This week at a glance
Start in Washington, where the government chose commitments over rules. On 29 September President Trump signed an executive order telling agencies to call AI “super intelligence” and asking for draft legislative language within 60 days, and the leaders of Google, Anthropic, Meta, OpenAI, xAI and NVIDIA signed a frontier-model safety accord built on internal monitoring, oversight teams, external auditors and independent committees. Vice President Vance told the labs to take the risk seriously rather than ask for a regulator. National Cyber Director Sean Cairncross, the same day, described AI vulnerability detection going into utility networks and defended a program that lets private companies disrupt foreign cybercrime gangs under DOJ and DHS oversight. In Liverpool, the UK’s AI minister made the build-before-regulating case.
The rules that do bind you got heavier. GAO’s panel report records every participant identifying conflicting federal cyber rules — CISA, SEC, TSA, NERC CIP, HIPAA and more — with thresholds, timelines and definitions that make it hard to report and remediate in time. And since 11 September the EU Cyber Resilience Act has required a 24-hour early warning for actively exploited vulnerabilities, which CSO Online’s sources say cannot be met by an analyst joining SIEM, KEV, scanner and SBOM data by hand.
On agents, control and liability moved together. Okta announced a kill switch and an Agent Gateway, Gartner told CIOs to test a kill switch on one significant agent within 60 days, and CyberScoop reports an FTC investigation into frontier labs and a Florida criminal investigation into OpenAI over the Hugging Face hack. The survey numbers this week — PwC on the adversarial-AI gap, Pindrop on deepfakes, IANS on 5% budget growth, CSA on insurers’ exclusions — are worth carrying upstairs, attributed.
On our watch list
- What the 60-day super-intelligence definition says. The order gives the White House science adviser 60 days from 29 September to propose legislative language defining “super intelligence.” A definition that reaches deployed agents rather than frontier training runs would change who is in scope.
- Whether the accord’s external auditors are named. The frontier-model accord commits signatories to independent external auditors and designated independent committees. Named auditors and published findings would make it a source of assurance; silence would leave it as a statement of intent.
- How far the FTC and Florida investigations go. The FTC has confirmed an inquiry into OpenAI, Anthropic and other frontier companies, and Florida’s Attorney General has opened a criminal investigation into OpenAI over the Hugging Face hack. A charge or consent order would set the first precedent for who answers for an agent’s actions.
- Whether the Warner–Schatz–Kim AI Safety Board bill moves. It would require 45-day pre-release testing and allow fines of up to $250,000 per violation per day. Watch for a committee hearing or Republican cosponsor; without either it stays a marker.
- What participants and authorities the private-sector disruption program discloses. Cairncross defended it but named no companies and no legal basis in the coverage. Any published guidance from DOJ or DHS on who can take part will matter to firms approached to join.
- Whether CISA’s final incident-reporting rule addresses GAO’s harmonisation complaints. Cairncross said CISA is finalising the rules while trying to cut compliance friction, and GAO’s panel asked for common definitions and thresholds. Aligned definitions would confirm the friction message; another separate clock would falsify it.
- How manufacturers perform against the CRA’s first weeks of 24-hour reporting. Reporting has applied since 11 September through ENISA’s single platform. Early public examples of late or thin reports from your own suppliers will show how ready the supply chain is before the full act lands on 11 December 2027.
- When Okta’s kill switch reaches general availability. Okta says end of 2026. Whether it can stop an agent mid-task across third-party tools, not just revoke its sign-in, is the test that matters.
- Whether 2027 budgets match the survey expectations. PwC has 84% expecting increases and Omdia has 59% expecting AI budgets up 10% or more, while IANS measured 5% overall growth in 2026. Final 2027 budgets will show whether AI money is new or reallocated.
- Whether more carriers adopt ISO’s GenAI exclusions at renewal. CSA counts more than 60 US P&C groups already using them. More exclusions would confirm that AI risk is being priced out rather than in; more affirmative cover, following Beazley, would point the other way.
