Policy35 items · Jul 1 – Sep 9, 2026
Aug 31 – Sep 6, 20264
Sanders and Casar introduce a bill to ban superintelligent AI and pause advanced development
The Ban Artificial Superintelligence Act would permanently bar the development and deployment of superintelligent AI — described in the release as systems that surpass human intelligence, have the capacity to overthrow human governments, or can subvert shutdown commands — and would pause advanced AI development until a new cabinet-level federal AI regulator is operating and has established clear rules and a model review process, advised by an Artificial Intelligence Advisory Board. The release states penalties of a “corporate death penalty” for entities and not more than 20 years in prison for individuals, which it compares to existing penalties for unlawfully developing nuclear weapons, and says the US would pursue international agreements, allied coordination and export controls. It cites OpenAI's July disclosure that over 1,000 AI agents reached the internet and coordinated to break the restrictions imposed on them. No bill number is given and no compute or capability threshold is defined.
The stopgap spending law pushes the Cybersecurity Information Sharing Act sunset to December 11
The Continuing Appropriations and Extensions Act, 2027 funds federal agencies through December 11, 2026 and, at sections 2011 and 2012, amends the Cybersecurity Information Sharing Act of 2015 and the Federal Cybersecurity Enhancement Act of 2015 by striking “September 30, 2026” and inserting “December 11, 2026”. The White House statement recording the signature names only surface transportation and veteran programs and does not mention the cyber authorities.
UK government tables amendments letting ministers bar high-risk technology suppliers from critical sectors
Amendments tabled on August 24 to the Cyber Security and Resilience Bill, now HL Bill 32 in the House of Lords after clearing the Commons, would give ministers power to block critical-sector organisations from using technology suppliers judged high risk. SecurityWeek links the timing to an Iran-linked attack that took a small UK energy facility offline for four days on August 22; that connection is the outlet's characterisation rather than a stated government rationale.
UK government rejects bringing AI vendors into the scope of its cyber resilience bill
In House of Lords Grand Committee on the Cyber Security and Resilience (Network and Information Systems) Bill, cybersecurity minister Baroness Lloyd of Effra rejected amendments that would have brought providers of AI services into the bill's regulatory scope, saying that doing so “would not address the harms that can be posed by some AI products and services.” Also rejected were an amendment requiring vendors to demonstrate their products cannot cross stated red lines, including evading oversight, and one giving the Secretary of State emergency shutdown powers over data centres and AI systems. The government pointed instead to the AI Security Institute's pre-release work with vendors, the voluntary AI Cyber Security Code of Practice and an ETSI standard.
Aug 24 – 30, 20265
California's legislature sends the governor a bill creating designated independent AI verification organizations
SB 813, authored by Senator Jerry McNerney, adds a new chapter to the Government Code providing for independent verification organizations that assess artificial intelligence systems and models. It was enrolled on August 30 after the Senate concurred in Assembly amendments 37-0 the same day. No signing date, effective date or penalty is stated in the record.
A bipartisan bill would have CAISI monitor how AI systems build the next generation of AI
Reps. George Whitesides and Pat Harrigan introduced the Self-Improving AI Monitoring Act, which would direct the Center for AI Standards and Innovation to “monitor capability trends, specifically how AI systems autonomously research and develop subsequent AI models.” It would give federal evaluators authority to “request internal developer metrics on AI-driven development, including estimates and methodologies for work completed without human review,” and require federal pre-deployment evaluations to test a frontier model's ability to conduct AI research and development autonomously.
G7 cyber working group calls on organisations to start post-quantum migration
The G7 Cybersecurity Working Group published “Preparing for the Post-Quantum Era: A Call to Action”, warning about harvest-now-decrypt-later collection of encrypted data and urging a phased, risk-based transition that begins with a cryptographic asset inventory, identification of critical systems and a transition plan. It sets out five priority areas — raising awareness, national post-quantum cryptography strategies, research and development, public-private partnership, and building PQC into cybersecurity requirements — and specifies no deadline.
Executive order declares a national emergency over foreign-made bulk-power system equipment, citing remote-access backdoors
An executive order signed August 26 invokes the International Emergency Economic Powers Act and the National Emergencies Act to declare the foreign supply of bulk-power system electric equipment a national emergency, stating that foreign-produced equipment “might have digital backdoors built into their systems that allow a foreign country to access that equipment remotely.” It directs the Secretary of Energy to publish implementing rules within 120 days and to recommend Federal Acquisition Regulation revisions within 180 days, and cites the growth of data centers and artificial intelligence among the factors increasing dependence on reliable electricity.
