SIPA Cyber Regulations Watch
Welcome to the SIPA Cyber Regulations Watch
Brought to you by the SIPA Cyber Regulations Lab at Columbia University's School of International and Public Affairs, this twice-monthly newsletter offers a comprehensive review of everything related to cybersecurity and regulations: law firms' analyses, events, new academic research, international trends, and more!
Click here to sign up for future issues!
Brought to you twice-monthly by Columbia University’s SIPA Cyber Program
Written by Eunice Lee and Tanya Reddy Sattineni with Jason Healey
29 September 2026
This Week: Senate Leaders’ Post Salt Typhoon Legislation, Federal Board Proposed to Investigate AI-Driven Cyberattacks, GAO Highlights Conflicts in Federal Cybersecurity Rules, China Expands AI Security Governance and more!
What’s Happening on the Hill
Congress Advances Telecom Cybersecurity Measures: CyberScoop and Inside Towers report that bipartisan lawmakers in both chambers have introduced legislation aimed at strengthening the cybersecurity and security of U.S. telecommunications networks.
- A Senate bill would create a NTIA-led government-industry working group to develop voluntary telecom cybersecurity standards and a third-party certification program, while a House bill would expand the FCC’s Covered List for telecommunications equipment and services deemed security threats.
- The measures come amid continued concerns over foreign threats to U.S. communications networks, including the Salt Typhoon campaign targeting telecom providers.
Federal Board Proposed to Investigate AI-Driven Cyberattacks: CyberScoop reports that Sen. Ed Markey has introduced legislation to establish a federal board for independently investigating cyberattacks carried out by AI agents.
- The proposed Cybersecurity and AI Board of Investigations would investigate AI-driven attacks affecting federal systems or critical infrastructure and could subpoena witnesses.
- The board would also examine systemic vulnerabilities in the AI supply chain, near-miss incidents and gaps in federal regulatory oversight.
What’s Happening in the World
China Expands AI Security Governance: China's Cyberspace Administration reports that its AI Security Governance Forum was held on 15 September as part of National Cybersecurity Awareness Week.
- Officials and industry representatives discussed AI-agent security, model security, AI-generated content and security testing.
- The forum emphasized security governance across the full AI lifecycle, reflecting China's expanding AI-security regulatory framework.
EU Updates Cyber Resilience Act Reporting Guidance: ENISA updated its Cyber Resilience Act Single Reporting Platform FAQ on 17 September, clarifying how manufacturers must comply with the new reporting obligations.
- The guidance clarifies that manufacturers must report actively exploited vulnerabilities and severe security incidents, with an early warning within 24 hours and a fuller notification within 72 hours.
- ENISA also clarified how reports are distributed among national CSIRTs and market-surveillance authorities through the single platform.
EU auditors warn weak cyber information sharing is undermining defenses: Reuters reports on 21 September that the European Court of Auditors found gaps in information sharing among EU member states are weakening the bloc’s cyber defenses. National-security concerns and differing national rules are limiting cross-border incident reporting, raising concerns about the implementation of NIS2, which depends on stronger cooperation and information sharing among member states.
US Regulators and Authorities
GAO Highlights Conflicts in Federal Cybersecurity Rules: The Government Accountability Office reports that industry representatives have identified duplication and conflicts among federal cybersecurity regulations affecting critical infrastructure sectors.
- Representatives from the energy, financial services, and healthcare sectors cited overlapping cybersecurity and incident-reporting requirements across federal and sector-specific regulations.
- GAO identified opportunities to harmonize reporting timeframes and thresholds and improve coordination among agencies responsible for receiving cyber incident report
NIST Finalizes Cloud Identity and Access Security Guidelines: NIST reports that it has finalized guidelines for protecting online identity and access tokens used in cloud environments.
- The guidance addresses threats including token theft, forgery and misuse, with recommendations for securing authentication and token lifecycles.
- Although not a regulation, the guidance provides a security framework relevant to federal agencies and organizations using cloud-based identity systems.
In Other Cyber News
Australia Investigates AI Agent Breach of Government Portal: Australian Prime Minister’s Office reports that on 24 September, an AI agent gained unauthorized access to Australia’s Medicare statistics portal. The government said the agent accessed public and non-public files but found no evidence that personal Medicare data was compromised.
