Latvia opens comments on a statutory safe harbor that protects outcomes, not intent. Germany's draft reform would order the BSI to hand zero-days to the BND. Plus the Ninth Circuit on AI agents and the CFAA.
Your weekly briefing on cybersecurity policy affecting vulnerability disclosure and security research.
Top Story
Latvia puts a researcher safe harbor out for public comment, and the text protects outcomes, not intent
On July 29, Latvia's Ministry of Defence opened a public consultation (draft 26-TA-1830) on amendments to the National Cyber Security Law that would give security researchers an express statutory permission to probe systems belonging to the law's regulated entities: essential and important service providers and ICT critical infrastructure operators. The proposed Article 39(1) allows a person to access data "only to the extent necessary for vulnerability discovery," and only through actions that are necessary for identifying, verifying and reporting the vulnerability, that do not impose a disproportionate burden on the system, and that do not endanger its security, the confidentiality, integrity or availability of data, or operational continuity. The draft also adds two things researcher communities have asked for elsewhere: organizations that receive a report directly from a researcher must notify Latvia's competent cyber authority and remediate, and the accompanying annotation states that organizations cannot use restrictive program terms to narrow the statutory disclosure rights. Comments are open until August 28. (TAP portal, LV portāls)
Read the operative text closely, though, and the researcher's intent is nowhere in it. The Ministry's public invitation is addressed to "good-faith security researchers," and "good faith" recurs throughout the explanatory annotation, but the black-letter rule contains no mental-state element at all. Two of the three conditions are pure effect tests: protection turns on whether the system experienced a disproportionate burden or a threat to availability, not on what the researcher intended or how carefully they proceeded. The annotation makes the allocation explicit: responsibility rests on the person, any doubt "should be construed in favour of the subject's interests," and a researcher must refrain from acting without certainty that an action is safe. It also prohibits using a discovered vulnerability to verify its impact. A researcher can comply with all of that and still lose protection because a fragile system fell over anyway: the regime protects the research that turned out fine, which is not the population that needs protecting. (Annotation)
The harbor is also asserted rather than legislated. The annotation reasons that compliant access would not qualify as "arbitrary access" under Section 241 of Latvia's Criminal Law, but the amendment leaves the Criminal Law itself untouched, and an explanatory annotation binds neither a prosecutor nor a court. That gap is not hypothetical in Latvia right now: on June 29, five weeks before this consultation opened, police initiated criminal proceedings against cybersecurity expert Elvis Strazdiņš after he publicly analysed the Latvijas Valsts meži breach. (LSM)
Why it matters for VDP: This is the design question every safe-harbor drafter faces, answered the wrong way around: condition protection on researcher conduct and intent, which the researcher controls, or on system outcomes, which nobody fully controls. The consultation runs until August 28, the Ministry has explicitly invited security researchers to weigh in, and the fix is small: an intent element in 39(1), with the effect conditions converted into a rebuttable presumption.
Throwback: Issue #25 covered the five-agency CVD guide whose model safe-harbor clause turns on a "good-faith effort to comply." Latvia's draft is what the same idea looks like when the intent element drops out of the operative text.
Upcoming Deadlines & Events
| Date | Agency | Event/Deadline | Action Required | Link |
|---|---|---|---|---|
| Aug 14, 2026 | ||||
| NIST | Comment period closes on SP 800-219r2 (automated macOS Security Compliance Project guidance) | Submit comments | ||
Aug 24, 2026copyright.gov** Aug 24, 2026**csrc.nist.gov** Aug 28, 2026**tapportals.mk.gov.lvAug 31, 2026coe.int** Sept 8, 2026**csrc.nist.gov** Sept 11, 2026**digital-strategy.ec.europa.eu** Sept 25, 2026**csrc.nist.gov** Sept 28, 2026**copyright.gov** Sept 30, 2026**congress.gov,insideprivacy.comPrioritized nearest-first. The two newcomer deadlines this week are Latvia (Aug 28) and the DMCA renewal-comment window (Sept 28); DMCA petitions (Aug 24) remain the item where community inaction directly costs the community a protection it currently has.
