9-minute read | 1,900 words
What to know this week
OpenAI backs UK AI legislation.
OpenAI has announced its support for creating a new binding UK law that would impose stricter rules on AI developers.
The European Union prepares to ban social media for minors.
At the annual State of the European Union speech, the European Commission President detailed the regional bloc’s new social media law.
This week's full stories
OpenAI backs calls for binding UK AI regulation.
THE NEWS
On Monday, OpenAI announced its support for stricter AI laws in the UK.
Tom Duff Gordon, OpenAI’s head of policy in EMEA, commented:
“OpenAI is in a position to support legislation in the UK to establish durable, mandatory, capability-based requirements for frontier AI that would build on the set of voluntary commitments that we currently have.”
Duff Gordon added that new legislation could put the UK on “equal footing” with the European Union and various frameworks in the US as the company supports “mandatory, capability-based national AI safety regulation.”
Some of the policies OpenAI is looking to establish within the UK include legislation that uses “flexible and adaptive” rules that are complementary to existing international policies.
The UK’s Labour Party has stressed in its 2024 manifesto that a policy goal was to “introduce binding regulation on the handful of companies developing the most powerful AI models.” Since then, party leaders have backed away from that approach, instead emphasizing safety testing and voluntary partnerships.
THE KNOWLEDGE
OpenAI’s support for stronger UK legislation is part of a broader effort by the company for mandatory, capability-based AI safety requirements. The approach is intended to establish common safety standards while allowing regulators to evolve as increasingly capable AI models are released.
In early September 2026, Chris Lehan, Chief Global Affairs Officer at OpenAI, published an article outlining the company’s current policy priorities and its approach to regulating increasingly capable AI systems.
Currently, the company is pursuing the following:
- Pushing for mandatory national AI safety requirements across the US.
- Continuing to support state AI safety legislation in the absence of comprehensive federal policies.
- Advancing industry standards by engaging with other frontier labs to establish voluntary standards.
- Working globally to create AI standards relating to managing risk, ensuring human control, and development procedures.
Lehan noted that one of the most critical goals is to prepare for “recursive self-improvement.” While OpenAI acknowledges that fully autonomous, recursive self-improvement is not a reality today, it is a technology that is coming. To get ahead of this advancement, OpenAI stated that governments need to develop ways to measure progress, ensure human control, and shared safety bars for handling AI development.
The company’s approach to regulation is also reflected in its Blueprint for Democratic Governance for Frontier AI. The blueprint outlines a potential federal framework for governing increasingly capable AI systems, including common testing and independent-assessment requirements, cybersecurity protections, incident reporting, and measures for tracking progress toward recursive self-improvement. OpenAI pointed towards California's SB 53, New York’s RAISE Act, and Illinois’s SB 315 as models for future legislation.
THE IMPACT
As AI models continue to advance, regulators face the challenge of keeping legislation and safety frameworks aligned with rapidly developing capabilities. Model-specific legislation and voluntary commitments can provide safeguards, but their requirements may become outdated as AI systems evolve.
Implementing complementary policies at the national and international levels that employ flexible rules and improve regulatory consistency could provide a pathway toward addressing this challenge. Rather than establishing requirements around individual models, capability-based frameworks could allow regulations to evolve alongside the technologies.
Creating a consistent and flexible policy regime will not be straightforward. Major AI powers such as China and the US are competing to advance their respective AI industries, while other countries, including the UK, are looking to strengthen their positions in the global AI ecosystem. Reaching agreement among these countries on common safety standards could therefore prove difficult, particularly as governments balance AI safety with economic and national security interests.
EU looks to ban social media for minors.
THE NEWS
On Wednesday, European Commission President Ursula von der Leyen spoke at the State of the European Union and highlighted the regional bloc’s latest proposal, named the EU Kids Act. More specifically, the proposal would ban minors under the age of thirteen from being able to access social media platforms, with teens aged thirteen and fourteen being able to access “mini accounts,” which are supervised by parents, and then minors fifteen and older would be allowed to have independent accounts.
Further, for minors ages fifteen to eighteen, platforms would need to provide a “safe design” for their users. Outside of restricting access to social media platforms, the Act would also address other online services, including AI chatbots and online games.
In the speech, von der Leyen stated:
“It is not about our minors accessing social media. It is about when and how do we allow social media access to minors. Children are pulled ever deeper into feeds designed to keep them scrolling.”
Agustin Reyna, the director of the European consumer watchdog BEUC, commented on the new law:
“Children clearly need better protection online, but age verification is not a silver bullet and would raise serious privacy and data protection concerns of its own.”
Once formally introduced, the proposal would need to go through the EU’s legislative process, where it would be debated, changed, and voted upon by the European Parliament and Council.
THE KNOWLEDGE
While the EU is not the first major government to debate a social media ban for minors, this move does mark not only one of the more restrictive bans but also would cover a significant region dramatically increasing pressure on these platforms. Outside of the EU, Australia has also instituted a similar ban, and US states such as California and Florida have passed similar restrictions.
