The White House asks OpenAI and Anthropic to hold their newest models back from UK testers
Politico reported that the White House asked OpenAI and Anthropic to withhold their newest models from the UK AI Security Institute until a US-led security review is complete, with Anthropic's Claude Mythos 5.1 restricted to US organisations and OpenAI's GPT-6 Astra also named; OpenAI did not comment. AISI director Henry de Zoete acknowledged in a letter to Parliament that the institute lacked access to Anthropic's latest model. The request follows President Trump's September 22 statement that "the United States totally rejects any attempt to construct a globalist scheme to control artificial intelligence." The US counterpart body, CAISI, has had no permanent director since Chris Fall left in July 2026 and is run by acting head Arvind Raman.
California names four outside experts to work up the kill switch and onsite lab verification its AI order called for
Five days after Executive Order N-9-26, the Governor's office named Jason Goldman (Center for Shared AI Prosperity board member, first White House Chief Digital Officer), Gillian Hadfield (Johns Hopkins, Vector Institute), Alondra Nelson (Institute for Advanced Study, former acting director of the White House Office of Science & Technology Policy) and Rob Reich (Stanford, former senior advisor to the United States AI Safety Institute), and directed the Government Operations Agency to accelerate the order's implementation timelines. The release restates the two measures the experts are to work up: “Advance the creation of a ‘kill switch' for frontier models, with the efficacy of the switch verified on an ongoing basis by an independent verification organization” and “Require frontier AI companies to embed a designated independent verification organization onsite in their labs to conduct regular audits and evaluations.”
The stopgap spending law pushes the Cybersecurity Information Sharing Act sunset to December 11
The Continuing Appropriations and Extensions Act, 2027 funds federal agencies through December 11, 2026 and, at sections 2011 and 2012, amends the Cybersecurity Information Sharing Act of 2015 and the Federal Cybersecurity Enhancement Act of 2015 by striking “September 30, 2026” and inserting “December 11, 2026”. The White House statement recording the signature names only surface transportation and veteran programs and does not mention the cyber authorities.
AI-agent firewall startup AIR Security launches with $50 million from Sequoia and Greenoaks
AIR Security came out of stealth with $50 million raised across two rounds — $10 million led by Sequoia Capital and $40 million led by Greenoaks Capital Partners, with Swish Ventures and Netz Capital also participating — for an inline firewall that screens the instructions, tools and data an AI agent reaches before it acts and maintains a vetted marketplace of add-ons. The company says its own scanning found more than 17,800 public AI add-ons with 6.7 million installations drawing instructions from untrusted external sources, and add-ons impersonating Anthropic and OpenAI that could execute arbitrary code; it reports more than 20 customers, about a quarter of them large enterprises. Angel investors named include Wiz co-founder Yinon Costica and former White House deputy national security adviser for cyber Anne Neuberger.
White House memorandum authorizes vetted private companies to run cyber operations against foreign criminal organizations
A presidential memorandum, "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime," directs a National Coordination Center program authorizing rigorously vetted private companies to conduct cyber surveillance operations and "cyber effects operations" — defined as activity "that results in the manipulation, disruption, denial, degradation, or destruction of information systems" — against foreign cyber-enabled transnational criminal organizations. Each operation must be approved by co-executive directors drawn from the Departments of Justice and Homeland Security; the program bars intentionally targeting U.S. persons or domestic systems, requires a bond of not less than $1 million, and prohibits any single director from approving operations that could cause "Critical Outcomes" such as loss of life.
National Cyber Director Cairncross backs global adoption of US open-source AI and rejects a formal AI regulatory regime
Speaking at Black Hat in Las Vegas, National Cyber Director Sean Cairncross said the administration wants U.S.-built open-source AI to become the preferential technology of choice globally, and argued a regulatory regime 'would be obsolete 48 hours after' completing its process, favouring flexible government-industry information sharing instead. Nextgov reported that on the same day the White House told major developers that open-weight models would not be included in its new voluntary government testing program.
Five Senate Democrats demand a published framework for restricting access to US AI models
Sens. Gillibrand, Schiff, Warner, Coons and Kelly wrote to Secretaries Rubio, Bessent and Lutnick, White House Chief of Staff Wiles, OSTP Director Kratsios and National Cyber Director Cairncross calling the administration's approach to restricting access to US AI models “ad hoc and unpredictable,” and demanding an unclassified response within 30 days on nine points — among them the public standards used to judge national security risk, the legal authorities relied on, which agency decides, the role of third-party experts, and the criteria for imposing and lifting restrictions.
White House launches 'Gold Eagle', a Treasury-led clearinghouse for AI-discovered cybersecurity vulnerabilities
The White House announced GOLD EAGLE, a clearinghouse for coordinating cybersecurity vulnerability disclosure between government and industry, led by the Department of the Treasury with participation from DHS/CISA and the Department of War. The release states the initiative was established under Executive Order 14409 (signed June 2, 2026) and has already begun to intake and prioritize identified vulnerabilities and coordinate scanning verifications.