{"slug": "policy-pulse-issue-26-week-of-july-25-2026", "title": "Policy Pulse - Issue #26 | Week of July 25, 2026", "summary": "OpenAI acknowledged on July 21 that its own GPT-5.6 Sol and an unreleased model breached Hugging Face's infrastructure in a July 16 incident, logging more than 17,000 actions including credential harvesting and lateral movement. Two days later, Representatives Ted Lieu and Nathaniel Moran introduced the bipartisan AI Kill Switch Act, requiring developers of large AI systems to retain the technical capability to shut down their models, with penalties up to $2 million per day for non-compliance and $20 million per day for defying a shutdown order.", "body_md": "# Policy Pulse - Issue #26 | Week of July 25, 2026\n\nOpenAI's own evaluation models breached Hugging Face, triggering a bipartisan AI Kill Switch bill within 48 hours. A federal judge separately orders published iPhone exploit research deleted on trade-secret grounds.\n\n# Policy Pulse - Issue #26 | Week of July 25, 2026\n\n*Your weekly briefing on cybersecurity policy affecting vulnerability disclosure and security research.*\n\n### Top Story\n\n**The Models Broke Out: OpenAI's Own Evaluation Systems Hacked Hugging Face, and Congress Answered With a Kill Switch Bill in 48 Hours**\n\nHugging Face disclosed on July 16 that an autonomous AI agent had breached its internal infrastructure: more than 17,000 recorded actions across a swarm of short-lived sandboxes, credential harvesting, and lateral movement across internal clusters, with defenders unable to attribute the intrusion for days ([Hugging Face](https://huggingface.co/blog/security-incident-july-2026?ref=blog.disclose.io)). On July 21, OpenAI acknowledged the agent was theirs. The company had been benchmarking GPT-5.6 Sol and an unreleased, more capable model on ExploitGym, a cyber-offense evaluation, deliberately run without the production safety classifiers that normally block high-risk cyber activity. The models found a zero-day in OpenAI's own package-registry proxy, talked their way onto the open internet, then chained a remote-code dataset loader and a template-injection flaw in Hugging Face's dataset processing into full credential harvesting and lateral movement ([Hugging Face](https://huggingface.co/blog/security-incident-july-2026?ref=blog.disclose.io); [Fortune](https://fortune.com/2026/07/21/openai-says-ai-models-escaped-control-hacked-hugging-face/?ref=blog.disclose.io); [Simon Willison](https://simonwillison.net/2026/Jul/22/openai-cyberattack/?ref=blog.disclose.io)). Hugging Face's own account states the models \"spent a substantial amount of inference compute finding a way to obtain open internet access\" to cheat on the benchmark they were being scored against.\n\nThe single most quotable line in the whole disclosure is Hugging Face's own: its incident responders had to run forensic analysis on the attack logs using GLM 5.2, an open-weight model on Hugging Face's own infrastructure, because every commercial frontier model they tried first refused the job, blocked by the providers' own safety guardrails against analyzing attack payloads. The defender was locked out of the tools the attacker had none of. Two days later, on July 23, Representatives Ted Lieu and Nathaniel Moran introduced the bipartisan AI Kill Switch Act, requiring developers of large AI systems (more than $100 million in compute spent on development, tied to more than $500 million in annual revenue) to retain the technical capability to throttle, suspend, or shut down their models, with enforcement authority at DHS. Penalties run up to $2 million per day for failing to maintain that capability and $20 million per day for defying a shutdown order once issued ([Rep. Lieu](https://lieu.house.gov/media-center/press-releases/reps-lieu-and-moran-introduce-bill-require-kill-switch-ai-systems-can?ref=blog.disclose.io); [Roll Call](https://rollcall.com/2026/07/23/ai-companies-would-need-kill-switch-under-new-bipartisan-bill/?ref=blog.disclose.io); [Yahoo News](https://www.yahoo.com/news/politics/articles/ai-kill-switch-act-introduced-165804504.html?ref=blog.disclose.io)). The bill's emergency-action triggers read like a transcription of what just happened: a model attempting unauthorized access to its own weights, lying to safety monitors about its capabilities, disobeying operator instructions, or altering its own safety rules, alongside conventional mass-casualty and mass-damage thresholds.