Fresh Insights
Cyber Incidents Slightly Above 2025: Board Cybersecurity has shared with us the most recent cybersecurity incident graph based on its cybersecurity incident tracker which covers SEC cybersecurity disclosures. As of 29 September 2026, SEC Cyber incidents disclosures are slightly above compared to last year showing that incidents are increasing.
Ask us about sponsorship!
For more from the SIPA Cyber Program, click here.
Let SIPA Cyber know about related new analyses or upcoming events by emailing us at [email protected]
Past Newsletters
Past Newsletters
-
September
Senate Advances Salt Typhoon Bill, Federal AI Cyber Board Proposed, GAO Flags Cyber Rule Conflicts, China Expands AI Security Rules & More! - September 29, 2026
Bipartisan House Bill Targets AI Security, Senate Weighs AI Risk Rules, EU Cyber Resilience Act Takes Effect, India Expands Cyber Rules and more! - September 15, 2026
White House Restricts Foreign Power Grid Equipment, Senate Targets Quantum Threats to U.S. Power Grid, CISA Advancements & Vietnam Cyber Expansion! - September 1, 2026
August
White House Authorizes Cyber Ops, California Launches AI Defense, Congress Probes Rogue AI, Water Sector Seeks Rules, India Expands Cyber Powers - 18 August 2026
CISA Nears CIRCIA Rule, Congress Targets AI, EU Expands Cyber Rules, Singapore Tightens CII - 4 August 2026
July
Supreme Court Ruling, EU-U.S. Data Privacy Framework, Pentagon Updates and more! - 21 July 2026
New Cyber and AI Rules Take Shape Worldwide: FCC, UK, Australia & More - 7 July 2026
June
US Tightens AI Cyber Governance, Anthropic Calls for Mandatory AI Safety Testing, Enforcement of Cyber Regulations Increase - 23 June 2026
May
SIPA Cyber Regulations Watch — 27 May 2026
Global Cyber Rules Tighten: UK Mandates MFA, US Speeds Patching, Oversight Expands, AI Risks — 6 May 2026
April
March
A New U.S. Cyber Strategy Anchors This Week’s Developments, Emphasizing Offensive Operations, AI, And Supply-Chain Resilience. Countries Across Europe And Asia Push New Cybersecurity Regulations. — 10 March 2026
February
CISA Opens Comments On Cyber Incident Rules; GSA Updates Contractor Requirements; Congress and Europe Push New Cybersecurity Regulations — 25 February 2026
Global Cyber Regulators Shift Toward Outcome-based Rules, AI Security, Enforcement — 10 February 2026
January
E.U. and U.S. Accelerate Cyber and AI Governance Amid Rising Threats — 27 January 2026
U.S. and Global Authorities Expand Cyber, AI, and Privacy Compliance Enforcement — 13 January 2026
-
December
Cyber & AI Regulation Accelerates Across the U.S. and Globally — 23 December 2025
CMMC Takes Off; India Finalizes Data Law; AI Sovereignty Grows — 9 December 2025
November
Action at the FCC, More on the Future Cyber Strategy, and a DORA Update — 25 November 2025
Special Feature Interview — Emily Park — 18 November 2025
FCC Scraps Requirements, CMMC Is Live, and More AI Rules from California — 11 November 2025
October
States Step Up as National Cyber Strategy Takes Shape — 28 October 2025
California AI Law, Senate Push on CISA 2015 Renewal, and Europe's Chat Control — 14 October 2025
September
CISA Expires, White House Eyes AI Deregulation, and the EU Tries to Cut Red Tape — 30 September 2025
CIRCIA Delay, CMMC's Final Rule, and Cairncross' First Remarks — 16 September 2025
Kids’ Privacy, AI Delays, and CISA Deadlines — 5 September 2025
August
Quantum Bills, Privacy Shifts, and FCC’s Legal Win — 19 August 2025
"We're Not Waiting Around" — Colin Ahern Interview — 12 August 2025
No Summer Vacation for AI Regulation — 5 August 2025
July
The Era of DORA Compliance is Here – 22 July 2025
A New Direction for AI Regulation — 8 July 2025
June
Where is Your Data Going — 24 June 2025
Executive Decision Comes for Cyber Regulations — 10 June 2025
May
Who Will Regulate AI? — 27 May 2025
April