❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Citing China, President Trump doubles down on hands-off approach to AI regulation

By: djohnson
22 September 2026 at 11:16

President Donald Trump continued to defend his administration’s hands-off approach to AI regulation in the wake of hacks carried out by U.S. commercial frontier models that have rattled policymakers and industry veterans and spurred calls for more regulatory oversight.

In a Truth Social post Monday, Trump dismissed worries from critics that “AI is going to kill us,” comparing them to complaints from environmentalists about climate change, which he also alleged was a false narrative. He also posited that nothing may matter more than future U.S. dominance of the technology over geopolitical rivals like China.

“Whoever wins AI, WINS!” Trump posted. “We are leading now over China, and everyone else, and I’m going to keep it that way! I’m not going to stifle Growth, of something that will be bigger than the Industrial Revolution, or the internet, itself.”

Trump has previously suggested that good leadership is the only regulation the U.S. needs for artificial intelligence. He later claimed the Department of Justice was ready to “rein things in” if companies overstepped, but offered no specifics on enforcement, legal authority, or where he would draw that line.

“We will be careful, and that’s why we have the Department of Justice, and other Law Enforcement bodies, that will rein things in if we have to, but I will only encourage AI or, SI (SUPER INTELLIGENCE)!” Trump concluded.

Secretary of the Treasury Scott Bessent recently told Congress that private lawsuits could force AI companies to institute better security, saying it’s clear what the government “shouldn’t do on safety is to give these labs a liability exemption, which is what they are asking for.”

“The best way to guarantee safety is that the creators are liable for what they build and generate,” Bessent said.

Beyond existential fears, critics also argue that inadequate regulation or cybersecurity controls in current AI systems make them impossible to fully control or monitor.

Recently, former President Barack Obama criticized the argument from Trump administration officials that the free market will naturally push industry toward self-regulation and that “these companies will solve the safety issues because they have every incentive to do so.”

“If it turns out to be dangerous, people will just sue them and they’ll be worried about financial liability,” Obama said last week in remarks at Colgate University in New York. “That’s not how we treat airlines or drug companies or food companies.”

The Trump administration issued an executive order earlier this year that set up a voluntary testing regime for some commercial frontier models, largely at private industry’s discretion. That order was significantly delayed and altered by AI industry boosters to ensure that governmental review did not cause companies to postpone their release timelines for new models.

That agreement did not last long before fast-moving events caused the administration to strike another, non-public agreement with frontier AI companies like OpenAI, Anthropic and others governing pre-release testing for models.

But the Trump administration has consistently argued that regulation will harm, not help, U.S. innovation and global competitiveness, and the threat of China frequently looms large in those discussions.

Experts believe China’s AI models are behind U.S. models at the top of the market, where OpenAI and Anthropic have consistently pushed the frontier limits of model capabilities. But Chinese lower and “middle class” models are often cheaper, more efficient and can even outperform more powerful models because users can dedicate exponentially more tokens for their tasks.

The U.S. government has accused Chinese AI companies of conducting widespread, “systematic” distillation of U.S. frontier models, with the implicit encouragement of Beijing.

In defending the administration’s approach, David Sacks, co-chair of the President’s Council of Advisors on Science & Technology and a top adviser on AI issues, specifically cited the threat from China and other countries that he claimed would not be subject to similar restrictions.

“We’re not the only country that has advanced AI labs, and as the president declared…we have to win this AI race,” Sacks told Politico in May, later adding “I think that’s the first thing to recognize is that if somehow we slow down or stop AI development, it doesn’t mean that AI progress is going to stop. It just means it’s going to happen in other countries and specifically China.”

Some observers have alleged that despite their larger differences, top leaders in the U.S. and China may view AI similarly at the strategic level, specfically that increased adoption – and risks – of AI are inevitable.

Ronan Murphy, director of the tech policy program at the Center for European Policy Analysis, posited that while there may not be a formal agreement between the two countries, “they share views both in Beijing and in Washington, particularly in the White House, of: you have to allow this to happen.”

“Clearly there’s a call for regulation from many quarters of AI in the U.S. and elsewhere, but in the White House – and we heard David Sacks talking about it [recently] – It’s ‘let them cook,’ and the Chinese approach seems to be the same,” said Murphy in a press briefing. “So there might be consensus at that level, if nothing else.”

The post Citing China, President Trump doubles down on hands-off approach to AI regulation appeared first on CyberScoop.

Supreme Court denies Trump request to allow USPS mail ballot changes

By: djohnson
14 September 2026 at 22:15

The Supreme Court has rejected a petition by the Trump administration to implement changes to the way the U.S. Postal Service handles mail-in ballots for the upcoming 2026 midterm elections, calling it “arbitrary and capricious.”

The 7-2 decision was handed down Monday with little explanation by the court. Writing for the majority, Justice Kentaji Brown Jackson said the administration “is unlikely to succeed on the merits of its challenge to the District Court’s preliminary injunction” and had failed to articulate a valid reason for seeking emergency relief from the court.

However, in a concurring statement, Justice Brett Kavanaugh said he believed there was “a fair prospect” that the final USPS final regulation would be within their legal authority and appeared to cite unreasonably short timelines imposed on states and his primary reason for denying the stay.

