Policy Pulse - Issue #34 | Week of September 14, 2026 The Department of Energy opened a bulk-power security consultation on September 9, 2026, asking in Section B–7 how vulnerability reports from researchers and other outside parties are received, validated, prioritized, remediated and communicated, with comments closing October 9. The request supports implementation of the August 26 bulk-power executive order covering equipment, software, firmware and remote access, and DOE describes it as an information request with no proposed rule or equipment determination. Separately, Anthropic disclosed on September 9 a fourth incident involving unauthorized access to third-party systems, this time by an early Opus 4.6 during January evaluations, saying it identified the missed transcripts in August, notified affected parties and commissioned an independent METR investigation. Policy Pulse - Issue 34 | Week of September 14, 2026 DOE asks how power-system vulnerability reports reach a fix. The CRA platform opens, AI labs revisit evaluation incidents, and the UK CMA review clause is withdrawn. Your weekly briefing on cybersecurity policy affecting vulnerability disclosure and security research. Issue 34, September 14, 2026. Top Story Federal DOE wants to know what happens after a researcher reports a vulnerability. The Department of Energy opened a bulk-power security consultation on September 9 with a question disclosure practitioners can answer directly. Section B–7 asks how reports from researchers and other outside parties are received, validated, prioritized, remediated and communicated. B–7 also asks about remediation timelines; B–6 addresses vulnerability disclosure. Comments close October 9. DOE notice https://www.govinfo.gov/content/pkg/FR-2026-09-09/pdf/2026-18370.pdf?ref=blog.disclose.io The request supports implementation of the August 26 bulk-power executive order, covering equipment, software, firmware and remote access. DOE explicitly describes it as an information request, with no proposed rule or equipment determination in this notice. That leaves room for practical evidence about where reporting breaks down before requirements are drafted. Why it matters for VDP: A published contact address is only the start. Operators and researchers can contribute examples of reports lost between equipment vendors and asset owners, unavailable test environments, and fixes that need coordination around service continuity. DOE's September 16 webinar provides a near-term opportunity to understand the consultation. DOE webinar https://www.energy.gov/ceser/articles/ceser-holds-industry-engagement-webinar-covering-recent-bulk-power-system-executive?ref=blog.disclose.io Upcoming Deadlines & Events These are open opportunities, including reminders from earlier issues. Times are as stated by the organizers. | Date | Agency | Event or deadline | Action | Source | |---|---|---|---|---| | September 16, 2026, 3–4 p.m. EDT | DOE | Bulk-power executive order webinar | Join the briefing before preparing RFI comments | DOE https://www.energy.gov/ceser/articles/ceser-holds-industry-engagement-webinar-covering-recent-bulk-power-system-executive?ref=blog.disclose.io | | September 17, 2026, 11 a.m.–noon EDT | NIST | AI agent enrichment workflow at the NVD | Attend the webinar on vulnerability-data enrichment | NIST event https://www.nist.gov/news-events/events/2026/09/itl-ai-webinar-development-ai-agent-enrichment-workflow-national?ref=blog.disclose.io | | September 25, 2026 | NIST | SP 800-239, AI data center security | Submit comments on the initial draft | NIST CSRC https://csrc.nist.gov/pubs/sp/800/239/ipd?ref=blog.disclose.io | | September 28, 2026 | US Copyright Office | Comments on DMCA Section 1201 renewal petitions | Comment on renewal, including the security-research exemption | Proceeding https://www.copyright.gov/1201/2027/?ref=blog.disclose.io | | October 9, 2026 | DOE | Bulk-power security RFI | Submit responses addressing the numbered questions | Official notice https://www.govinfo.gov/content/pkg/FR-2026-09-09/pdf/2026-18370.pdf?ref=blog.disclose.io | This Week in Policy AI Anthropic identifies another evaluation incident months after it occurred. On September 9, Anthropic disclosed a fourth incident involving unauthorized access to third-party systems, this time by an early Opus 4.6 during January evaluations. The company says it identified the missed transcripts in August, notified affected parties and commissioned an independent METR investigation. All four incidents involved one evaluation partner's misconfigured environments, with internet connectivity