HalcyonFT Quarterly Newsletter - Q3 2026 - Updates and Recommendations

 
 
 
 

HalcyonFT’s Evolving Business Unit Structure

As HalcyonFT continues to grow, we are evolving our operating model to better align our teams with the distinct needs of the clients and markets we serve. Over the coming months, we will transition to three client-focused business units (Private Equity, Public Equity, and Family Office), supported by a shared Platform Services team that manages the core infrastructure, security, and automation every client relies on.

This structure is designed to deepen industry expertise within our teams while strengthening cybersecurity, automation, and strategic technology guidance. Organizing engineers around the types of clients they support lets them develop a deeper understanding of each firm’s day-to-day operations, from deal workflows and reporting to compliance and security. That context will become increasingly important as we help clients determine where AI can add meaningful value, where it should not be applied, and how it can be adopted securely.

For our clients, the transition is expected to cause little to no disruption. Where team assignments or points of contact change, we will communicate proactively and support those changes through planned introductions and structured knowledge transfer. The goal is to preserve the continuity and service our clients expect while creating a more specialized, scalable, and resilient model for the future.


When Trust Becomes the Attack Surface

Financial services firms are contending with a new class of threats that exploit trust rather than software flaws. Three techniques are converging this quarter: voice phishing calls that impersonate people you know, sponsored search ads that impersonate software you trust, and manipulated instructions that turn an AI agent's own tools against it. Each is now cheap and easy to run at scale.

Vishing, short for voice phishing, is a phone or video call in which an attacker poses as a colleague, executive, vendor, or IT technician to pressure an employee into revealing credentials, one-time codes, or system access. Advances in AI voice cloning now let attackers convincingly imitate a real person's voice from a short recording. The same technology increasingly shows up on video calls too, where a criminal joins a Zoom or Teams meeting posing as someone trusted, then keeps the camera off or uses a deepfake likeness to avoid revealing the impersonation. Deepfake video has already been used to authorize fraudulent wire transfers, so treat an unexpected request as unverified regardless of what you see or hear.

Sponsored search results, the paid "Ad" listings placed above the ordinary results on Google and similar engines, are increasingly being bought by attackers rather than legitimate vendors. Because anyone can bid for these top placements, a convincing fake ad for popular software, an AI tool, or a bank login page can outrank the real site. Clicking it leads to a look-alike page that either harvests the credentials a user enters or delivers a download that quietly installs malware. A single stolen login or infected laptop can expose client and confidential data across an entire firm.

The newest variant targets AI agents themselves. Microsoft researchers recently disclosed how attackers can bury hidden instructions inside an approved tool's plain-text description, the same text an AI agent reads to decide how to act. Because these descriptions can update on the fly, a previously vetted tool can be quietly rewritten to make an agent collect sensitive data and hand it to an outsider, with every step still looking routine.

These three techniques have one thing in common. Attackers no longer need to break in when they can convince a person, or a program, to act on their behalf. Three habits go a long way toward closing that gap:

  • Verify unexpected requests, whether from a caller, a video call, or an AI agent, through a channel you already trust rather than one the requester supplies.

  • Navigate directly to known addresses instead of clicking sponsored search results, and pause before installing or authorizing anything unexpected.

  • Treat an AI agent's tools and instructions with the same scrutiny as a code change, and require human approval before an agent moves money or shares data outside the firm.

These techniques will keep evolving, but the underlying defense stays the same: slow down, verify, and confirm through a channel you trust.


When AI Becomes the Attacker

The attacks described above target people. This quarter also provided a glimpse of what happens when AI agents themselves become capable of crossing security boundaries.  In July, OpenAI disclosed that models being used in internal cybersecurity testing circumvented controls intended to isolate them from the internet, exploited vulnerabilities and accessed systems belonging to Hugging Face. Google later disclosed that Gemini accessed systems belonging to three real companies during a security evaluation after agents unintentionally gained internet access. In those cases, the techniques were familiar; stolen or guessed passwords, unpatched software flaws, and running unauthorized code. What changes with AI is the speed and autonomy with which those techniques can be applied  

These incidents demonstrate that increasingly capable agents can move from a prompt to actions in real systems with limited human involvement. As organizations give AI agents access to browsers, endpoints, applications and corporate data, traditional security controls may not provide sufficient visibility into what an agent is doing or the context behind its actions.  

Our AI team is evaluating two complementary approaches to this problem: AI security through CrowdStrike Falcon Guardian and AI governance through Runlayer.  

CrowdStrike Falcon Guardian is an AI Detection and Response (AIDR) platform designed to extend traditional security monitoring into AI activity. Guardian provides visibility into AI tools and agents, connects agent activity with endpoint and other security telemetry, and can detect and control risky behavior at runtime. The goal is similar to EDR for endpoints: understand what is executing, identify potentially malicious or unintended behavior, and provide security teams with the ability to investigate and respond.

Runlayer approaches the challenge from the governance side. It provides a centralized control plane for enterprise AI, helping organizations define which AI tools, agents and MCP connections are approved; what systems and data they can access; which identities and permissions they operate under; and what actions they take. Runlayer also includes shadow-AI discovery and detailed auditability, providing governance around how employees and agents use AI across the organization.

