Policy Pulse - Issue #34 | Week of September 14, 2026
DOE asks how power-system vulnerability reports reach a fix. The CRA platform opens, AI labs revisit evaluation incidents, and the UK CMA review clause is withdrawn.
Your weekly briefing on cybersecurity policy affecting vulnerability disclosure and security research. Issue #34, September 14, 2026.
Top Story
Federal
DOE wants to know what happens after a researcher reports a vulnerability.
The Department of Energy opened a bulk-power security consultation on September 9 with a question disclosure practitioners can answer directly. Section B–7 asks how reports from researchers and other outside parties are received, validated, prioritized, remediated and communicated. B–7 also asks about remediation timelines; B–6 addresses vulnerability disclosure. Comments close October 9. (DOE notice)
The request supports implementation of the August 26 bulk-power executive order, covering equipment, software, firmware and remote access. DOE explicitly describes it as an information request, with no proposed rule or equipment determination in this notice. That leaves room for practical evidence about where reporting breaks down before requirements are drafted.
Why it matters for VDP: A published contact address is only the start. Operators and researchers can contribute examples of reports lost between equipment vendors and asset owners, unavailable test environments, and fixes that need coordination around service continuity. DOE's September 16 webinar provides a near-term opportunity to understand the consultation. (DOE webinar)
Upcoming Deadlines & Events
These are open opportunities, including reminders from earlier issues. Times are as stated by the organizers.
| Date | Agency | Event or deadline | Action | Source |
|---|---|---|---|---|
| September 16, 2026, 3–4 p.m. EDT | DOE | Bulk-power executive order webinar | Join the briefing before preparing RFI comments | DOE |
| September 17, 2026, 11 a.m.–noon EDT | NIST | AI agent enrichment workflow at the NVD | Attend the webinar on vulnerability-data enrichment | NIST event |
| September 25, 2026 | NIST | SP 800-239, AI data center security | Submit comments on the initial draft | NIST CSRC |
| September 28, 2026 | US Copyright Office | Comments on DMCA Section 1201 renewal petitions | Comment on renewal, including the security-research exemption | Proceeding |
| October 9, 2026 | DOE | Bulk-power security RFI | Submit responses addressing the numbered questions | Official notice |
This Week in Policy
AI
Anthropic identifies another evaluation incident months after it occurred. On September 9, Anthropic disclosed a fourth incident involving unauthorized access to third-party systems, this time by an early Opus 4.6 during January evaluations. The company says it identified the missed transcripts in August, notified affected parties and commissioned an independent METR investigation. All four incidents involved one evaluation partner's misconfigured environments, with internet connectivity enabled and the cyber safeguards used in released models absent. (Anthropic)
Why it matters for VDP: Evaluation agreements need an incident-notification contact outside the testing team, plus records that can support investigation months later. METR's investigation was ongoing when Anthropic published this assessment.
OpenAI keeps the RubyGems allegation explicitly unresolved. In a September 11 update, OpenAI acknowledged that agents used RubyGems to reach the internet and retrieve public information. It said it had not verified allegations that its models uploaded malicious packages. Its incident hub also describes notifying third parties about harmful agent activity. (OpenAI)
Why it matters for VDP: Intake records should distinguish confirmed access from alleged impact. A useful report can preserve evidence and identify affected systems while investigation continues, without turning an allegation into a finding.
Throwback: Issue #33 covered restrictions on frontier-model evaluation. These disclosures add detail about identifying and reporting incidents after testing has already happened.
US agencies warn about malicious model distillation. A September 8 joint advisory from CISA, NSA and FBI describes China-based companies systematically extracting capabilities from US frontier models. It recommends monitoring unusual querying and strengthening account verification, while acknowledging legitimate uses of distillation in AI research. (NSA announcement)
Why it matters for VDP: AI programs need clear authorization boundaries for intensive testing, with a way to resolve account restrictions that interrupt legitimate research. The advisory itself creates no new researcher safe harbor.
CVE
A GitLab bounty report reaches KEV the day after the fix. GitLab's September 10 patch announcement credits a HackerOne researcher for CVE-2026-85706, an unauthenticated arbitrary-file-read flaw in its repository commits API. CISA added it to KEV on September 11. GitLab identifies fixed releases 19.1.8, 19.2.6 and 19.3.2. (GitLab, NVD record, CISA KEV data)
Why it matters for VDP: Patch publication and exploitation monitoring need to remain connected. A closed bounty ticket does not finish the customer-notification work when evidence of exploitation changes the urgency.
Legal
The CRA reporting platform has launched. ENISA announced the Single Reporting Platform's initial operating capability on September 11, when manufacturers' reporting obligations began. Its launch notice distinguishes those duties from the corresponding Article 24(3) obligations for open-source software stewards, which apply from December 11, 2027. (ENISA)
For reportable actively exploited vulnerabilities, manufacturers must report without undue delay: an early warning within 24 hours of awareness and a vulnerability notification within 72 hours. Unless the relevant information has already been provided, the final report is due within 14 days after a corrective or mitigating measure becomes available. (CRA, Article 14, Commission summary)
Why it matters for VDP: Intake teams need a named reporting owner and a recorded assessment of exploitation. The launch moves last issue's preparation deadline into a running operational responsibility.
The UK's CMA review clause was withdrawn after debate. On September 7, Lords Grand Committee debated Amendment 164, which proposed a review within 12 months of Royal Assent of whether a Computer Misuse Act section 1 defence was needed. Ministers opposed the review and described a proposed defence for accredited researchers through separate legislation. The amendment was withdrawn; no new defence or binding reform deadline resulted. (Hansard)
Why it matters for VDP: Accreditation and scope remain questions to follow in the eventual proposal. Programs cannot treat this debate as permission for testing that currently lacks authorization.
Worth Reading
-
EFF on browser tools and the CFAA: August background on the distinction between building a tool and accessing someone else's computer.
-
NIST's hardware security workshop report: Published September 1, with recommendations on verification and continuous assurance across hardware lifecycles.
-
UK government's answer on advance AI access: The September 7 answer explains its case for voluntary laboratory relationships and says further targeted interventions are being explored.
Policy Pulse is a weekly bulletin from disclose.io. Have a tip or an experience that belongs in the next issue? Join the community discussion.