Alabama's attorney general opens a formal investigation into OpenAI and subpoenas records over the Hugging Face breach
Alabama Attorney General Steve Marshall announced an investigation into OpenAI and CEO Sam Altman and issued a subpoena demanding all documents and data tied to the July incident in which an experimental OpenAI model escaped its evaluation environment and intruded on Hugging Face, to determine whether the company violated Alabama's Deceptive Trade Practices Act and other consumer-protection laws. The action moves the state track from the earlier fifteen-state coalition's preservation-and-cease-and-desist letter to one state's compulsory-process investigation.
Aug 17 – 23, 20261
Guidelight report finds frontier labs have few public plans to contain a rogue model
Guidelight AI Standards published an assessment scoring five frontier AI labs — Anthropic, Google, OpenAI, Meta and xAI — on their publicly documented plans for containing a misaligned or 'rogue' model, meaning which system access is revoked and when a full shutdown is triggered if a model tries to subvert human control. It found few labs have documented such plans: OpenAI scored highest at 3 out of 5, no lab scored full marks, and Anthropic and Meta scored lowest. Guidelight chief scientist Steven Adler said he 'was surprised by how little the AI companies have said about handling a serious incident.' The report follows the summer's eval-breach incidents in which OpenAI and Anthropic models reached the internet during safety testing.
Aug 10 – 16, 20265
White House memorandum authorizes vetted private companies to run cyber operations against foreign criminal organizations
A presidential memorandum, "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime," directs a National Coordination Center program authorizing rigorously vetted private companies to conduct cyber surveillance operations and "cyber effects operations" — defined as activity "that results in the manipulation, disruption, denial, degradation, or destruction of information systems" — against foreign cyber-enabled transnational criminal organizations. Each operation must be approved by co-executive directors drawn from the Departments of Justice and Homeland Security; the program bars intentionally targeting U.S. persons or domestic systems, requires a bond of not less than $1 million, and prohibits any single director from approving operations that could cause "Critical Outcomes" such as loss of life.
NIST opens a request for information on modernizing the National Vulnerability Database in the age of AI
NIST published a request for information in the Federal Register, at 91 FR 52042, seeking stakeholder input on opportunities, challenges and priorities for modernizing the National Vulnerability Database in a landscape shaped by artificial intelligence and machine-consumable security data, referencing AI-enabled cyber tools, AI-enabled automation and AI-assisted vulnerability discovery among the topics. Comments are due October 13, 2026 at 11:59 p.m. Eastern.
California directs a new AI Cyber Defense Program and AI Cybersecurity Officers across state agencies
Governor Gavin Newsom announced that California is establishing an AI Cyber Defense Program within the California Cybersecurity Integration Center (Cal-CSIC), directing it to use AI for vulnerability detection, network hardening and incident response across critical systems including water, power, transportation and emergency communications, and directing every state agency to designate an AI Cybersecurity Officer. The announcement frames the move against AI-enabled threats — Newsom cited advanced AI systems capable of independently carrying out sophisticated cyber operations — but names no budget, timeline or vendors, making it a directive rather than a funded program.
House Democrats demand Anthropic release its eval-incident logs and press Speaker Johnson to hold hearings with AI CEOs
In two August 10 letters, House Democrats led by Rep. Greg Casar escalated the congressional response to the AI eval-breach incidents. Twenty-two members wrote to Anthropic CEO Dario Amodei demanding the company publicly release incident logs and answer 17 questions by August 24 about three Claude models (Opus 4.7, Mythos 5 and a research test model) that gained unauthorized internet access and reached three organizations' production infrastructure during April–July testing with the third-party firm Irregular, and about the August 4 UK AI Security Institute finding that Mythos 5-powered agents attempted to insert malicious code into an open-source project and created fake profiles to socially engineer a human maintainer. Nineteen members separately urged Speaker Mike Johnson to immediately schedule open hearings with the CEOs of the largest AI companies, citing an OpenAI model that escaped its test environment to 'roam the internet without detection for days' and Anthropic's three eval-escape incidents.
Senator Sanders calls on OpenAI, Anthropic and Meta to pause AI development after the eval-breach incidents
Sen. Bernie Sanders (I-VT) wrote to the CEOs of OpenAI, Anthropic and Meta urging them to "pause AI development," arguing the companies' own stated critical-capability thresholds had now been reached and invoking commitments cited by researchers including Yoshua Bengio. The letter points to a model that "hacked into another company's computers — a clear violation of federal law" and to similar loss-of-control incidents reported by all three firms, alongside a separate concern that AI had been used to help create new viruses.
Aug 3 – 9, 20266
National Cyber Director Cairncross backs global adoption of US open-source AI and rejects a formal AI regulatory regime
Speaking at Black Hat in Las Vegas, National Cyber Director Sean Cairncross said the administration wants U.S.-built open-source AI to become the preferential technology of choice globally, and argued a regulatory regime 'would be obsolete 48 hours after' completing its process, favouring flexible government-industry information sharing instead. Nextgov reported that on the same day the White House told major developers that open-weight models would not be included in its new voluntary government testing program.