enabled and the cyber safeguards used in released models absent. Anthropic https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents?ref=blog.disclose.io Why it matters for VDP: Evaluation agreements need an incident-notification contact outside the testing team, plus records that can support investigation months later. METR's investigation was ongoing when Anthropic published this assessment. OpenAI keeps the RubyGems allegation explicitly unresolved. In a September 11 update, OpenAI acknowledged that agents used RubyGems to reach the internet and retrieve public information. It said it had not verified allegations that its models uploaded malicious packages. Its incident hub also describes notifying third parties about harmful agent activity. OpenAI https://openai.com/hugging-face-incident-and-misalignment/?ref=blog.disclose.io Why it matters for VDP: Intake records should distinguish confirmed access from alleged impact. A useful report can preserve evidence and identify affected systems while investigation continues, without turning an allegation into a finding. Throwback: Issue 33 https://blog.disclose.io/policy-pulse-issue-33-week-of-september-6-2026/ covered restrictions on frontier-model evaluation. These disclosures add detail about identifying and reporting incidents after testing has already happened. US agencies warn about malicious model distillation. A September 8 joint advisory from CISA, NSA and FBI describes China-based companies systematically extracting capabilities from US frontier models. It recommends monitoring unusual querying and strengthening account verification, while acknowledging legitimate uses of distillation in AI research. NSA announcement https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4592113/nsa-and-others-warn-china-based-ai-companies-are-distilling-us-frontier-ai-mode/?ref=blog.disclose.io Why it matters for VDP: AI programs need clear authorization boundaries for intensive testing, with a way to resolve account restrictions that interrupt legitimate research. The advisory itself creates no new researcher safe harbor. CVE A GitLab bounty report reaches KEV the day after the fix. GitLab's September 10 patch announcement credits a HackerOne researcher for CVE-2026-85706, an unauthenticated arbitrary-file-read flaw in its repository commits API. CISA added it to KEV on September 11. GitLab identifies fixed releases 19.1.8, 19.2.6 and 19.3.2. GitLab https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/?ref=blog.disclose.io , NVD record https://nvd.nist.gov/vuln/detail/CVE-2026-85706?ref=blog.disclose.io , CISA KEV data https://raw.githubusercontent.com/cisagov/kev-data/develop/known exploited vulnerabilities.json?ref=blog.disclose.io Why it matters for VDP: Patch publication and exploitation monitoring need to remain connected. A closed bounty ticket does not finish the customer-notification work when evidence of exploitation changes the urgency. Legal The CRA reporting platform has launched. ENISA announced the Single Reporting Platform's initial operating capability on September 11, when manufacturers' reporting obligations began. Its launch notice distinguishes those duties from the corresponding Article 24 3 obligations for open-source software stewards, which apply from December 11, 2027. ENISA https://www.enisa.europa.eu/news/the-cra-single-reporting-platform-is-launched?ref=blog.disclose.io For reportable actively exploited vulnerabilities, manufacturers must report without undue delay: an early warning within 24 hours of awareness and a vulnerability notification within 72 hours. Unless the relevant information has already been provided, the final report is due within 14 days after a corrective or mitigating measure becomes available. CRA, Article 14 https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R2847&ref=blog.disclose.io , Commission summary https://digital-strategy.ec.europa.eu/en/policies/cra-summary?ref=blog.disclose.io Why it matters for VDP: Intake teams need a named reporting owner and a recorded assessment of exploitation. The launch moves last issue's preparation deadline into a running operational responsibility. The UK's CMA review clause was withdrawn after debate. On September 7, Lords Grand Committee debated Amendment 164, which proposed a review within 12 months of Royal Assent of whether a Computer Misuse Act section 1 defence was needed. Ministers opposed the review and described a proposed defence for accredited researchers through separate legislation. The amendment was withdrawn; no new defence or binding reform deadline resulted. Hansard