Low Library Column

SIPA Cyber Regulations Watch

Welcome to the SIPA Cyber Regulations Watch

Brought to you by the SIPA Cyber Regulations Lab at Columbia University's School of International and Public Affairs, this twice-monthly newsletter offers a comprehensive review of everything related to cybersecurity and regulations: law firms' analyses, events, new academic research, international trends, and more! 

Click here to sign up for future issues!

 

Brought to you twice-monthly by Columbia University’s SIPA Cyber Program

Written by Eunice Lee and Tanya Reddy Sattineni with Jason Healey 

29 September 2026

This Week: Senate Leaders’ Post Salt Typhoon Legislation, Federal Board Proposed to Investigate AI-Driven Cyberattacks, GAO Highlights Conflicts in Federal Cybersecurity Rules, China Expands AI Security Governance and more!

What’s Happening on the Hill 

Congress Advances Telecom Cybersecurity Measures: CyberScoop and Inside Towers report that bipartisan lawmakers in both chambers have introduced legislation aimed at strengthening the cybersecurity and security of U.S. telecommunications networks.

  • A Senate bill would create a NTIA-led government-industry working group to develop voluntary telecom cybersecurity standards and a third-party certification program, while a House bill would expand the FCC’s Covered List for telecommunications equipment and services deemed security threats.
  • The measures come amid continued concerns over foreign threats to U.S. communications networks, including the Salt Typhoon campaign targeting telecom providers.

Federal Board Proposed to Investigate AI-Driven Cyberattacks: CyberScoop reports that Sen. Ed Markey has introduced legislation to establish a federal board for independently investigating cyberattacks carried out by AI agents.

  • The proposed Cybersecurity and AI Board of Investigations would investigate AI-driven attacks affecting federal systems or critical infrastructure and could subpoena witnesses.
  • The board would also examine systemic vulnerabilities in the AI supply chain, near-miss incidents and gaps in federal regulatory oversight.

What’s Happening in the World

China Expands AI Security Governance: China's Cyberspace Administration reports that its AI Security Governance Forum was held on 15 September as part of National Cybersecurity Awareness Week.

  • Officials and industry representatives discussed AI-agent security, model security, AI-generated content and security testing.
  • The forum emphasized security governance across the full AI lifecycle, reflecting China's expanding AI-security regulatory framework.

EU Updates Cyber Resilience Act Reporting Guidance: ENISA updated its Cyber Resilience Act Single Reporting Platform FAQ on 17 September, clarifying how manufacturers must comply with the new reporting obligations.

  • The guidance clarifies that manufacturers must report actively exploited vulnerabilities and severe security incidents, with an early warning within 24 hours and a fuller notification within 72 hours.
  • ENISA also clarified how reports are distributed among national CSIRTs and market-surveillance authorities through the single platform.

EU auditors warn weak cyber information sharing is undermining defenses: Reuters reports on 21 September that the European Court of Auditors found gaps in information sharing among EU member states are weakening the bloc’s cyber defenses. National-security concerns and differing national rules are limiting cross-border incident reporting, raising concerns about the implementation of NIS2, which depends on stronger cooperation and information sharing among member states.

 

US Regulators and Authorities

GAO Highlights Conflicts in Federal Cybersecurity Rules: The Government Accountability Office reports that industry representatives have identified duplication and conflicts among federal cybersecurity regulations affecting critical infrastructure sectors.

  • Representatives from the energy, financial services, and healthcare sectors cited overlapping cybersecurity and incident-reporting requirements across federal and sector-specific regulations.
  • GAO identified opportunities to harmonize reporting timeframes and thresholds and improve coordination among agencies responsible for receiving cyber incident report

NIST Finalizes Cloud Identity and Access Security Guidelines: NIST reports that it has finalized guidelines for protecting online identity and access tokens used in cloud environments.

  • The guidance addresses threats including token theft, forgery and misuse, with recommendations for securing authentication and token lifecycles.
  • Although not a regulation, the guidance provides a security framework relevant to federal agencies and organizations using cloud-based identity systems.

In Other Cyber News

Australia Investigates AI Agent Breach of Government Portal: Australian Prime Minister’s Office reports that on 24 September, an AI agent gained unauthorized access to Australia’s Medicare statistics portal. The government said the agent accessed public and non-public files but found no evidence that personal Medicare data was compromised.

 

Fresh Insights

Cyber Incidents Slightly Above 2025: Board Cybersecurity has shared with us the most recent cybersecurity incident graph based on its cybersecurity incident tracker which covers SEC cybersecurity disclosures. As of 29 September 2026, SEC Cyber incidents disclosures are slightly above compared to last year showing that incidents are increasing.

Image
2026 Updated Chart

Ask us about sponsorship!

For more from the SIPA Cyber Program, click here.

Let SIPA Cyber know about related new analyses or upcoming events by emailing us at [email protected]

 

Past Newsletters

Past Newsletters