ArXiv AI: Weekly Top Picks
This week in AI papers
We keep an eye on new AI papers on arXiv, pick one or two that really matter each day, and share the key ideas — no hype, just clear explanations.
We keep an eye on new AI papers on arXiv, pick one or two that really matter each day, and share the key ideas — no hype, just clear explanations.
Excerpt — Multimodal agentic retrieval-augmented generation (RAG) systems expand the attack surface beyond prompt injection to include text poisoning, image injection, direct-query attacks, and orchestrator-level tool…

Excerpt — Large language models (LLMs) are increasingly deployed in interactive applications, yet they remain vulnerable to adversarial interactions that induce harmful, deceptive, or policy-violating outputs. Existing defenses…

Excerpt — Retrieval-Augmented Generation enhances large language models by incorporating external knowledge, but deploying it in sensitive scenarios risks privacy leakage via malicious prompts. To address this, we propose a…

Excerpt — The rapid adoption of open-source Large Language Models (LLMs) in offline and enterprise environments has introduced a largely unexamined security risk like susceptibility to adversarial phishing prompts under static…

Excerpt — Foundation models are moving from response generation into operational roles. They plan across steps, call tools, request human input, coordinate with other agents, and increasingly carry responsibility for work that…

Excerpt — LLM agents increasingly rely on persistent long-term memory, which creates a critical vulnerability that we study here: memory poisoning. An adversary can store untrusted content in one session that later steers a…

Excerpt — Memory is a core component of AI agents, enabling them to accumulate knowledge across interactions and improve performance. However, persistent memory introduces the risk of memory poisoning, where a single adversarial…

Excerpt — Detecting harmful content in multi turn dialogue requires reasoning over the full conversational context rather than isolated utterances. However, most existing methods rely mainly on models internal parametric…

Excerpt — Tool-using language-model agents introduce security failures that go beyond unsafe text: they can disclose protected objects, write persistent memory, send messages, modify databases, or trigger harmful code and tool…

Excerpt — Modern AI agents retrieve documents, call tools, check intermediate information, and then produce a final answer or action. This creates a risk-control problem that is not visible from the final answer alone. A final…

Microsoft's Work Trend Index and Anthropic's Economic Index — two unrelated datasets — point at the same conclusion: AI value in banking is decided by the operating model, not the tooling. Here's what that means for corebanking.
Xi Jinping's WAIC 2026 keynote gave open-source AI exactly one sentence — and closed on being ready to change course. If your bank is building on Chinese open-weight models, that ratio is the strategy question. Part 1 of 3.
On 2 August, the EU AI Act's transparency obligations become enforceable. Six concrete scenarios from a bank's floor — chatbot, RM emails, market commentary, campaigns, call centre, agents — show why nobody owns this yet.
The market stopped hiring juniors because of AI — entry-level postings are down 32% in Switzerland alone. The data says that's the wrong conclusion, and the firms that see it have a rare window.