybe empowers law firms to build and control their own AI-powered legal workflows (July 27, 2026)

» What to watch this week

Tomorrow's signal lands here.