Policy Pulse Policy Pulse - Issue #34 | Week of September 14, 2026 DOE asks how power-system vulnerability reports reach a fix. The CRA platform opens, AI labs revisit evaluation incidents, and the UK CMA review clause is withdrawn.
Policy Pulse Policy Pulse - Issue #33 | Week of September 6, 2026 OpenAI's Astra hits Critical on cyber capability, Google gates Gemini Cyber to vetted defenders, and Anthropic paused external safety testing right as both happened. Plus a live UK CMA reform clause and four DMCA 1201 renewals.
Policy Pulse Policy Pulse - Issue #32 | Week of September 1, 2026 A preview cyber model escaped a stock VM three times on bugs nobody had labelled as security issues, and its disclosure trail is one line. Plus IST's Fragile Foundations sprint and PaperCut on KEV.
policy What Ten State AI Bills Mean for Security Research When it's "Assisted By a Foundation Model" Ten state frontier-AI bills regulate developers, not researchers, and none has a safe harbor for AI-assisted security research. Here is where the chilling effect comes from.
Policy Pulse Policy Pulse - Issue #30 | Week of August 23, 2026 Mandiant found more than 100 critical flaws in two days with an agentic review harness. NIST opened two new comment windows, and CISA added nine actively exploited vulnerabilities.
Policy Pulse Policy Pulse - Issue #29 | Week of August 16, 2026 The White House authorizes vetted private firms to run offensive cyber operations, with no CFAA safe harbor in sight. NIST opens a 60-day RFI on rebuilding the NVD, and OpenAI ships a purpose-built offensive-security model.
policy NIST Wants to Modernize the NVD. Disclosure Should Be Part of the Answer. NIST is asking how to rebuild the NVD for the AI era, and vulnerability disclosure programs are named in the architecture. Comments close October 13. Here's what a useful response looks like.
policy What the White House's New Private-Sector Cyber Operations Memo Actually Says (and What It Doesn't) The August 12 memorandum authorizes vetted private companies to conduct cyber operations under federal control. What it says, what it doesn't, and why authorization is the hinge.
Policy Pulse Policy Pulse - Issue #28 | Week of August 10, 2026 Latvia opens comments on a statutory safe harbor that protects outcomes, not intent. Germany's draft reform would order the BSI to hand zero-days to the BND. Plus the Ninth Circuit on AI agents and the CFAA.
policy Watch: How Hackers Helped the DOJ Protect Security Researchers Leonard Bailey's BSidesLV 2026 keynote tells the inside story of the DOJ's good-faith security research policy, and how the hacker community helped make it happen. Watch it here.
Policy Pulse Policy Pulse - Issue #27 | Week of August 1, 2026 Anthropic discloses three Claude models breached three real organizations during cyber evals, days after OpenAI breached Hugging Face the same way. Congress pushes the FRONTIER Act as CISA's 2015 sharing law nears sunset.
Policy Pulse Policy Pulse - Issue #26 | Week of July 25, 2026 OpenAI's own evaluation models breached Hugging Face, triggering a bipartisan AI Kill Switch bill within 48 hours. A federal judge separately orders published iPhone exploit research deleted on trade-secret grounds.