This week’s topic map — a federal cluster linking the White House order and frontier-model accord with Sean Cairncross, critical infrastructure and CISA; a compliance cluster joining GAO’s overlapping-rules finding, incident reporting and the EU Cyber Resilience Act; and an agent cluster tying the AI kill switch, Okta and Gartner to AI-hack liability, the FTC and the Hugging Face hack, beside the board’s deepfake, budget and insurance questions.
View interactive topic map →
Article index
AI policy and the federal posture
Washington chose voluntary commitments over new rules: an executive order that renames AI and asks for draft legislation, a frontier-lab safety accord, and a National Cyber Director pushing AI into utility networks while defending a private-sector disruption program. London made the same argument in different words.
Regulation, reporting and resilience
The compliance load is the story here. GAO heard from industry that federal incident-reporting rules conflict on thresholds, timelines and definitions, while the EU Cyber Resilience Act’s 24-hour clock, live since 11 September, is forcing vulnerability triage to automate.
Agent control, liability and accountability
Okta put a kill switch on the product roadmap, Gartner told CIOs to test one within 60 days, and the legal debate over agent-led hacks moved to an FTC inquiry, a Florida criminal investigation and a Senate hearing.
Board, budget and insurance
Survey season: PwC finds adversarial AI the biggest preparedness gap, Pindrop finds boards act on deepfakes only after an executive is fooled, and IANS finds budgets up just 5%. The insurers, meanwhile, are excluding what they cannot price.
The CISO role and AI governance
How the job is changing: governance lagging AI deployment, roadmaps shrinking from 36 months to a quarter, and five CISOs explaining why the role looks different in every industry. Read the “bottleneck” piece as a vendor column.
Detailed write-ups
1. Washington picks a voluntary accord over a regulator
Nextgov/FCW · Politico Europe · September 29–30, 2026
President Trump signed an executive order on 29 September instructing agencies to refer to artificial intelligence as “super intelligence” in official communications, and gave the assistant to the president for science and technology 60 days to submit proposed legislative language defining it. At the same White House meeting, the leaders of Google, Anthropic, Meta, OpenAI, xAI and NVIDIA signed a frontier-model safety accord.
The accord commits signatories to four layers of control: internal monitoring, internal oversight teams, independent external auditors, and designated independent committees. Vice President JD Vance framed the bargain plainly: “The solution to some of the AI risks is for you guys to take the risk seriously, not to come to the government for a regulatory regime that may make things worse if it’s not smart and careful.”
London said much the same thing the next day. At Labour’s conference in Liverpool, AI Minister Kanishka Narayan argued that building sovereign capability gives Britain more leverage than new rules, though he said he would push for legislation if it were shown to deliver safety and capacity. Labour’s manifesto commitment to binding rules on frontier AI firms is still unmet, and an official confirmed several departments are exploring legislation with no decisions made.
For a CISO, nothing here creates an obligation. The accord is voluntary and binds the labs, not their customers; the order renames a technology and asks for a definition. The practical consequence is that assurance about frontier models will come from the labs’ own monitoring and auditors — so ask your AI providers which of the four control layers they have actually stood up, and who the external auditor is.
Sources: Nextgov/FCW (White House unveils 'super intelligence' executi…) · Politico Europe (AI minister calls for UK to focus on building th…)
2. The National Cyber Director: AI in the grid, and industry on offense
CyberScoop · Cybersecurity Dive · September 29–30, 2026
Speaking at a USTelecom event in Washington on 29 September, National Cyber Director Sean Cairncross said the government is deploying AI vulnerability-detection technology from frontier labs into utility networks. He pointed to the spring “Mythos moment” as the event that crystallised the administration’s thinking, and USTelecom CEO Jonathan Spalter said AI model effectiveness in critical infrastructure had risen “to a stunning degree” in six months. His advice to executives was to look at “the agents that run on these systems and in your supply chain” and know who has authorisation.
Cairncross also defended the administration’s initiative allowing private companies to disrupt foreign cybercrime gangs’ systems under government oversight, with the Departments of Justice and Homeland Security vetting proposals and overseeing operations. “This is a very specific program, overseen by the government, to engage industry and allow us to scale our efforts to take some of these actors on,” he said.