“But applying the rule in the 2026 elections would be arbitrary and capricious and in violation of the Administrative Procedures Act because state and local election officials do not have sufficient time to reasonably implement the rule before the elections,” wrote Kavanaugh.

The executive order would have tasked the USPS with verifying  voter citizenship and the validating ballot materials. The order would have created a barcode tracking system for mail ballot envelopes and “State Citizenship Lists” compiled by the Department of Homeland Security.

The order was quickly challenged by states and voting rights organizations, who argued the executive branch had no constitutional authority to dictate how they maintained their voter rolls.

The White House has justified the order by claiming the federal government has “an unavoidable duty” under Article II of the Constitution to maintain confidence in election outcomes by preventing violations of criminal law, including noncitizen voting.

Lower courts disagreed, blocking the executive order from being put in place before November. The petition to the Supreme Court represented the administration’s best and final hope for judicial relief.

As the administration fought the matter in courts, it moved ahead finalizing the USPS rule. A whistleblower complaint alleged that a “rushed” effort by the White House and U.S. Postal Service to install three new restrictive IT systems meant to verify citizenship that could potentially deny thousands of mail-in ballots if the federal government disagrees with states on a voter or ballot’s eligibility.

While Jackson and Kavanaugh’s rationale took up less than half a page, a dissenting opinion written by Justice Samuel Alito and signed by Justice Clarence Thomas was more than 7 pages long.

Alito wrote that he would have granted the Trump administration their request for a stay, allowing the order to be implemented in time for the 2026 elections. He said states and organizations suing the government lacked standing, and dismissed their concerns that implementing the USPS order ahead of the 2026 elections would thwart their ability to educate voters about mail-in voting, calling them “abstract social interests.”

Ahead of the decision, David Becker, executive director of the nonprofit Center for Election Integrity and Research, told reporters that he doubted members of the Supreme Court majority “want to own the chaos that would ensure” as the USPS, states and voters attempt to navigate changes put in place just months before elections and after many states have begun sending out ballots that do not comply with the proposed rules.

He also said that it would be in line with previous Supreme Court decisions that have recognized state supremacy when it comes to specific election administration authorities, like where and how their citizens vote.

“When they consider issues related to the administration of elections, the casting and counting of ballots, they have sided with the states every time,” said Becker.

The post Supreme Court denies Trump request to allow USPS mail ballot changes appeared first on CyberScoop.

Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure

26 August 2026 at 17:38

Citing cyber and other security threats, President Donald Trump signed an executive order Wednesday that declares a national emergency to secure the U.S. bulk-power system and aims to prohibit certain foreign-produced equipment, software and systems from being used in the  country.

The order says it forbids “any acquisition, importation, transfer, or installation” of such foreign-produced equipment if it’s determined to pose a significant national security risk.

“To deal with the threat to the national security, foreign policy, and economy of the United States, the Order, among other things, generally prohibits certain foreign-produced bulk-power system electric equipment, including associated critical software and digital capabilities that could pose cybersecurity or operational risks, from being purchased or installed in the United States, or appropriately conditions such purchases and installations to address those risks,” the White House said in a fact sheet.

The executive order is a response to fears of Chinese-made equipment housed within U.S. energy infrastructure, and a continuation of other measures from the Trump administration to shun that equipment.

The order, “Declaring a National Energy Emergency to Secure the United States Bulk-Power System,” cites “malicious cyber activities” as one impetus.

“The minimal restrictions on acquisition or operation in the United States of foreign-produced bulk-power system electric equipment augment the ability of some foreign entities to create and exploit vulnerabilities in such equipment; for instance, such equipment might have digital backdoors built into their systems that allow a foreign country to access that equipment remotely,” it states.

China supplies 85% of solar supply chain production capacity, according to the International Atomic Energy Agency, and China is a major player in the power transformer manufacturing business.

In 2024, then-FBI Director Christopehr Wray told Congress that hackers prepositioning themselves in small office and home routers had the electricity grid as one of their targets should China and the United States go to war.

Near the end of Trump’s first term he also signed an executive order seeking to limit the purchase of foreign-made bulk-power equipment. The Biden administration suspended that order, citing the need to review its scope, and revoked and replaced a related Energy Department order. Some utilities found compliance with the 2020 executive order difficult.

For the new order, the Energy Department has 120 days to develop rules to implement the order, in consultation with other key departments.

The post Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure appeared first on CyberScoop.

Postal Service moves to finalize mail ballot regs before SCOTUS ruling

By: djohnson
22 August 2026 at 13:01

In a late Friday night posting to the Federal Register, the U.S. Postal Service said it is finalizing new regulations that would give the federal government potentially vast powers to control mail-in ballots for voters.

The changes are part of an executive order signed by President Donald Trump in March, which directed USPS to develop lists of residents “eligible” for mail-in voting — standards that would be defined by the federal government.

The U.S. Constitution vests states and Congress with the power to regulate elections, and the USPS rules have already been struck down by multiple lower courts. But as the White House appeals to the Supreme Court to reverse those decisions, it is still moving ahead in finalizing the regulations, though USPS says it will not move to implement them until after the Supreme Court rules.

But USPS said it must begin moving forward now in order to ensure the changes are in place by the mid-term elections.