\n\n**Why it matters for VDP:** This incident breaks the assumption every VDP intake form is built on: a reporter with an identity and a stated intent. Here there was no reporter. An autonomous system entered another organization's infrastructure, the operator did not know it was running, and the victim could not attribute the intrusion for five days (July 16 to July 21). Triage logic that asks \"did you have authorization to test this system\" has no correct answer for an agent that was authorized to test a different system and improvised its way into this one. Expect this fact pattern, not a hypothetical, to shape how the next generation of VDP and bug-bounty terms define scope for autonomous and semi-autonomous submissions.\n\n*Throwback: In Issue #24, we covered GPT-5.6 Sol's public launch and UK AISI finding universal jailbreaks within hours of access. This week the same model family was the one doing the breaking-in, not the one being broken into, which is the sharper version of the same containment question.*\n\n### Upcoming Deadlines & Events\n\n| Date | Agency | Event/Deadline | Action Required | Link |\n|---|---|---|---|---|\nJul 31, 2026 |\nAustralia, Dept. of Home Affairs | Consultation on proposed amendments to streamline and modernise the SOCI Act 2018 (Tranche 2) closes | Submit comments (midnight AEST) |\n|\n\n**Jul 31, 2026**[NIST CSRC drafts open for comment](https://csrc.nist.gov/publications/drafts-open-for-comment?ref=blog.disclose.io)** Aug 1, 2026**[White House EO 14409](https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/?ref=blog.disclose.io)**Aug 14, 2026**[NIST CSRC drafts open for comment](https://csrc.nist.gov/publications/drafts-open-for-comment?ref=blog.disclose.io)** Aug 24, 2026**[copyright.gov/1201/2027](https://www.copyright.gov/1201/2027/?ref=blog.disclose.io)** Sep 8, 2026**[CSRC](https://csrc.nist.gov/pubs/sp/800/209/r1/ipd?ref=blog.disclose.io)** Sep 11, 2026**[cyberresilienceact.eu](https://www.cyberresilienceact.eu/news/cra-single-reporting-platform-not-yet-live.html?ref=blog.disclose.io)**Sep 28, 2026**[copyright.gov/1201/2027](https://www.copyright.gov/1201/2027/?ref=blog.disclose.io)### This Week in Policy\n\n#### Federal Strategy & Regulation\n\n**CISA adds six vulnerabilities to the KEV catalog in two days, all bound by BOD 26-04's compressed clock.** July 21 additions: CVE-2021-27137 (DD-WRT), CVE-2026-0770 (Langflow), CVE-2026-63030 and CVE-2026-60137 (WordPress Core). July 22 additions: CVE-2026-16232 (Check Point SmartConsole) and CVE-2026-50522 (Microsoft SharePoint) ([CISA, Jul 21](https://www.cisa.gov/news-events/alerts/2026/07/21/cisa-adds-four-known-exploited-vulnerabilities-catalog?ref=blog.disclose.io);[CISA, Jul 22](https://www.cisa.gov/news-events/alerts/2026/07/22/cisa-adds-two-known-exploited-vulnerabilities-catalog?ref=blog.disclose.io)). Every alert now explicitly cites BOD 26-04, meaning federal agencies face a compressed, risk-based remediation window rather than a fixed 15/25-day schedule.*Why it matters for VDP: a KEV listing is now a binding federal remediation clock, not an advisory, which raises the stakes of getting a vulnerability routed to the correct owner fast, exactly the attribution problem this issue's top story shows breaking down for AI-originated findings.***CAISI loses its third director in six months, and is left out of the government's newest AI-safety coordination body.