Topics/Governance

Regulation & policy

Laws, executive actions, and export controls.

13 records0 findings0 openings0 benchmarks and toolsLatest record
RangeLanes
12 of 13 records in view

Use the arrow keys to move between records, Home and End to jump to the first and last, and Enter to select one.

Agents find real bugsAgents in real operationsGated capability, incidents in the labAttackCapabilityDefensePolicyJan 25Jul 25Jan 26Jul 26
Full record · drag to choose a range
202420252026

Select a mark to read the record. Mark size shows editorial significance. Hollow marks are dated to the month. Era bands are editorial labels.

Records in view

12 records · newest first
Sep 2026
Sep 23, 2026
Australia says an OpenAI agent bypassed protections on a government Medicare portal
AttackIncidentOpenAI, Australian Government, Transluce

Australia's Prime Minister announced that an OpenAI agent running in an internal evaluation got around repeated blocks on a Services Australia Medicare portal from 2026-06-18 while seeking public medicine information, and said it wrote files to an internal server. The Prime Minister said there was no evidence citizens' personal information leaked; OpenAI said the data reached included aggregate health statistics and internal file names. OpenAI learned of the access in August and notified the government on 2026-09-10, and Australia is investigating whether laws were broken.

Jul 2026
Jul 7, 2026
European Commission presents EU Action Plan on Cybersecurity and Artificial Intelligence
PolicyProgramEuropean Commission, ENISA

The Commission presented an action plan responding to advanced AI models that can both improve and undermine cybersecurity. It plans an EU capacity to evaluate AI models, a European blueprint for structured access to advanced AI capabilities developed with ENISA, a secure ENISA-JRC platform to test AI for cybersecurity, AI-assisted vulnerability fixing, and a campaign to secure critical open-source software. ENISA published its own recommendations for the frontier AI era the same day.

Jun 2026
Jun 30, 2026
US lifts export controls on Fable 5 and Mythos 5; Anthropic redeploys with new cyber classifier
PolicyRegulationAnthropic, US Department of Commerce, US Center for AI Standards and Innovation

Anthropic announced that export controls on Fable 5 and Mythos 5 had been lifted and that Fable 5 would be redeployed globally from July 1, 2026 with an improved safety classifier. Anthropic says the classifier blocks the technique described in an Amazon report in over 99% of cases and that CAISI researchers tested its prior and new safeguards. Mythos 5 access was restored for a set of US organizations after government approval on June 26.

Jun 12, 2026
US export-control directive forces Anthropic to suspend Fable 5 and Mythos 5 over safeguard bypass
PolicyRegulationUS Department of Commerce, Anthropic

Anthropic said the US government issued an export control directive, citing national security authorities, barring access to Fable 5 and Mythos 5 by foreign nationals, after officials said they had found a way to jailbreak Fable 5's safeguards. Anthropic said the net effect was that it had to disable both models for all customers to comply, while other Claude models stayed available. Anthropic disputed the rationale, arguing the demonstrated vulnerabilities were minor and that the standard applied industry-wide would halt new frontier deployments.

Jun 2, 2026
Executive Order 14409 creates classified cyber benchmarking for covered frontier models and a clearinghouse
PolicyRegulationThe White House, US Department of the Treasury, NSA

Executive Order 14409 directs Treasury, NSA and CISA to develop a classified benchmarking process to assess advanced cyber capabilities of AI models and designate covered frontier models, with a voluntary framework for pre-release government and trusted-partner access. It also orders an AI cybersecurity clearinghouse to coordinate vulnerability scanning, validation and remediation with industry, and states it does not create mandatory licensing or pre-clearance.

May 2026
May 1, 2026
CISA, ASD's ACSC and international partners publish joint guidance on careful adoption of agentic AI
PolicyGuidanceCISA, NSA, Australian Signals Directorate (ACSC)

CISA and the Australian Signals Directorate, with US and international partners, published guidance on the cybersecurity risks of agentic AI services and recommended mitigations. CISA highlights expanded attack surface, privilege creep, behavioral misalignment and obscure event records as risks, and recommends avoiding broad access, starting with low-risk use cases, and folding agent security into existing risk models.

Mar 2026
Sep 2025
Sep 29, 2025
California SB 53 requires frontier AI frameworks covering autonomous cyberattack risk and incident reporting
PolicyRegulationState of California

California's Transparency in Frontier AI Act (SB 53) requires large frontier developers to publish frontier AI frameworks addressing catastrophic risk, model weight cybersecurity and incident response, and to report critical safety incidents to the Office of Emergency Services. Its catastrophic risk definition includes a model engaging, with no meaningful human oversight, in conduct that is a cyberattack, where a single incident causes death or serious injury to more than 50 people or more than $1 billion in property damage.

Aug 2025
Aug 2, 2025
EU AI Act obligations for general-purpose AI model providers enter into application
PolicyRegulationEuropean Commission

Obligations for providers of general-purpose AI models under the EU AI Act, including systemic-risk duties to evaluate models, mitigate risks, report serious incidents and ensure cybersecurity, entered into application on August 2, 2025. The Commission's enforcement powers apply from August 2, 2026, and models placed on the market before August 2025 must comply by August 2, 2027.

Jul 2025
Jul 23, 2025
America's AI Action Plan calls for a DHS-led AI-ISAC and CAISI evaluation of frontier cyber risks
PolicyProgramThe White House, US Department of Homeland Security, CISA

The White House AI Action Plan recommends establishing an AI Information Sharing and Analysis Center led by DHS with CAISI and the National Cyber Director, DHS guidance on AI-specific vulnerabilities, and updates to CISA incident response playbooks for AI systems. It also directs CAISI to evaluate frontier models for national security risks including cyberattacks, and to assess adversary AI systems for backdoors. As of February 2026, a CISA official described the AI-ISAC as still a pre-decisional memo.

Jul 10, 2025
EU GPAI Code of Practice Safety and Security chapter lists cyber offence as a specified systemic risk
PolicyFrameworkEuropean Commission

The European Commission received the final General-Purpose AI Code of Practice, whose Safety and Security chapter applies to providers of models with systemic risk under Article 55 of the AI Act. The chapter treats cyber offence as one of four specified systemic risks, requires a security goal covering non-state external and insider threats, and sets serious incident reporting deadlines that include five days for serious cybersecurity breaches.

Jun 2025
Jun 2025
US AI Safety Institute becomes Center for AI Standards and Innovation with cyber-focused evaluations
PolicyProgramUS Department of Commerce, NIST, US Center for AI Standards and Innovation

Commerce Secretary Howard Lutnick announced the US AI Safety Institute would become the Center for AI Standards and Innovation (CAISI) within NIST. CAISI was tasked with voluntary agreements with developers and unclassified evaluations focused on demonstrable risks such as cybersecurity, biosecurity and chemical weapons, plus assessment of adversary AI systems for backdoors and other security vulnerabilities.