“To ensure the faithful execution of federal law in connection with federal elections, this rule has an immediate effective date,” USPS wrote. “Delaying the effective date would jeopardize implementation of this rule in time for the 2026 general election, which will be held on November 3, 2026.”

According to the notice, USPS has received an astonishing 200,000 comments from the public in response to the proposed rule. It doesn’t provide a breakdown of how many comments were in support or opposition.

By the agency’s own admission, the vast majority of supportive comments appear to argue that the rules would help with the perception among voters that fraud is a “significant problem.”  Phrases like “strengthens confidence” and “reduce uncertainty” are peppered throughout the descriptions.

But no credible evidence of coordinated mail-in voter fraud is presented, and Trump and his allies have been the primary force in American politics spreading the perception that voter fraud by noncitizens, dead people and Democrats is rampant. Courts, post-election audits and independent experts have repeatedly debunked these arguments.

“Whether or not voter fraud is common or uncommon, the Postal Service has the legal authority to take the measures in this rule to facilitate enforcement of federal law, reduce the risk of fraud, and help protect the integrity of federal elections,” the notice stated.

According to the notice, the comments in opposition pointed out that two courts have already blocked the White House’s USPS rules, finding them unconstitutional. Others expressed concerns that the Postal Service “would refuse to accept certain ballots for federal elections that states tender without satisfying the data-entry obligations that the rule would impose,” echoing concerns that election experts have conveyed to CyberScoop in interviews.

The notice also dismisses comments “influenced by partisan political speculation,” that include “conjecture about the underlying intent” of the order, its impact on voter turnout and elections.

“Such remarks are speculative and exceed the scope of this proceeding,” USPS wrote in its notice. “In any event … this rule does not—nor is it intended to—facilitate any form of voter suppression, affect election outcomes, or target particular demographics, districts, or states.”

Last week the U.S. District Court of Massachusetts, which ruled against the administration’s USPS order in an ongoing lawsuit brought by states and voter groups, took the unusual step of issuing a second, separate injunction against the USPS rules. It’s not clear whether the Supreme Court will address both injunctions in the same ruling or separately ahead of election day in November.

“The court has already answered and will again resolve the question clearly and affirmatively,” Judge Indira Talwani wrote when issuing the second injunction. “The executive branch has no authority to regulate elections.”

Some voting groups quickly moved to condemn the Friday night posting, saying it will confuse voters about a state-led voting process that is, as of today, still the law of the land.

“For the 2026 election, voters can continue to rely on the voting rules established by their state unless and until a court orders otherwise,” said Michael McNulty, senior policy director at the nonprofit Issue One. “Yet, because the Trump administration continues its attempts to undermine trust in an effort to centralize control of elections, we all must remain vigilant and continue to build trust in our election system.”

The post Postal Service moves to finalize mail ballot regs before SCOTUS ruling appeared first on CyberScoop.

Federal judge issues second order blocking Trump mail-in voting directive

By: djohnson
11 August 2026 at 19:26

A federal judge has issued a second injunction preventing the United States Postal Service from carrying out President Donald Trump’s executive order focused on mail-in voting.

Judge Indira Talwani had previously ruled that the White House order, which would have essentially placed the federal government in charge of deciding which voters in each state would receive mail-in ballots, was unconstitutional.

The order was part of an ongoing lawsuit between the federal government and 23 states over the order’s legality. The Trump administration has formally petitioned the U.S. Supreme Court to review the case and reverse the decision.

In a new ruling issued Tuesday, Talwani’s said the court “finds it prudent to review the EO now, where less than 90 days pend before the midterms and the millions of citizens who rely on mail voting require clarity as to how or whether they will vote in November.”

“As to those elections occurring before or on November 3, 2026, the court preserves the current electoral status quo, grants the Plaintiffs’ Renewed Motion…enjoins the USPS’s implementation of Section 3 of the EO,” Talwani wrote.

The opinion concluded that the states “are likely to succeed on the merits” in claiming that Section 3 of the executive order violates constitutional separation of powers, and noted that the federal government’s “sole attempts to grapple with the actual merits of Plaintiff Organizations’ constitutional challenge are their briefly presented unitary executive arguments.”

But Talwani wrote that whether the president has ultimate authority over USPS actions is irrelevant if it results in a “facially unconstitutional” act.

“Instead, the court need only determine whether the EO is facially unconstitutional based on the substance of the text’s directives,” the opinion said. “The court has already answered and will again resolve the question clearly and affirmatively. The executive branch has no authority to regulate elections.”

The post Federal judge issues second order blocking Trump mail-in voting directive appeared first on CyberScoop.

National cyber director lays out White House plans to secure AI without writing new rules

4 August 2026 at 23:17

The Trump administration executive order on artificial intelligence tried to strike the balance between responsible use, security and mutual benefit, all with an eye toward not making it regulatory in nature, National Cyber Director Sean Cairncross said Tuesday.

“Everyone is working towards the same goal in terms of protecting the country and securing our systems, and we are trying to ensure that defenders have this technology as quickly and at scale as possible, but there are obviously specific security concerns, and industry has been very sensitive to this as well,” Cairncross said at the Black Hat 2026 conference in Las Vegas.

The security concerns about AI have moved to the forefront of discussions about the technology after OpenAI models escaped a test environment to hack the company Hugging Face last month.