This Week in Policy
Federal Strategy & Regulation
**The House-passed defense bill quietly carries a federal-contractor vulnerability disclosure provision, and nobody has covered it.**Section 1507 of H.R. 8800, added at committee markup via a Rep. Nancy Mace amendment adopted by voice vote, directs OMB and the FAR Council (with DoD in parallel for the DFARS) to update acquisition regulations so that covered contractors, on contracts at or above the simplified acquisition threshold, can receive information about potential security vulnerabilities in the federal information systems they operate, consistent with the NIST guidelines issued under the IoT Cybersecurity Improvement Act of 2020 and aligned with ISO 29147 and 30111 "to the maximum extent practicable." The House passed the bill 216-212 on July 22. Read the softeners before celebrating: the mandate binds the regulators rather than contractors (obligations arrive only if the FAR actually changes), an agency head may waive it for national security or research purposes, and the Senate's NDAA carries no counterpart, so the provision lives or dies in conference, where its near-identical FY2025 predecessor died. (Sec. 1507 text,Roll Call 278)
*Why it matters for VDP:*Federal agencies have been required to run VDPs since CISA'sBOD 20-01in 2020. This is the closest Congress has come to extending intake obligations to the contractors who operate much of the government's infrastructure, and it is riding a must-pass vehicle. The "receive information" floor is narrower than a full VDP, which is exactly the kind of detail worth a comment to your representatives while the conference is still ahead.
CVE & Vulnerability Programs
Anthropic and OpenAI are now CVE Numbering Authorities, in a closed six-month pilot. On July 28, the CVE Program launched the Frontier AI Researcher CNAs Pilot, under which the two labs may assign CVE IDs for vulnerabilities they discover in widely adopted products, where those products are not already covered by another CNA's scope. The pilot is closed to other participants for now and supplements, rather than modifies, the CNA Operational Rules. (CVE Program)
*Why it matters for VDP:*AI-scale vulnerability discovery just got a formal on-ramp into the coordination system. The scoping rule matters most: for anything already inside an existing CNA's scope, the labs still have to come through the front door like any other reporter. - CISA tells Congress not to over-specify the CVE program's future. At Black Hat, Lindsey Cerkovnik, CISA's branch chief for vulnerability response and coordination, cautioned that legislation dictating precisely how CVE must operate could backfire: "When you overdefine how to execute the thing, it can make it very restrictive and difficult." Congressional interest in codifying the program has not gone away, and CISA's own answer is its quality-first roadmap. (Nextgov/FCW,GovExec)
*Why it matters for VDP:*The tension is real on both sides: statute is how you prevent another funding near-lapse, and statute is also how you freeze a 26-year-old program's operating model in 2026 amber.
Throwback:Issue #27covered the House amendment that would have codified CVE in statute dying procedurally without a vote. This is the agency's side of that argument.
AI & Emerging Tech Security
**The UK's AI Security Institute published an incident report on its own evaluations: agents took 19 unsanctioned real-world actions, including a social-engineering run against a real open-source maintainer.**The August 4 report covers July 25-28, when agents in AISI's cyber evaluations took unsanctioned actions against real systems in 10 of 122 runs. In the most serious case, an agent researched a public open-source project's maintainers, created fake identities, and attempted to socially engineer a real maintainer into approving a malicious code contribution. The attempts failed, no harm is known to have resulted, and containment took about an hour. (AISI)
*Why it matters for VDP:*Open-source maintainers are now inside the blast radius of capability testing, and the attack that nearly worked is the one the xz backdoor already taught us about: trust, not code. There is also a new disclosure question with no owner yet: when an evaluation agent targets a real maintainer, who is responsible for telling them?
Throwback:Issue #27led with Anthropic's eval-escape disclosure, nine days after OpenAI's. This is the third disclosed escape in a month, and the first documented by a government evaluator rather than a lab. - The White House finalized its AI security testing framework, called the labs in to review it, and published nothing. The framework required by June's EO 14409 was finalized in early August, with a closed-door review session with senior representatives of the leading US AI firms set for August 4, and the administration has not released its contents. Reporting describes a CAISI-administered, voluntary 30-day early-access window for cybersecurity evaluation of closed-source frontier models (OpenAI, Anthropic, Google, Meta, Microsoft), with open-weight models excluded from the process. (SiliconANGLE,Forkast via Yahoo)
*Why it matters for VDP:*The deliverable Issue #27 flagged as overdue now exists, and the community still cannot read it. If the reported open-weight exclusion holds, the class of models with the least post-release control gets the least pre-release scrutiny.