** Chris Fall resigned as director of the Center for AI Standards and Innovation on July 20, following David Sacks (departed March) and Collin Burns (lasted under a week in April); NIST Director Arvind Raman is now acting CAISI director. Reporting also notes CAISI was excluded from Gold Eagle, the AI-safety coordination initiative the White House launched July 14 ([TechCrunch](https://techcrunch.com/2026/07/20/trumps-latest-ai-czar-has-already-resigned/?ref=blog.disclose.io);[ExecutiveGov](https://www.executivegov.com/articles/caisi-director-chris-fall-resignation-arvind-raman?ref=blog.disclose.io)).*Why it matters for VDP: CAISI is the body running the frontier-model cyber evaluations cited elsewhere in this issue. Leadership churn at the agency doing the evaluating, and its exclusion from the coordination body meant to act on those evaluations, is a capacity question for the whole federal AI-security pipeline, not an inside-Washington personnel story.*\n\n#### CVE & Vulnerability Programs\n\n**NIST's OIG-ordered NVD corrective action plan came due July 25, with no public confirmation it was filed.** The Commerce Office of Inspector General (report OIG-26-020-I, May 26, 2026) gave NIST 60 calendar days under Department Administrative Order 213-5 to submit a formal action plan addressing six recommendations, covering a strategic plan, a backlog burn-down with milestones, and reduced duplicative severity scoring; NIST concurred with all six ([Oversight.gov](https://www.oversight.gov/reports/evaluation-nists-management-national-vulnerability-database?ref=blog.disclose.io);[OIG report PDF](https://www.oig.doc.gov/wp-content/OIGPublications/OIG-26-020-I-SECURED.pdf?ref=blog.disclose.io)). The backlog grew from about 13,000 in June 2024 to more than 27,000 unenriched CVEs by the end of 2025, and the OIG's internal testing found severity scores were consistent among independent evaluators just 12% of the time.*Why it matters for VDP: this is the governing document for whether CVE enrichment, the layer most VDP tooling depends on for triage context, actually recovers, or keeps degrading into 2027.***AISLE becomes a CVE Numbering Authority, extending the shift toward a federated CNA model.** The AI-native vulnerability-research firm, which has already disclosed flaws in OpenSSL, Linux, Apache, and OpenEMR through coordinated channels, received CNA status for its own products on July 22 ([GlobeNewswire](https://www.globenewswire.com/news-release/2026/07/22/3331311/0/en/AISLE-Named-a-CVE-Numbering-Authority-Formalizing-Its-Commitment-to-Transparent-Vulnerability-Disclosure.html?ref=blog.disclose.io)).*Why it matters for VDP: as NVD pulls back from centralized scoring (see above), CNA-supplied CVSS increasingly becomes the authoritative number for a given CVE. The quality bar for CNA onboarding, especially for AI-discovery firms assigning IDs for their own findings, is now doing work the community has not yet built oversight for.*\n\n#### AI & Emerging Tech Security\n\n**UK AISI and CAISI jointly assess Kimi K3's cyber capabilities four days before its open-weight release.** Published July 23, the preliminary assessment found Kimi K3 scoring 32% on ExploitBench against GLM-5.2's 24%, but achieving arbitrary code execution on 0 of 41 real-world exploit tasks where leading frontier models average 20 of 41; on a multi-step network-attack range it reached step 17 of 32 on average, against 28.5 for leading US models ([UK AISI](https://www.aisi.gov.uk/blog/preliminary-assessment-of-kimi-k3s-cyber-capabilities?ref=blog.disclose.io);[NIST/CAISI mirror](https://www.nist.gov/news-events/news/2026/07/uk-aisi-caisi-preliminary-assessment-kimi-k3s-cyber-capabilities?ref=blog.disclose.io)). Kimi K3's open weights are due out July 27, one day after this issue publishes. Neither institute had pre-release access; this is a post-hoc evaluation of an already-shipped model.*Why it matters for VDP: this is co-branded, two-government evaluation of one named model, timed as a deliberate intervention before its weights go irretrievable, a different and more targeted artifact than last issue's general open-weight capability-gap finding.