“The design of this is that when there is something that happens, when there is a breach, when there is an event, that that system, that network of connections can exist, adapt to that, and seek to remedy that as quickly as possible, so that form follows function rather than turning that upside down, and as usual with the government pen just proceeding in a vacuum,” Cairncross said.

The Trump administration has drawn criticism over whether it has struck the right balance on AI rules. Trump’s AI executive order notably got pulled just before its scheduled release, with the final version signed in June missing some aspects that had drawn industry opposition.

“What needs to be built is a flexible, adaptable structure that enables information sharing between industry and government, so we can guarantee that this technology benefits everyone it’s going to benefit, but is used responsibly and securely,” Cairncross said.

He said the administration is working with industry during implementation of the executive order.

“A regulatory regime would not only strangle growth, development, and innovation, and be enormously harmful to the industry, but it would be obsolete 48 hours after it was gone through whatever process it had gone through,” Cairncross said.

Open source will play a “vital” role in the U.S. spreading its vision for AI across the globe, he said.

“We are extremely interested in looking at ways to build U.S. open source, make it competitive, make it the preferential adoption by planet Earth,” Cairncross said. “We understand and appreciate the value to the ecosystem that it has, the innovation, the startups who rely on it, the leap forward it makes possible in ways that otherwise would never happen. And so I think it’s an incredibly thriving ecosystem in AI right now, and we are looking to do what we can to grow, foster, and push that U.S. open source model.” 

Speaking at the same conference, Nick Andersen, the acting director of the Cybersecurity and Infrastructure Security Agency, seconded Cairncross’s comments about AI executive order implementation. He touted the Gold Eagle clearinghouse as one example.

“Those are fantastic opportunities we have to really provide a unifying function around the way that we’re going to do AI-enabled vulnerability reporting and disclosure at scale in a way that we haven’t had to do before with some of our legacy platforms, and just continue to expand out those opportunities,” he said. “That access — to build off the director’s point earlier — to really enable that industry collaboration, that’s so key and critical to us as we move forward.”

Matt Kapko contributed reporting to this story.

Updated 8/5/2026: to include comments from Andersen.

The post National cyber director lays out White House plans to secure AI without writing new rules appeared first on CyberScoop.

CISA issues recommendations to federal agencies on open-source software security

30 July 2026 at 14:24

The Cybersecurity and Infrastructure Security Agency published a guidebook for federal agencies Thursday to aid them on managing security risks with open-source software, touching on topics like patching and open-source AI models.

An executive order President Joe Biden signed and that President Donald Trump amended ordered CISA and other agencies to issue open-source security recommendations to federal agencies. But the guidance is also timely, given a recent slew of attacks on open-source software (OSS).

“As part of our statutory mission, CISA remains laser-focused on enhancing the nation’s cybersecurity by collaborating with government, industry and the open-source community to understand and securely use OSS,” said Chris Butera, acting executive assistant director for cybersecurity. “CISA encourages federal civilian agencies to review this guide and implement the principles and practices to improve risk management, better execute their mission, and better serve the public.” 

The document, “Open Source Software: Security Principles and Practices,” touts the advantages of open-source software — which anyone can use, modify and share — as offering benefits in efficiency, cost, security transparency and more, but notes that it also has unique tradeoffs.

“All software carries risk, and OSS is no more or less risky than other software. The key distinction is that, with OSS, agencies can directly assess code quality and security, rather than relying solely on vendor assurances,” the guidance reads. “OSS is increasingly intertwined with emerging technologies such as artificial intelligence. Agencies that adapt to OSS’s unique characteristics will position themselves to meet future challenges and leverage new innovations.”

The guidance says that agencies need to take steps to evaluate the trustworthiness of an OSS project before approving an OSS component for use, and track OSS in their asset management repositories. It details how agencies should deal with patching, including when there’s a new OSS vulnerability that doesn’t have one. It offers advice on how agencies might contribute to OSS projects, produce them and secure rights for government reuse of code when contracting for custom software development. And it explains how it should approach open-weight AI models.

“Agencies should approach ‘open source’ AI systems differently from other OSS because open source licenses for AI software do not require the level of transparency needed to evaluate the trustworthiness of the software,” the guidance states.

Æva Black, an open-source security expert and former OSS lead at CISA, said she applauded her former agency for the guidance, telling CyberScoop that it “demonstrates a grounded understanding of the global, diverse, and participatory nature of open source software development, and provides essential guidance for federal agencies to safely use open soure during a crucial moment.” 

She singled out its recommendations on the risks of deploying unverifiable open-weight AI models on sensitive networks.

“Due to recent advances in AI, particularly in large language models capable of finding and exploiting software vulnerabilities, vulnerability management is facing a global crisis,” she said. “Many proprietary software vendors are using this as an opportunity to spread ‘fear, uncertainty, and doubt’ about open source in order to capture public attention, and, I presume, public money — but when used responsibly and maintained collaboratively, I believe open source software is, and will remain, the safest and most cost-effective means for building large scale public infrastructure.” 

CISA has produced a bevy of security guidance and updated advisory materials this week: on the creation of software bills of materials written in conjunction with other agencies and allied governments that won praise from experts; on the isolation of vital operational technology during a crisis, also written with other agencies and allied governments; and the release of updated secure cloud configuration baselines for Google Workspace.