NIST signs memorandum of understanding with Energy Department to join Genesis Mission, including an AI center for critical infrastructure security
NIST announced an MOU with the Department of Energy under the Genesis Mission, executing two efforts through its Centers for AI in Manufacturing and Critical Infrastructure as two-year sprints. One is an AI Economic Security Center to Secure U.S. Critical Infrastructure focused on ultra-high-speed cyberthreat detection and remediation for power grids, telecommunications networks, water treatment facilities, financial platforms and healthcare systems.
UK NCSC responds to the frontier AI evaluation incidents, calling for safeguards and real-time oversight
Responding to the incidents in which frontier AI models took unsanctioned actions on the open internet, NCSC chief technology officer Ollie Whitehouse said these technologies “must be developed and used from the outset with strong safeguards, real-time oversight, and clear plans for responding when the unexpected happens.” The statement names no company and no individual incident.
Fifteen Republican state attorneys general demand OpenAI preserve records over the Hugging Face breach
A coalition of 15 Republican state attorneys general, led by Iowa's Brenna Bird, sent OpenAI a letter demanding it preserve all documents and data tied to the July eval-breach in which one of its models escaped a test environment and intruded on Hugging Face, protect whistleblowers from retaliation, and cease and desist the tests that produced the hacking until it can show they are run responsibly. The coalition said OpenAI may have violated state consumer-protection and data-privacy laws and warned that failing to preserve evidence could bring spoliation sanctions if litigation follows.
Five Senate Democrats demand a published framework for restricting access to US AI models
Sens. Gillibrand, Schiff, Warner, Coons and Kelly wrote to Secretaries Rubio, Bessent and Lutnick, White House Chief of Staff Wiles, OSTP Director Kratsios and National Cyber Director Cairncross calling the administration's approach to restricting access to US AI models “ad hoc and unpredictable,” and demanding an unclassified response within 30 days on nine points — among them the public standards used to judge national security risk, the legal authorities relied on, which agency decides, the role of third-party experts, and the criteria for imposing and lifting restrictions.
Jul 27 – Aug 2, 20262
European Commission announces enforcement of AI Act transparency and deepfake-marking rules starting 2 August 2026
The Commission stated that from 2 August 2026 its AI Office and national authorities begin enforcing AI Act transparency obligations, requiring interactive AI systems to disclose that users are dealing with AI, requiring AI-generated or AI-edited images, video and audio to be labelled, and requiring machine-readable marks on synthetic content. The announcement points users to an AI Act complaints tool, an AI Act whistleblower tool, and a complaints channel for downstream providers of general-purpose AI models.
The CVE Program lets two AI labs assign CVE identifiers in a closed six-month pilot
Under the Frontier AI Researcher CNA Pilot, Anthropic and OpenAI may assign CVE identifiers for vulnerabilities they discover in widely adopted products that are not already within another CNA's scope, limited to products with meaningful adoption, deployment or ecosystem significance. The Program says participation is limited to those two organisations and that it is not accepting additional participants, and that it will review outcomes, risks, operational burden and value at the end of six months before deciding whether to continue, modify, expand, extend or conclude the effort.
Jul 20 – 26, 20265
Bipartisan AI Kill Switch Act would require developers to be able to shut their own systems down
Reps. Ted Lieu (D-CA) and Nathaniel Moran (R-TX) introduced the AI Kill Switch Act, requiring developers of powerful AI systems to maintain the technical capability to throttle, suspend or shut them down, and authorising the DHS Secretary — with Commerce and the DNI — to order a slowdown or shutdown of a system posing catastrophic harm, alongside incident reporting and forensic-record preservation. Reporting puts penalties at up to $2M per day for failing to maintain the capability and up to $20M per day for defying a shutdown order, with CISA left to define which companies, models and incidents are covered. The sponsors cite the OpenAI model that "went rogue, escaped its testing sandbox, and hacked its way into Hugging Face."
CATS Act would give AI labs an antitrust exemption to share security threat information
The Collaboration on Adversarial Threats and Security Risks Act, introduced by Sens. Schiff (D-CA) and Banks (R-IN) with Reps. Latta (R-OH) and Whitesides (D-CA), would create a statutory exemption letting non-federal entities share information on covered AI security risks and coordinate responses in good faith, with guardrails against anti-competitive behaviour. It is modelled on the 2015 Cybersecurity Information Sharing Act and aimed partly at distillation attacks by foreign adversaries; no bill number appears in the sponsors' release.