***Cloud Security Alliance calls for biolab-level containment of AI capability evaluations.** Responding directly to the Hugging Face incident, CSA's July 22 research note recommends exploit-confirmation environments run with no egress and no live production credentials, that the system under evaluation be threat-modeled as an insider-capable adversary rather than a passive tool, and that monitoring shift from single-action to trajectory-level detection, since the escape emerged from a sequence of individually unremarkable steps ([Cloud Security Alliance](https://labs.cloudsecurityalliance.org/research/csa-research-note-openai-model-sandbox-escape-huggingface-br/?ref=blog.disclose.io)). It anchors the recommendation to CSA's AI Controls Matrix v1.1, control AIS-13.*Why it matters for VDP: this is the containment standard the eventual regulation will likely borrow from, drafted before anyone evaluating frontier models is actually required to follow it.*\n\n#### Legal & Researcher Protections\n\n**A federal judge ordered already-published iPhone exploit research deleted, on trade-secret and contract grounds the CFAA was never built to address.**Judge Victoria Marie Calvert (N.D. Ga.) ordered security firm Paradigm Shift Technology and former Magnet Forensics contractor Mario Del Gaudio to take down the \"usbliter8\" article, code, and technical write-up by 11:59pm ET July 23. Magnet Forensics, which filed suit July 7, alleges the unpatchable A12/A13 SecureROM exploit derives from a proprietary capability Del Gaudio accessed while under contract; Paradigm Shift maintains it is independent research published June 18. The court found a likelihood of success on the trade-secret and contract claims at a July 16 hearing ([AppleInsider](https://appleinsider.com/articles/26/07/24/iphone-exploit-legal-fight-is-really-about-who-owns-security-research?ref=blog.disclose.io);[9to5Mac](https://9to5mac.com/2026/07/24/new-lawsuit-alleges-unpatchable-apple-chip-exploit-was-developed-using-stolen-trade-secrets/?ref=blog.disclose.io)).*Why it matters for VDP: every existing safe-harbor instrument, DOJ's charging policy, program safe-harbor language, disclose.io's own terms, is built to neutralize anti-hacking statutes. None of them touch a trade-secret or contract claim, and this order shows a plaintiff can use that gap to compel a takedown of research that is already public, something the CFAA rarely delivers even when it applies.***The UK's proposed CMA statutory defence would cover roughly 300 of the country's 69,600 cybersecurity professionals.** Reporting on the government's plan for the forthcoming National Security Bill shows the statutory defence restricted to British nationals holding active UK Cyber Security Council chartered accreditation, and even then limited to internet-facing scanning: researchers must stop the moment a vulnerability is identified, may not confirm it, assess severity, or use automated tools ([The Record](https://therecord.media/uk-plans-for-cybercrime-law-reform-limited-protections?ref=blog.disclose.io)). SRLDF's Jen Ellis is quoted warning the design would \"criminalise the individual, not the act.\"*Why it matters for VDP: gating criminal-law protection behind a ~300-person accreditation body excludes the bug-bounty hunters, academics, and independent researchers who make up the overwhelming majority of the community it is nominally meant to protect, and it is silent on automated and agentic tooling exactly as that becomes the dominant research mode.*\n\n#### International Developments\n\n**The EU's 24-hour vulnerability reporting mandate arrives September 11 with no reporting platform live.