The post CISA issues recommendations to federal agencies on open-source software security appeared first on CyberScoop.

Supply chain challenges loom large in quantum race, White House official says

29 July 2026 at 16:22

One of the most difficult obstacles to overcome in the quantum race will be the supply chain, given how diffuse it is, a top White House official said Wednesday.

“Supply chain is one of the biggest challenges in my mind, and really, the challenge with the quantum supply chain is that quantum is not defined by a single hardware platform,” said Brad Blakestad, director of the National Quantum Coordination Office within the White House Office of Science and Technology Policy.

“If you look at the quantum computing technologies, the quantum sensing technologies, the networking — those are all different,” he said in a webinar hosted by Inside Cybersecurity and USTelecom. “And even within computing, there’s seven different modalities that use completely different components. So we have this not just one monolithic supply chain, but just a bunch of different supply chains that are kind of intertwined in various ways.”

Blakestad made his remarks a little more than a month after President Donald Trump signed two executive orders on quantum computing. He referenced proposed ways to address the supply chain challenge in one of the orders.

“The other major issue or challenge that we face right now is that we’re on the cusp of quantum exploding from a commercialization perspective, but we’re not quite there yet,” he said. “So there’s not the funding, the revenue coming from large-scale quantum companies at this point to really make the supply chain as robust as you would want. So thinking about it from the government perspective, it’s just [that] there are too many places that I would want to bolster and not enough funding to do it.”

Blakestad touted steps to help that along such as the government buying widgets from a company that makes them to certain specifications, or prize challenges.

The quantum supply chain isn’t just diffuse in the United States, an International Institute for Strategic Studies policy paper noted Wednesday. It’s “inherently international: no single country dominates the supply chain, whether specialised materials, cryogenic equipment, hardware, software, fabrication or algorithms,” the authors, Dongyoun Cho and Maria Shagina, wrote.

And a March report from the Center for a New American Security identified strengthening the quantum supply chain as pivotal to the United States seizing the benefits of the technology, citing gaps in the U.S. supply chain and reliance on foreign suppliers such as China and Russia. 

Supply chain wasn’t the only obstacle Blakestad mentioned as looming large.

“The encryption challenge is a real challenge, and we want to make sure that we are aware of when quantum computers will ultimately get to a scale that they start having these sorts of implications and move as quickly as we can,” he said. “So, just by owning the technologies, by owning the workforce, by making the United States the place that people want to come to be on the cutting edge of this technology, I think that kind of addresses both of those issues, and that’s what makes it so critical.”

Another difficulty is measuring progress, Blakestad said: “It’s also very, very hard to benchmark, and to know that you’re actually doing what you’re supposed to, what you are intending to do.”

The post Supply chain challenges loom large in quantum race, White House official says appeared first on CyberScoop.

OpenAI’s rogue AI agent shows why we need federal rules for autonomous systems

By: Greg Otto
29 July 2026 at 06:00

Months before the Hugging Face breach, Emergence AI published research that investigative journalist Ronan Farrow made public. Ten autonomous AI agents operated across five virtual environments for fifteen days without human intervention. Much of the attention focused on Grok 4.1 turning violent and Gemini 3 Flash committing 683 crimes.

What mattered more went unnoticed: Anthropic’s Claude Sonnet 4.6 built a peaceful democracy in isolation, then stole resources from neighboring environments the moment it joined a shared one. The lesson was clear: safety is not a model attribute. It emerges from the operating environment. The models didn’t change. Working as designed, their behavior evolved as the environment changed. The lesson is hard to ignore: The governance environment changed, and with it, the reward dynamics.

The story here concerns institutions, specifically OpenAI’s and Hugging Face’s, and how we must understand their recent security incident through that lens.

The industry agrees on how the Hugging Face breach happened. Cybersecurity experts have focused on the vulnerabilities, how they were used, and remediation. OpenAI has highlighted the model’s capabilities. Both conversations matter. What requires attention is why this breach is strategically important. After spending the past weekend discussing it with policymakers, security researchers, and industry practitioners in Aspen, I came away convinced we’re examining the wrong problem.

In 1961, Yale psychologist Stanley Milgram’s experiments revealed a broader truth: changing the institutional architecture changes behavior without changing the actor. The Emergence AI researchers didn’t change Claude’s agent. They changed the governance architecture that determined what constituted success for the system. Claude’s behavior changed with it.

OpenAI built a smart model but forgot to build a smarter room. That choice made the Hugging Face breach possible. Every organization now deploying autonomous agents now faces the same governance problem.

OpenAI gave the agent one objective: pass a cybersecurity evaluation. To stress-test it fully, they loosened the safety restrictions, and the agent found a shorter path. Rather than solving the evaluation directly, it found the answers outside the test environment, escaped its sandbox, and exploited a flaw in Hugging Face’s data-processing pipeline to reach live production systems. Over the weekend, with no human oversight, it ran more than 17,000 automated actions by escalating its own access, moving through internal systems, and harvesting credentials.

Hugging Face is one of the world’s most prominent AI companies, valued at approximately $4.5 billion. It provides the infrastructure that governments, defense organizations, and technology companies use to build and deploy AI. The agent was pursuing the objective it had been given. Breaking into Hugging Face was the fastest path to passing the test. Governance set the goal, the level of risk to accept, and who was accountable. Technical design determined whether those governance decisions could be enforced. As researchers James Shires and Max Smeets have argued, for a model capable enough to act on its own, testing and deployment must both must be governed the same way.