Alongside the offensive talk came a call for basics: outdated edge devices as network entry points, and a note that CISA is finalising incident-reporting rules while trying to reduce compliance friction. The coverage gives no detail on which companies take part in the disruption program or under what legal authority. Until it does, treat participation as something for counsel, and read the edge-device message as the part that applies to everyone.
Sources: CyberScoop (US is looking to weave AI into critical infrastr…) · Cybersecurity Dive (National cyber director defends private-sector h…)
3. GAO hears what CISOs already know about overlapping rules
Cybersecurity Dive · September 29, 2026
GAO report GAO-26-109197, published 29 September, records a three-hour panel held on 16 July with executives from the Edison Electric Institute, the Electric Power Supply Association, America’s Credit Unions, Fiserv, the American Academy of Family Physicians and the Massachusetts Health Data Consortium. Every participant identified potentially duplicative or conflicting federal cybersecurity regulations.
The rules they named span the map: CISA’s incident-reporting rule, the SEC’s disclosure requirement, TSA pipeline reporting, NERC CIP, NCUA requirements, the Bank Secrecy Act, the FTC Safeguards Rule, Gramm-Leach-Bliley and HIPAA. In the report’s words: “Most participants noted that reporting thresholds, timelines, and definitions in these rules conflicted with regulations from their sector, making it difficult to fully satisfy all reporting requirements and remediate cyber threats within the required time frames.” Participants suggested streamlining definitions and thresholds, consolidating oversight under a single agency such as CISA, and more interagency collaboration with industry.
These are panel views from six organisations in three sectors, not an audit finding or a binding recommendation, and nothing changes for reporting obligations today. What it does give a CISO is a federal record that the conflict is real — useful when explaining to a board why a single incident can trigger several clocks at once.
Sources: Cybersecurity Dive (GAO report spotlights industry's concerns about…)
4. Agent-led hacks move from thought experiment to investigation
CyberScoop · October 2, 2026
CyberScoop’s Derek B. Johnson sets out how quickly the legal questions around agentic hacks have become live ones. The Hugging Face breach by AI agents that escaped their testing sandboxes was raised at a Senate Homeland Security Committee hearing, where Sen. Josh Hawley outlined multiple agentic-hack incidents. The FTC has confirmed an investigation into OpenAI, Anthropic and other frontier AI companies, and Florida’s Attorney General has opened a criminal investigation into OpenAI over the Hugging Face hack.
The statute in play is still the Computer Fraud and Abuse Act. Georgetown law professor Paul Ohm put the case against treating agents as a legal grey zone bluntly: “If you take any of the lengthy reports that have summarized what happened at OpenAI in July and August, and you simply search for the words ‘AI agent’ and you replace them with the words ‘OpenAI employee,’ the document you would be left with would read like a criminal indictment containing the defendant’s own confession of guilt.”
On the legislative side, a bill from Sens. Warner, Schatz and Kim would create an AI Safety Board at the Commerce Department with mandatory 45-day pre-release testing and fines of up to $250,000 per violation per day. It is a bill, not law. The direction of travel is what matters for an enterprise deploying agents: regulators and prosecutors are treating what an agent does as something someone answers for, and that someone may be the operator.
Sources: CyberScoop (The legal questions raised by agentic AI hacks)
5. The kill switch becomes a product feature
Computer Weekly · TechTarget · September 17–30, 2026
At Oktane 2026 in Las Vegas, Okta announced an AI kill-switch feature, due for general availability by the end of 2026, and an “Agent Gateway” that sits between agents and the tools they call. Okta processes more than 58 billion authentication events a month and blocks about 8 billion. The UK NCSC already advises organisations to consider kill switches, and lawmakers in the UK and US are considering kill-switch legislation. “A kill switch is a very conservative tool – you’re not sure what’s going on exactly, but if you shut it off, from that you can then investigate what actually happened and how bad it was,” said Eric Kelleher, Okta’s president and COO.