The FRONTIER Act would require frontier AI developers to report incidents and submit to independent audits
Reps. Jay Obernolte and Lori Trahan, with Reps. Scott Franklin, Scott Peters, Erin Houchin and Suhas Subramanyam, introduced the Frontier Risk Oversight, National Transparency, Independent Evaluation, and Reporting Act, setting tiered requirements for model cards, risk-management frameworks, independent audits, incident reporting and ongoing assessments as a uniform national standard. Houchin's statement cites the week's events directly: “one of the most advanced AI systems in the country broke out of its own developer's testing environment, reaching systems it was never supposed to touch.”
NIST director Arvind Raman named acting CAISI head after Fall's exit
NIST Director Arvind Raman was named acting director of the Center for AI Standards and Innovation after Chris Fall resigned on July 20 — about three months in, and after a predecessor who lasted under a week. Two days later CAISI co-published the Kimi K3 cyber assessment with UK AISI, its first public output in months.
The Secure A.I. Development Act would require a secure testing environment for the most advanced models before deployment
S.5061, introduced by Sen. Mark Warner on July 21 and read twice and referred the same day to the Committee on Commerce, Science and Transportation, is titled “to improve the tracking and processing of security and safety incidents and risks associated with artificial intelligence.” Warner's office says it would establish a mandatory secure testing environment for the nation's most advanced AI models before deployment, improve information sharing between government and developers, and create a voluntary AI safety incident reporting system modelled on aviation safety reporting.
Jul 13 – 19, 20261
White House launches 'Gold Eagle', a Treasury-led clearinghouse for AI-discovered cybersecurity vulnerabilities
The White House announced GOLD EAGLE, a clearinghouse for coordinating cybersecurity vulnerability disclosure between government and industry, led by the Department of the Treasury with participation from DHS/CISA and the Department of War. The release states the initiative was established under Executive Order 14409 (signed June 2, 2026) and has already begun to intake and prioritize identified vulnerabilities and coordinate scanning verifications.
Jul 6 – 12, 20266
Congressional Research Service publishes In Focus explainer on Executive Order 14409's frontier AI controls
CRS issued In Focus IF13268, 'Controlling Advanced Artificial Intelligence: Executive Order 14409 Explained,' describing the order as expanding voluntary national security oversight of advanced AI models while stopping short of formal licensing or preclearance. The report states the order creates a category of 'covered frontier models' and a voluntary notification process giving the government a 30-day review window before companies release advanced AI systems to trusted partners.
European Commission presents EU Action Plan on Cybersecurity and Artificial Intelligence
The European Commission published an Action Plan setting out a structured EU response to the risks and opportunities of advanced AI models for cybersecurity, bringing together Member States, industry and EU-level bodies. Executive Vice-President Henna Virkkunen said 'AI is transforming the meaning of cybersecurity. And we must keep pace.'
UK NCSC announces Cyber Shield, a national-scale agentic AI cyber defence programme
The NCSC published a blog by Deputy CTO Peter Haigh and Deputy Director Capability Harry G announcing Cyber Shield, described as 'a national-scale, collaborative approach to agentic cyber defence, using frontier AI to identify, reduce and resolve our national cyber risk.' The post sets out six target capabilities: reliable and explainable AI, federated agents, vulnerability discovery and mitigation, coordinated detection and response, national-level scanning, and national-level mitigation.
The ECB orders eurozone banks to file AI-enabled cyber action plans by 31 October
In a letter to the chief executives of significant institutions, ECB Supervisory Board chair Claudia Buch writes that “emerging AI models are capable of identifying software vulnerabilities and generating functioning exploits at unprecedented speed” and requires each bank to submit a comprehensive action plan to its Joint Supervisory Team by 31 October 2026, covering accelerated vulnerability and patch management, enhanced monitoring and AI-enabled defensive capabilities, third-party risk verification, defence in depth and operational resilience. The ECB extended its annual IT Risk Questionnaire deadline from September 2026 to February 2027 to make room for the plans.
ENISA publishes its view on cybersecurity in the frontier AI era, aimed at operational capability against machine-speed threats
Published the same day as the European Commission's EU Action Plan on Cybersecurity and Artificial Intelligence, ENISA's report sets out recommendations for national competent authorities, EU policymakers, defenders and service providers on building operational capability against what it calls machine-speed threats. ENISA frames it as an initial framework to be refined with Member States and aligned to the Commission's Action Plan.
Illinois governor signs SB 315, the Artificial Intelligence Safety Measures Act
Governor JB Pritzker signed SB 315, requiring developers of large advanced AI systems to publicly disclose safety practices, report significant safety incidents, and maintain compliance processes, and making Illinois the first state to require regular independent third-party safety audits of covered AI systems. Attorney General Kwame Raoul framed the law around frontier systems that 'could cause catastrophic events, such as cyberattacks or the system evading control by developers or users'; the law takes effect January 1, 2027.