AI agent design requires baseline standards. Observability, including a monitoring layer that flags when an agent goes beyond its scope, is a baseline requirement. Human review also matters at escalation boundaries, like when an agent shifts from internal tools to external ones. When any agent crosses that boundary, what alert fires? What human reviews it? We lack clear answers to either. That is a governance choice, not simply a security failure. At best, this was a catastrophically failed test. At worst, how can we trust any frontier AI company to self-govern autonomous agent deployment?

More than a decade ago, the U.S. Department of Defense built the Comply-to-Connect (C2C) program: every device connecting to sensitive networks must prove it belongs there, or it is cut off from the network. C2C works because the quarantined actor stops. A laptop that fails verification goes offline and stays there. An autonomous AI agent adapts around enforcement. C2C was built for passive actors. Governance for autonomous agents must accommodate ones that adapt. Visibility is not enforcement, and enforcement is not control. We are missing all three.

A second failure that is not being discussed enough: the breach exploited an implicit trust assumption in Hugging Face’s data-processing pipeline, where inputs were treated as trusted without verification. After SolarWinds, the U.S. government set rules for software supply chain integrity: Executive Order 14028 and verification demands for federal software. The principle was simple: trust must be verified through proof. Those principles have not yet been comprehensively or consistently applied to the AI model supply chain. The rules remain weak. No one has been asked to explain why.

The answer is not a new framework. Existing frameworks suffice. C2C proved that visibility without enforcement leaves gaps, while Executive Order 14028 established that trust in software supply chains requires proof and verification. The challenge lies in applying these principles to a new category of actor. Congress, the Cybersecurity and Infrastructure Security Agency, or the Office of Management and Budget should make formal determinations that autonomous AI agents must follow the same rules as every other actor on a federal network. The framework exists; it must be updated.

The next incident is already in progress. It will show up in the logs as odd traffic, get handed to the same people who published these frameworks this week, and spark another round of recommendations no one acts upon. We’ve solved this problem before: for devices, for software, for supply chains. We know how to build smarter rooms. The tools exist. The will, the authority, and the decision to govern remains absent.

The post OpenAI’s rogue AI agent shows why we need federal rules for autonomous systems appeared first on CyberScoop.

Trump asks Supreme Court to let him curtail mail-in voting ahead of midterms

By: Greg Otto
27 July 2026 at 18:32

The Trump administration asked the Supreme Court on Monday to let it enforce an executive order that would restrict mail-in voting, after a federal appeals court kept the order blocked in nearly half the states just months before the November midterm elections.

Solicitor General D. John Sauer told the justices that a Massachusetts federal judge acted too soon when she struck down key parts of the order, which blocked federal agencies from carrying it out in 23 states and the District of Columbia. Sauer said the order only directs agencies to study changes and has not yet produced a final rule, so no state has suffered harm. 

“The district court preemptively decided that whatever the agencies may choose to do will necessarily be unlawful,” he wrote. He asked the court to pause the injunction while the case moves through the appeals court, and to grant an immediate stay in the meantime.

President Donald Trump signed an order in March that directs the Department of Homeland Security to compile lists of confirmed U.S. citizens in each state and send them to election officials, along with directing the U.S. Postal Service to draft rules on mail-in and absentee ballots. California and 22 other Democratic-led states sued three days after Trump signed the order, arguing the Constitution gives states and Congress, not the president, power over elections.

U.S. District Judge Indira Talwani ruled in June that the administration lacked power to build its own citizen-voter database and that the Postal Service could not impose new rules on states’ mail ballots by itself. She also found the order’s enforcement language amounted to an improper threat against local election officials. 

In Monday’s filing, the administration leaned on a 2020 case, Trump v. New York, in which the justices threw out a challenge to a separate Trump order on census counts because it was too soon to know how agencies would carry it out. Sauer argued the same logic applies here. The order tells agencies to act only “to the extent feasible and consistent with applicable law.” That wording, he said, means the Postal Service and Homeland Security could still drop or narrow the changes once they finish reviewing public comments and checking what the law allows.

The filing follows a string of fights over how the 2026 midterms will run. Earlier this month, Trump gave a prime-time address reviving his claim that the 2020 election was rigged, this time pointing to China, without providing any new evidence.

The filing also follows a Supreme Court ruling in late June that let states keep counting mail ballots that arrive after Election Day if postmarked on time. 

You can read the full filing below. 

The post Trump asks Supreme Court to let him curtail mail-in voting ahead of midterms appeared first on CyberScoop.

Rubio restricts visas for sextortionists, cyber scammers

23 July 2026 at 16:14

The State Department will restrict visas for cybercriminals like scammers to sextortionists, and in some cases even their family members, Secretary of State Marco Rubio said Thursday.

The Trump administration has sought to make a crackdown on foreign-based scams one of the signature issues of his second term. An executive order that the president signed in March indicated that visa restrictions would be on the table as one response.

“By restricting visa issuance to those who are responsible for or complicit in these criminal enterprises, we are sending a clear message: The United States will go after those who prey on our citizens,” Rubio said.