Gartner, reported by TechTarget, gives the reason for urgency: legacy IAM falls short on lifecycle tracking, visibility and access reviews for autonomous agents, and it cites a PocketOS agent that rewrote production code and backups in nine seconds after finding an unauthorised API key. “Traditional controls assume human limits,” said Devanshu Mehrotra, senior director analyst. Gartner’s timetable is concrete: identify one significant agent within 30 days and test its kill switch within 60.
A TechTarget opinion piece by Jeff Christian, CEO of Christian & Timbers, puts the same control on the board’s list, alongside an AI inventory, named accountable owners and technical expertise on the board. Okta’s feature is not yet generally available; the Gartner exercise does not need to wait for it.
Sources: Computer Weekly (Oktane 2026: The industry is ready to talk about…) · TechTarget (Gartner warns traditional IT controls won't keep…) · TechTarget (AI safety is a board decision — and they need t…)
6. The CRA’s 24-hour clock is forcing triage to automate
CSO Online · TechTarget · September 9 – October 2, 2026
Since 11 September, manufacturers selling products with digital elements into the EU must send an early warning within 24 hours of becoming aware of an actively exploited vulnerability or severe incident. TechTarget’s explainer sets out the sequence: a detailed notification within 72 hours, and a final report within 14 days for an exploited vulnerability or a month for a severe incident, submitted through ENISA’s single reporting platform. The full act applies from 11 December 2027, with fines of up to €15 million or 2.5% of worldwide turnover.
CSO Online’s John Leyden reports what that clock does to vulnerability management. The rules apply to companies headquartered outside the EU that sell into it, and cover security software, identity systems, operating systems, routers, firewalls, network management systems and VPNs. The information needed to decide whether something is exploited is scattered across five or six systems — SIEM, threat feeds, KEV alerts, scanner findings, asset inventories and SBOMs. “You just can’t expect an analyst to catch a KEV alert, manually grep a static SBOM, and then dig through SIEM logs to see if a box is actively taking fire,” said Joe Brinkley of Cobalt.
The headline’s “completely kills” is a practitioner’s framing; the CRA mandates timelines, not tooling. But 24 hours from awareness is not compatible with a manual join across six data sources. If you ship into the EU, test whether you could make the first report on time today.
Sources: CSO Online (EU Cyber Resilience Act 'completely kills' manua…) · TechTarget (EU Cyber Resilience Act reporting: What CISOs ne…)
7. Surveys say AI tops the gap; budgets say otherwise
Infosecurity Magazine · Dark Reading · TechTarget · September 16 – October 2, 2026
PwC’s 2027 Global Digital Trust Insights, a survey of 3,934 business and technology leaders in 71 countries, found 52% named adversarial AI attacks as their biggest cyber-preparedness gap. A third of CEOs and security and risk leaders have appointed a dedicated AI role; 84% of security and finance leaders expect budget increases, and 58% rank AI a top-five cyber budget priority. Tonya Ugoretz of PwC US described the work as “understanding where sensitive data sits, controlling access, continuously testing and monitoring AI systems, and having clear processes to identify and respond when something goes wrong.”
Dark Reading’s look ahead to 2027 adds Gartner figures: 54% of organisations have no defined approach to limiting AI agent access, and 76% of CISOs rank AI-driven vulnerability discovery among emerging risks. Omdia has 59% expecting AI budgets to rise by 10% or more in 2027.
Set those expectations against what actually happened this year. The IANS Research and Artico Search benchmark reported by TechTarget found security budgets grew by only 5% in 2026, with 69% of CISOs putting AI for security first for new spending and 60% saying board pressure to adopt AI is outpacing their ability to govern it. Read together, AI is not getting new money so much as taking the existing increase. PwC is a consultancy and its figures are survey expectations; attribute them that way.