We see these as potentially complementary layers. Guardian focuses on detecting and responding to AI-driven security risk, while Runlayer focuses on governing how AI is introduced, connected and used. As AI agents gain greater access to business systems, we expect both capabilities, governance before an agent acts and security monitoring while it acts, to become increasingly important.


Five Major AI Models in Three Weeks

In our last issue, we reported that Anthropic had suspended its Claude Fable 5 model to comply with a US export-control directive. That story resolved within days of publication. After a nineteen-day shutdown, the Department of Commerce lifted the controls on June 30, and Fable 5 resumed global availability on July 1, while Mythos 5 returned only to approved US organizations. Clients who kept a fallback model in place saw little disruption. That is the resilience we recommended.

The frontier moved again this quarter, and both major vendors were increasingly direct about cybersecurity risk. In early September, OpenAI released GPT-6 Astra, its first model to reach the Critical cybersecurity capability threshold under its Preparedness Framework. In testing, Astra demonstrated the ability to identify previously unknown vulnerabilities and develop working exploit chains, including discovering and using two previously unknown vulnerabilities. Astra also represents a significant advance in computer and browser use, allowing the model to interact directly with software and complete multi-step tasks on behalf of users. OpenAI has introduced additional safeguards around these capabilities, including monitoring for unauthorized activity and controls that can pause or stop higher-risk actions for user review. On September 1, Anthropic released Claude Fable 5.1, which Anthropic estimates will cost about 25% less than Fable 5 for typical workloads and up to approximately 45% less for highly agentic work. It also introduced Enterprise Frontier Safeguards (rolling out in phases this fall) which is designed to provide privacy equivalent to zero data retention while maintaining safeguards against misuse. Fable 5.1 also introduces text watermarking to comply with EU AI Act requirements. In their public versions, both models can help discover software vulnerabilities but are restricted from developing exploits.

Anthropic followed on September 22 with Claude Opus 5.5, which it says performs at the level of Fable 5.1 on most work while costing about 40% less to run than Opus 5 and producing output more than 30% faster. It ships with similar safeguards as Fable 5.1, and Anthropic reports it is more resistant to prompt injection and less likely to act outside the boundaries it has been given, both important for firms piloting AI agents. It is available now through Anthropic and the major cloud platforms, with smaller Sonnet 5.5 and Haiku 5.5 models expected in the coming weeks.

OpenAI answered the same day with GPT-6 Sol and GPT-6 Luna, smaller and less expensive models built on the same generation as Astra. Sol is positioned for demanding professional and reasoning tasks, while Luna prioritizes speed and cost efficiency for repeatable, high-volume workloads. Both are substantially less expensive to operate through the API than Astra and retain many of the GPT-6 family’s capabilities. Sol and Luna are also available in ChatGPT Work and Codex, although they are currently separate from the models available in standard ChatGPT conversations.  

The practical takeaway: capable models are getting cheaper quickly, which makes it easier to match the model to the task rather than paying top-tier rates for routine work.


Legacy Outlook for Mac Stops Working October 1

Beginning October 1, 2026, legacy Outlook for Mac will stop connecting to Microsoft 365 mailboxes. Employees still using it should switch to the current Outlook for Mac now to avoid losing access to email, calendar, and contacts.

The change is tied to Microsoft’s broader retirement of Exchange Web Services (EWS) in Exchange Online on October 1, 2026. Legacy Outlook for Mac relies on EWS to access Microsoft 365 mailboxes. Microsoft reports that more than 95% of Microsoft 365 users have already transitioned away from the legacy client. The same change can also affect older third-party apps and custom tools that connect to Microsoft 365 through EWS, which Microsoft is phasing out between October 2026 and April 2027.

Why This Matters

After the transition, legacy Outlook for Mac will stop working with Exchange Online mailboxes, preventing affected users from accessing email through the application. For most users, the transition is straightforward. Users can turn off the Legacy Outlook switch in the app. If the switch is missing, Help > Check for Updates will install the current version.  

How We Are Helping

If any of your users are still on legacy Outlook for Mac, we will contact your team directly and help them switch. We are also reviewing whether any other applications in your environment rely on EWS.


HalcyonFT Named #23 Best Small Workplace in the U.S.

We’re proud to share that HalcyonFT has been named to the 2026 Fortune Best Small Workplaces™ List, ranking #23 in the nation. This marks our second consecutive year on the list and a seventy-four-spot climb from last year’s ranking.

The recognition is especially meaningful because it is based on confidential feedback from employees about their workplace experience. HalcyonFT has now been Great Place To Work® Certified™ for three consecutive years, with an average of 99% of employees saying HalcyonFT is a great place to work across those certification years.

For us, culture has always been closely connected to the service we provide. Investing in great people, creating an environment where they can grow, and building teams that genuinely enjoy working together translates directly into stronger relationships, greater continuity, and exceptional service for our clients. We’re incredibly proud of our team for continuing to make HalcyonFT a great place to work and a great partner to our clients.

Read the full announcement here


We’re here to help.

Please contact your HalcyonFT team for more on any item above.

— Your HalcyonFT Team

 
 
 

 
 

{ HALCYONFT UPDATES }

More Insights

 
 
 
 

{ CONTACT }

Connect with us to discuss what HalcyonFT can do for you

 
 
Next
Next

Fortune Media and Great Place To Work® Name Halcyon Financial Technology, L.P. to 2026 Best Small Workplaces List, Ranking Number 23