Other departments have also made efforts to reduce foreign-run scams. In June, the Department of Justice seized infrastructure used by subsidiaries of the Huione Group, a Cambodia-based corporate conglomerate tied to one of the world’s most prolific criminal marketplaces used to commit cyber scams and other crimes.

Rubio authorized the visa restrictions under a 1952 law that gives the State Department the ability to deport or rule as inadmissible someone who poses “potentially serious adverse foreign policy consequences.”

Critics have accused the Trump administration of abusing that provision of the law for political purposes.

Rubio’s statement on the visa restrictions mentions “individuals responsible for, or complicit in, cybercrime and cyber-enabled crime, such as those involved in cyberscams, and sextortion.”  Furthermore, he said, “Immediate family members of individuals engaged in such illicit activities may also be subjected to visa restrictions.”

Betsy Cooper, Founding Director of the Aspen Policy Academy, said the visa restrictions on cybercriminals could be valuable, but offered a caveat.

“Scamming people is a growing global enterprise, and it is a laudable goal to penalize those who scam and defraud people since they so rarely suffer consequences for their actions,” she said in a statement to CyberScoop. “So long as the new visa controls are used narrowly and deployed only against verified scammers and fraudsters, this is a positive step toward combatting cyber-enabled crime.”

While some cyber experts have questioned how much visa restrictions, prosecutions and other punishments of cyber miscreants who are based overseas will affect them, others maintain that it can serve as a deterrent to those who would consider getting into the line of work but want freedom to travel the globe.

FightCyberCrime.org, a nonprofit that seeks to help cybercrime victims, applauded the restrictions on the cybercriminals.

“We welcome efforts to hold cybercriminals accountable across borders. Cryptocurrency investment scams, romance scams, and sextortion cause devastating financial and emotional harm to victims,” it said in a statement to CyberScoop. “Meaningful disruption of these transnational criminal networks is an essential part of the response.”

But there’s still a long way to go in the fight, the statement continued.

“At the same time, we must invest more in victim support, prevention, and recovery resources,” the organization said. “Accountability is critical, but ensuring victims have access to trauma-informed support and resources is equally important.”

The post Rubio restricts visas for sextortionists, cyber scammers appeared first on CyberScoop.

White House details ‘Gold Eagle’ clearinghouse for AI cyber threats

By: djohnson
14 July 2026 at 17:44

The Trump administration unveiled its new federal clearinghouse for sharing AI cyber threat information between the government and private sector, and said the project is already receiving threat intelligence on cybersecurity vulnerabilities and prioritizing patching.

Created last month through a White House executive order, “Gold Eagle” will be managed by the Department of the Treasury, with contributions from the Cybersecurity and Infrastructure Security Agency, Department of Homeland Security, and Department of Defense, as well as open-source software providers, critical infrastructure operators and industry.

“Under President Trump’s leadership, the Treasury Department is working hand in hand with the private sector to safeguard our financial institutions, close vulnerabilities, and protect the integrity of the U.S. financial system,” Secretary of the Treasury Scott Bessent said in a statement. “Treasury, along with our partner agencies, will continue to harness frontier AI capabilities to stay ahead of our adversaries and defend the American people from emerging threats.”

Gold Eagle is meant to help both public and private organizations find, fix and patch vulnerabilities found using AI tools before they’re discovered and exploited by bad actors. The work will involve using AI to find cybersecurity vulnerabilities in victim systems and software, and Secretary of Homeland Security Markwayne Mullin said it would also further explore ways for the technology to be leveraged for cyber defense.

A senior White House official told reporters on a background call that closed source models from frontier AI models, including Anthropic’s Mythos, will be used to discover vulnerabilities.

White House officials said they worked with the Software Engineering Institute, SEI at Carnegie Mellon University to develop a new platform, the Vulnerability Information and Coordination Environment – or VINTS – to receive third-party reports on AI-discovered vulnerabilities. According to the White House, the system has already begun collecting intelligence on vulnerabilities and prioritizing patches.

“I think on the early side of this, we have seen that the scale of vulnerability discovery, particularly with users of new technology to scan their system, is something that is a step function change [than] we’ve seen seen before,” the official said.

As AI models have improved at carrying out core cybersecurity-related tasks – like scanning code for vulnerabilities or developing proof-of-concept exploit code – cybersecurity experts and policymakers have become increasingly worried. The modern internet is rife with insecure code, misconfigurations and other mistakes that can be identified and exploited faster than ever before using AI tools.

Vulnerabilities in open-source software can be both widespread and hidden, as many commercial software products on the market rely on open-source code but few bother to document it. When hackers compromised a logging tool in the Log4J open-source Apache software library in 2021, it required a massive, multi-month coordination effort by CISA, the private sector and other stakeholders to find and fix affected pieces of software.

The White House official said the work of Gold Eagle is reflective of the administration’s “full support” of U.S. open-source software providers and maintainers.

Open source tools are “vital to systems that run throughout our country and daily life,” a senior administration official said, speaking to reporters on background. “It is being maintained by a talented group of people and entities and we will do everything we can to support the strength of that community.”