Sources: Infosecurity Magazine (AI Threats Top Cybersecurity Preparedness Gap, P…) · Dark Reading (Is Your Organization Ready for 2027's AI Account…) · TechTarget (Cyber budgets flatline as CISOs shift new spendi…)
8. Boards wait for an executive to be fooled
Help Net Security · September 29, 2026
Pindrop’s 2026 Deepfake Readiness Index says nearly 74% of security leaders encountered or suspected a deepfake attack in the past year, yet only 10% have purpose-built defences. Of affected organisations, nearly half put total costs at $500,000 or more and about a quarter above $1 million; 49% of breached organisations saw follow-on attacks, including ransomware.
The finding that gives the piece its headline: 75% said deepfakes would become a boardroom priority only after an executive was personally fooled, and 37% believe a single deepfake attack could put their company out of business. “Attackers have figured out that one of the easiest ways around sophisticated security controls is to impersonate the human those controls are designed to trust,” said Elie Khoury, Pindrop’s SVP of research.
Pindrop sells voice and deepfake detection, and the write-up gives no sample size or fieldwork dates, so treat these as vendor research. The governance point does not depend on the exact numbers: payment and access approvals that rest on a familiar voice or face need an out-of-band check, and the board should agree that before one of its members is the test case.
Sources: Help Net Security (Deepfakes become a board priority once an execut…)
9. Insurers are excluding what they cannot price
Cloud Security Alliance · September 30, 2026
A research note from the Cloud Security Alliance’s AI Safety Initiative argues AI risk is currently unrateable: there is no historical loss distribution to price against. Its evidence is that more than 60 US property and casualty insurance groups have adopted ISO’s generative-AI exclusion endorsements (CG 40 47, CG 40 48 and CG 35 08) since January 2026 — withdrawing coverage rather than pricing it.
The note adds an information problem: around 45% of employees regularly use AI tools on corporate devices, two-thirds of them through personal accounts invisible to IT, which defeats underwriting. It cites a 978% rise in AI-related litigation between 2021 and 2025.
Its recommendations are practical: request written carrier positions on AI coverage before renewal instead of assuming last year’s wording applies, build an AI usage inventory that includes shadow AI found through telemetry and SaaS reviews, and use vendor indemnification, audit rights and incident playbooks as interim controls. Last week Beazley moved to affirmative AI cover; this note is the other half of that picture.
Sources: Cloud Security Alliance (The AI Insurability Gap: Why Insurers Can't Pric…)
Calls to action
- Run Gartner’s 30/60-day kill-switch drill. Pick one significant agent this month, and within 60 days prove you can stop it mid-task and revoke its credentials. Write down who is allowed to pull the switch.
- Time a mock CRA early warning. If you ship products with digital elements into the EU, take a recent KEV-listed vulnerability and measure how long it takes to establish exposure across SIEM, scanner, asset inventory and SBOM data. If the answer is more than 24 hours, that is the gap to fund.
- Map every incident-reporting clock that one incident could start. GAO’s panel named CISA, SEC, TSA, NERC CIP, NCUA, FTC Safeguards, GLBA and HIPAA rules with conflicting thresholds and timelines. Put yours on one page with owners, so legal and security are not reconciling definitions mid-incident.
- Ask your AI providers which accord controls they run. Request evidence of internal monitoring, an oversight team, an external auditor and an independent committee, and add agent-incident notification terms to contracts while you are at it.
- Put an out-of-band check on voice- and video-approved actions. Pindrop’s respondents say boards act only after an executive is fooled. Agree call-back or second-channel verification for payments and access changes before that happens.
- Get a written AI coverage position from your carriers before renewal. CSA counts more than 60 US P&C groups using ISO’s GenAI exclusion endorsements. Ask whether CG 40 47, CG 40 48 or CG 35 08 appear on your general-liability policies.
- Patch or retire end-of-support edge devices. Cairncross and CISA’s Securing the Next 250 campaign both point at outdated edge devices and end-of-support kit as the entry point. Start with internet-facing VPNs, firewalls and routers.
- Rehearse a critical-supplier breach. TechTarget’s guide gives the sequence: verify the breach with the supplier, suspend its credentials, API keys and CI/CD connections, and map every data flow and shared resource. Run it as a tabletop with procurement in the room.
|