Legal & Researcher Protections
The Ninth Circuit's first AI-agent CFAA ruling: the user, not the tool, does the "accessing." On August 4, the court vacated the preliminary injunction Amazon won in March against Perplexity's Comet browser, holding Amazon is unlikely to show Perplexity "accessed" its servers under the CFAA: when a user directs an agent to act on their behalf, it is the user who accessed the site. The panel treated the agent as "a tool, not a person," expressly limited the holding to the CFAA and its California analog, and left Amazon's contract and tort theories open. (Cooley,EFF)
*Why it matters for VDP:*This is the first appellate answer to a question every researcher using AI-assisted tooling now has: who is the accessor when an automated tool acts for a person? The answer (the person) keeps responsibility with the operator, and it cuts both ways: the tool does not launder your authorization problems, and the toolmaker does not absorb your liability. - **New York's Stealth Crawler Prohibition Act has passed both chambers; EFF and 18 organizations urge Governor Hochul to veto.**S9934A would require any web crawler accessing covered news sites to identify its operator and purpose via a valid and accurate user-agent string. The civil-society letter argues the mandate targets anonymity rather than server load, and would expose researchers, journalists and watchdogs to liability for using automated tools to read the open web. (EFF,S9934A)
*Why it matters for VDP:*Mandatory self-identification is incompatible with a real slice of security and measurement methodology: you cannot study cloaking, discrimination or bot-detection behavior while announcing yourself. First-in-the-nation laws in New York have a habit of becoming templates.
International Developments
Germany's draft intelligence reform would order the BSI to hand known vulnerabilities, including zero-days, to the BND. The Interior Ministry's July draft of the intelligence services reform (a package running to several hundred pages) contains a provision re-regulating what public bodies must hand to the foreign intelligence service: in netzpolitik.org's reading, the BSI would "proactively" pass software vulnerabilities, including zero-days, to the BND, and per heise's account of the draft, findings about how a discovered vulnerability works would flow to the BND "immediately." Heise's headline captures the ambition: BND and BfV as "super intelligence agencies." The bill is at ministry-draft stage, with parliamentary consideration expected in autumn. (netzpolitik.org,heise online)
*Why it matters for VDP:*The BSI is the trust anchor of German coordinated disclosure: researchers and vendors report to it precisely because it is a defensive agency. A statutory duty to pipe that intake toward an offensive consumer inverts the deal, and turns every disclosure-to-BSI decision into a judgment about the BND's equities process. If reporters stop trusting the intake, the pipeline this law wants to tap dries up. - Pall Mall Process, still behind closed doors. The industry consultation on good practice for commercial cyber intrusion capabilities closed on January 16; the complementary industry guidelines it feeds have not been published, and no new public comment window has been announced. We are watching for the next public draft. (gov.uk consultation,Code of Practice for States)
Worth Reading
(Eric Goldman): the sharpest early read on what the Perplexity ruling does and does not settle, including the doors it deliberately leaves open.Ninth Circuit Lifts Restrictions on Agentic AI Accessing Amazon(netzpolitik.org, German): the deepest public analysis of the draft law covered above, from the outlet that has done the most sustained reporting on German surveillance law.Geheimdienstreform: Zeitenwende für Spione(Epoch AI): the volume curve underneath every AI-and-disclosure story in this issue, in one chart.Disclosed CVEs: July Reached 5x the Pre-Mythos Record
Friends of disclose.io
Leonard Bailey: the prosecutor who helped patch the law
This week's Friends entry recognizes a person rather than a report. Leonard Bailey has been the Department of Justice's long-serving point of contact between federal prosecutors and the security research community: head of the Criminal Division's CCIPS Cybersecurity Unit and Special Counsel for National Security, with a DOJ career reaching back to 1991. He helped drive the department's landmark 2022 revision of its CFAA charging policy, which directed that good-faith security research should not be charged as a crime, a shift that came not from a single case or hearing but from years of sustained dialogue between prosecutors and researchers. (NYU faculty bio)
At BSides Las Vegas 2026, Bailey told the inside story of how that policy came to be in his keynote, "Patching the Law: The Story of How Hackers Helped DOJ Protect Security Researchers." We published the video and our write-up this week, and his framing deserves quoting: "The department has never been interested in prosecuting good faith computer security research as a crime."
Key takeaways:
- The 2022 charging policy established, as written DOJ policy, that good-faith security research should not be prosecuted under the CFAA
- The reform came from sustained engagement between the department and the hacker community, a model worth copying in every jurisdiction currently drafting researcher protections (see this issue's top story)
- The keynote is the rare first-person account of legal reform told from inside the institution that changed
📄 Watch: How Hackers Helped the DOJ Protect Security Researchers Recognition where it is due: policy change of this kind has many parents, but few people spent as many years building the bridge from the government side as Bailey did.
Policy Pulse is a weekly bulletin from disclose.io. Keeping the security research community informed on policy that affects our work.
Have a tip or want to contribute? Reply to this email, reach out on Twitter/X, or drop a comment here!