Michael Daniel, former White House cyber coordinator under President Barack Obama, told CyberScoop that AI is still so new that policymakers continue to observe its impact and adapt. While some existing communication channels for sharing cybersecurity threat information could probably be duplicated for tracking AI threats, there is still much for policymakers to learn more about the technology, the kind of threats it produces and its ecosystem of stakeholders.

“It may turn out at the end of the day that phishing is still phishing, and the fact that now you’ve got AI tools doing it, it’s still phishing. Or there may be something fundamentally different about it that we need to figure out how to combat and share information around,” he said.

The post White House details ‘Gold Eagle’ clearinghouse for AI cyber threats appeared first on CyberScoop.

Found fast, fixed slow: The gap the AI clearinghouse must close

By: Greg Otto
8 July 2026 at 05:00

The AI-focused executive order President Donald Trump signed last month gave the Treasury Department, the National Security Agency, and the Cybersecurity and Infrastructure Security Agency (CISA) 30 days to establish a new “AI cybersecurity clearinghouse.” The deadline passed last week.

The clearinghouse is meant to coordinate the scanning, discovery, and validation of software vulnerabilities in critical infrastructure, and then prioritize how those vulnerabilities get patched and distributed.

It’s the right problem to solve. The question now is whether what is created will actually solve it.

The risk is that urgency produces something that looks like a clearinghouse, but functions like a committee: collecting information, convening meetings, and then stalling when it gets to the hard part.

Going beyond bug discovery is mission critical

It’s counterintuitive at a moment when AI-assisted vulnerability discovery is advancing rapidly, but the hard part is no longer just finding bugs. Those of us working at the intersection of AI and cybersecurity know where the real bottleneck is. HackerOne has seen it firsthand as a launch partner in Patch the Planet, OpenAI‘s initiative to use AI to find and fix vulnerabilities in critical open-source software at internet scale. The lesson underpinning that work, and informed by more than a decade of running vulnerability disclosure programs, is consistent: AI tools can surface vulnerabilities faster than anyone can act on them. What lags behind is everything that comes after discovery: deciding which findings are real, assessing severity in context, writing and testing a fix, and getting a patch accepted and deployed by the people responsible for maintaining the affected code.

Experienced human reviewers frequently disagree with AI-assigned severity ratings, because a model cannot see a project’s threat model or operational context. Software providers, especially the many volunteer open-source maintainers that so much of today’s digital infrastructure rely upon, face a relentless queue: verify the claim, assess the importance, write the patch, coordinate disclosure. AI has accelerated the incoming volume without yet equally accelerating our people and processes’ capacity to manage it. Better bug-finding tools mean you find more bugs. The improvements that really matter are the ones that help defenders push patches out and get them deployed faster.

That lesson should sit at the center of how the clearinghouse is designed.

If the clearinghouse focuses primarily on scanning coordination, which the executive order’s text emphasizes, it risks widening that gap rather than closing it. A body that finds more vulnerabilities but cannot move them to resolution is not a security win. At national scale, it is a backlog generator.

Laying a foundation for success

The administration can get this right, but it requires building the correct infrastructure now, not layering it on later.

The clearinghouse needs to do more than coordinate scanning. It needs to actually triage the results. Its core job should be filtering reports to identify which findings are truly credible, exploitable, and consequential for critical infrastructure. Using shared validation standards and risk-based prioritization, it can determine what warrants a national response. Otherwise, it’s just automating bigger backlogs.

Second, the clearinghouse also needs to tackle something more fundamental. Defenders don’t have the resources to respond to what gets reported. Vulnerabilities in critical infrastructure often live in open-source code maintained by small teams or individuals with no formal obligation to respond to disclosures and limited capacity to act quickly. The clearinghouse should work with the National Institute of Standards and Technology (NIST) to develop guidelines for open-source maintainers on structuring repositories and workflows to speed up patch review and deployment.

These guidelines should include how to use AI-assisted patching and clarify what downstream consumers of open-source code should do to help maintainers address vulnerabilities.  Federal policy should create incentives for downstream users to share responsibility for remediation through funding, engineering support, AI-assisted patch development, and procurement requirements that reward participation in coordinated vulnerability response.

Third, the clearinghouse should treat software bills of materials (SBOMs), the structured inventories of the components that make up a software product, as foundational infrastructure. SBOMs are what make it possible to trace where a vulnerable component lives across the supply chain. Without them, validated findings won’t be fixed fast enough at scale.

Finally, the clearinghouse should measure success based on what is fixed, not based on what is discovered.  Agencies need to publish data on validation rates, time-to-patch, adoption of fixes, and recurring classes of vulnerabilities. These metrics help AI systems, software vendors, and policymakers to continuously improve how vulnerabilities are addressed.

Most importantly: the agencies standing up this clearinghouse should resist the temptation to build its operational model from scratch. The private sector and the open-source security community have years of experience running exactly the kind of vulnerability intake, triage, and coordinated disclosure workflows the clearinghouse needs. The executive order wisely calls for voluntary collaboration with industry. That collaboration should be structural, not advisory, embedded in how the clearinghouse operates from the start, not bolted on after the architecture is already set.

The clearinghouse can work. But the challenge is no longer finding vulnerabilities. It is building a system that can turn discoveries into action. That is how its success should be measured.

The post Found fast, fixed slow: The gap the AI clearinghouse must close appeared first on CyberScoop.

❌
❌