Though the measure is not law yet, and it could take time to debate and roll out, there is significant momentum behind the policy as EU member states have already begun to pass or debate national versions of social media bans. These member states include the following:
- France: Passed a bill in July 2026 that banned social media for minors under fifteen, but the nation’s Constitutional Council blocked the measure in August.
- Germany: The nation is considering legislation that would establish an age limit for social media after receiving recommendations from an expert commission.
- Greece: Planning to ban social media for minors under fifteen and if passed will take effect on January 1st, 2027.
- Denmark: Announced in late 2025, the nation passed a social media ban in September 2026 for minors under fifteen, set to take effect on July 1st, 2027.
- Austria: Drafting legislation to ban social media for minors under fourteen.
- Spain: Planning to ban social media access for minors under the age of sixteen.
Together, these measures demonstrate growing interest among European governments for imposing age-based restrictions on social media. The range of national initiatives could add political momentum to the EU-level proposal, although the legislation would still face negotiations and potential legal and implementation challenges.
THE IMPACT
If enacted, the EU Kids Act would establish a strong new set of requirements for social media platforms within the EU. Platforms would now need to determine a user’s age, enforce different levels of access, and create stronger protections for underage users.
Additionally, the proposal could also increase pressure on platforms to change how their services are designed for younger users. Rather than relying solely on parents to monitor children’s activity, the proposed framework would place additional responsibility on platforms to limit potentially harmful features and provide safer experiences.
For platforms operating in Europe, the challenge will be determining how these requirements interact with the growing number of national regulations. Different age thresholds and implementation timelines could create a fragmented regulatory environment, making it difficult to be in compliance and avoid liability.
This Week's Caveat Podcast: The battle for AI regulation.
Dave Bittner and Ben Yelin sit down with Ethan Cook to look at the growing calls to increase AI regulation. Over the past several weeks, pressure has grown from within the AI industry to better address the rapid scale at which AI is developing and how there are numerous examples of agents escaping sandboxes and hacking other companies. However, despite these calls, the federal government has shown no implementing these changes.
OTHER NOTEWORTHY STORIES
OpenAI agents attacked RubyGems.
What: On Friday, researchers found that OpenAI agents attacked RubyGems, two months before the attack on Hugging Face.
Why: Researchers have disclosed another incident where OpenAI agents successfully attacked another company. In this incident, agents attacked RubyGems, a software service company, uploading malicious packages in May 2026. In a statement, an OpenAI spokesperson commented:
“Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information. We’ll continue to investigate as part of our broader review of agent activity during training and evaluation.”
Outside of this incident, Anthropic has also confirmed that its agents engaged in an unauthorized hacking incident in January 2026. In that incident, Anthropic agents learned how to bend rules and exploit loopholes when attacking the external company.
SEPTEMBER 11, 2026 | Source: Reuters
Anthropic disrupts global adversaries.
What: Anthropic announced that it had disrupted misuse of its models that were being used for research on biological weapons and hacking efforts.
Why: Last week, Anthropic announced that it had disrupted several major adversary efforts to misuse its Claude models. According to Anthropic, both Chinese and Russian-linked hackers were using the models to develop cyber operations, develop biological weapons, and hack its platform to exfiltrate capabilities. In the report, Anthropic documents five examples of scientists using its models to support biological weapons development and it being used for weeks to plan an avian influenza mammalian-adaptation experiment.
Additionally, Anthropic noted new “categories of threat actors” misusing Claude to create software for weapon systems, with operations being tied to China, Russia, and Yemen.
Jacob Klein, head of Anthropic’s threat intelligence group, commented:
“A year ago, let’s say you wanted to optimize a drone or optimize the software on a missile, the models just wouldn't be as good at that task as they are now.”
Anthropic has banned all discovered accounts engaging in misuse and is using the findings to develop stronger safeguards.
SEPTEMBER 10, 2026 | Source: Reuters
UK, US and Netherlands issue advisory on Iran-linked spyware.
What: Several governments published a joint cybersecurity advisory that details spyware that has been linked to Iranian state-linked actors.
Why: On Tuesday, the UK, US, and Netherlands issued a joint cybersecurity advisory that highlights an Iranian-linked spyware that was used to target dissidents, activists, and journalists. The spyware dubbed as “CHOSEN BRICK” was used to steal emails, messages, and other information that was then used for “spear-phishing” campaigns.
The NCSC also commented that the attackers were often posing as trusted contacts on messaging apps in their phishing attempts and at times used fake documents, such as fabricated MRI results, to fool victims into downloading the malware.
In a statement, Paul Chichester, NCSC director of operations, commented:
“The details of this cyber campaign reveal how Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the regime, stealing emails and messages and accessing devices.”
SEPTEMBER 15, 2026 | Source: Reuters