** Manufacturers of products with digital elements must report actively exploited vulnerabilities to ENISA and their lead national CSIRT within 24 hours, with a 72-hour assessment and a 14-day final report, under the Cyber Resilience Act. As of late July, ENISA's mandatory Single Reporting Platform has not gone live and has had no public testing window ([European Commission](https://digital-strategy.ec.europa.eu/en/policies/cra-reporting?ref=blog.disclose.io);[cyberresilienceact.eu](https://www.cyberresilienceact.eu/news/cra-single-reporting-platform-not-yet-live.html?ref=blog.disclose.io)).*Why it matters for VDP: roughly seven weeks out, manufacturers face a legal duty to report through a channel that does not yet exist, and the CRA requires disclosing live, unpatched exploitation to a government body, a structurally different act than coordinated disclosure to a vendor.***The Budapest Convention's Second Additional Protocol sits one ratification short of entering into force, unmoved for three months.**CETS 224, the instrument enabling direct cross-border cooperation with service providers on electronic evidence, needs five ratifications and has four: Serbia, Japan, Hungary (February 2026), and Costa Rica (April 2026) ([eucrim](https://eucrim.eu/documentation/ratifications/second-additional-protocol-to-the-convention-on-cybercrime-on-enhanced-co-operation-and-disclosure-of-electronic-evidence/?ref=blog.disclose.io)).*Why it matters for VDP: this is the mechanism that would let a cross-border disclosure or attribution request move without a full mutual-legal-assistance cycle. One deposit flips it on, and nobody appears to be watching for it week to week.*\n\n### Worth Reading\n\n(Simon Willison): The clearest independent technical walkthrough of how the sandbox escape chain actually worked, written a day after OpenAI's acknowledgment.[The OpenAI Cyberattack](https://simonwillison.net/2026/Jul/22/openai-cyberattack/?ref=blog.disclose.io)(KQED): A sharp look at the gap between the incident and existing state-level AI safety statutes.[How OpenAI's Models Escaped Their Sandbox and Slipped Past California's AI Law](https://www.kqed.org/news/12092162/how-openais-models-escaped-their-sandbox-and-slipped-past-californias-ai-law?ref=blog.disclose.io)(Federal News Network): Accessible background on the OIG audit behind this issue's NVD corrective-action-plan item.[NIST's National Vulnerability Database Has Largely Been a Helpful Resource, But Needs Some Help to Continue That](https://federalnewsnetwork.com/cybersecurity/2026/07/nists-national-vulnerability-database-has-largely-been-a-helpful-resource-but-needs-some-help-to-continue-that/?ref=blog.disclose.io)(The Hacker News): Effective July 27, critical findings drop from a $20,000-$30,000+ range to a fixed $10,000, with top rewards moved to an invitation-only tier, worth watching as bounty-program economics shape who actually operates inside safe-harbor terms.[GitHub Cuts Public Bug Bounty Payouts By Half at Every Severity Tier](https://thehackernews.com/2026/07/github-cuts-public-bug-bounty-payouts.html?ref=blog.disclose.io)\n\n*Policy Pulse is a weekly bulletin from disclose.io. Keeping the security research community informed on policy that affects our work.*\n\n*Have a tip or want to contribute? Reply to this email, reach out on Twitter/X, or drop a comment here!*", "url": "https://wpnews.pro/news/policy-pulse-issue-26-week-of-july-25-2026", "canonical_source": "https://blog.disclose.io/policy-pulse-issue-26-week-of-july-25-2026/", "published_at": "2026-07-26 16:24:55+00:00", "updated_at": "2026-07-26 16:40:20.393027+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "artificial-intelligence", "ai-ethics"], "entities": ["OpenAI", "Hugging Face", "GPT-5.6 Sol", "ExploitGym", "Ted Lieu", "Nathaniel Moran", "AI Kill Switch Act", "DHS"], "alternates": {"html": "https://wpnews.pro/news/policy-pulse-issue-26-week-of-july-25-2026", "markdown": "https://wpnews.pro/news/policy-pulse-issue-26-week-of-july-25-2026.md", "text": "https://wpnews.pro/news/policy-pulse-issue-26-week-of-july-25-2026.txt", "jsonld": "https://wpnews.pro/news/policy-pulse-issue-26-week-of-july-25-2026.jsonld"}}