CyberScoop spoke with members of Congress, former federal law enforcement officials, cybersecurity attorneys and other experts about which laws, regulations or policies might apply to agentic hacks carried out by models at Anthropic, OpenAI, Meta, Google and other companies. (Image via Getty)
Experts and policymakers want AI companies to face consequences for agentic hacks. There may not be a clear-cut answer under existing laws and regulations.
SAN FRANCISCO, CALIFORNIA – SEPTEMBER – 15: Nvidia CEO Jensen Huang speaks during the keynote address at Salesforce’s Dreamforce conference at the Moscone Center on September 15, 2026 in San Francisco, California. Dreamforce is an annual event that highlights the company’s technologies and encourages professional networking. (Photo by Benjamin Fanjoy/Getty Images)
One expert told CyberScoop that the announcement reflects industry recognition that after years of training models to behave safely or ethically, more outside controls are needed.
Boston, MA – August 29: Senator Ed Markey addresses his supporters during a ‘Power to the People’ rally at the IBEW Local 103 facility on August 29, 2026. (Photo by Craig F. Walker/The Boston Globe via Getty Images)
A new Democratic bill in Congress would establish a federal Cybersecurity and AI Board of Investigations to provide independent government oversight of cyberattacks carried out by AI…
US President Donald Trump (C) and Open AI CEO Sam Altman (L) react during a working lunch meeting of G7 members, partner countries, and artificial intelligence business leaders as part of the G7 summit, in Evian, eastern France, on June 17, 2026. A G7 summit is set to take place June 15 to 17 in the French town of Evian-les-Bains near Switzerland and it will be attended by country leaders as well as the EU’s foreign policy chief and ministers from Brazil, Canada, the United Arab Emirates and Turkey. (Photo by Ludovic MARIN / AFP via Getty Images)
Following a series of chaotic agentic hacks, Trump and administration officials have consistently expressed fears of Chinese AI dominance in pushing for fewer regulations.
Researchers at Hacktron discovered a vulnerability, HEIF Heist, named for its ability to trigger memory corruption errors in affected software, allowing the attacker to pilfer sensitive data from its victims. (Image Source: Getty)
The bug, since patched, gave attackers remote code execution privileges and access to user accounts and production environments, including Meta’s core product suite and an OpenAI software…
In recent conversations, cybersecurity and national security professionals raised questions about both the technical solutions OpenAI and Anthropic use to contain their models, as well as the glaring absence of federal oversight from federal regulators or truly independent third-party review. (Image via Getty)
While large language models present real risks to society, experts say they can be tested and largely controlled using well-worn cybersecurity and policy choices.
The report details a Russian-aligned espionage campaign against more than 20 organizations, an exploit foundry run by Chinese undergraduates and ShinyHunters-affiliated breaches, among other disrupted operations.
OpenAI, Anthropic, Google, Microsoft, and others say there’s a narrow “defenders’ window” to strengthen security before AI-powered attacks become more sophisticated.
A data center in Vernon, Calif. They are groups calling for AI, and the technology it sits on, to be designated as critical infrastructure. (Getty Images)
The designation would unlock a range of federal services, tools and resources for an industry that policymakers view as increasingly tied to national and economic security.