7-minute read | 1,500 words
What to know this week
Newsom signs an order to explore AI rules.
Governor Newsom signed an executive order focused on exploring stronger AI controls, including “kill switch” capabilities.
ShinyHunters hacked the FBI.
ShinyHunters claims to have hacked the FBI, stealing over two terabytes of sensitive FBI personnel data.
This week's full stories
Newsome advances California’s AI oversight push.
THE NEWS
On Friday, California Governor Gavin Newsom signed an Executive order focused on AI. More specifically, the order speeds up the implementation of two laws already in place and requests experts to explore proposals designed to increase oversight of advanced models.
The two laws that had their implementation moved up by a year include SB 813 and AB 1405, both of which were signed into law in September 2026.
Regarding exploring new proposals, the order mandates that experts provide the state with recommendations within two months on how the state could improve its current AI safety laws.
In Newsom’s press release, he wrote:
“The federal government’s abject failure to create any form of meaningful AI oversight or accountability should alarm every American, especially when AI CEOs themselves are begging for regulations.”
Outside of this order, Governor Newsom is also considering other actions on AI safety, including hosting special legislative sessions.
An OpenAI spokesperson reacted positively to the order stating:
“We welcome Governor Newsom’s continued interest in strengthening the state’s approach. We look forward to working with Governor Newsom on his proposals and with the California Legislature and the state’s next governor on broader AI policy next year.”
THE KNOWLEDGE
One of the potential security ideas involves mandating that frontier AI models implement kill switches. Notably, a bill centered around these issues already reached Governor Newsom’s desk in 2024. The bill, called SB 1047, or the Safe and Secure Innovation for Frontier AI Models Act, aimed to define target thresholds for loss, implement a mandatory kill switch for frontier models, impose new liability for developers, and improve auditing capabilities.
However, at that time, Governor Newsom vetoed the bill. When vetoing the effort, Governor Newsom noted that while the bill was “well-intentioned,” its regulations were too “stringent.” The order revisits several concepts that appeared in SB 1047 and is considering them for future enforcement efforts.
California state senator Josh Becker voiced support for implementing kill switches, stating:
“With the breakouts we’ve already seen, we have to have the ability to shut down these systems when they’re behaving in ways we don’t want them to behave.”
Regarding the other two laws,
- SB 813 centers around creating independent verification organizations to assess AI safety risks.
- AB 1405 focuses on establishing independent third-party AI auditors.
Outside of these two laws and executive orders, California has also passed SB 53 in 2025, which is one of the most comprehensive state AI laws to date. SB 53, or the Transparency in Frontier AI Act sets mandatory transparency and safety reporting requirements for major AI developers alongside improving whistleblower protections.
By reconsidering protective measures, like the kill switch, and speeding up timelines, California is moving toward greater independent oversight of frontier AI models.
THE IMPACT
California’s latest actions mark a shift in how frontier AI systems are being monitored, with the possibility of moving to a more responsible model for evaluating safety risks from AI developers.
For AI developers operating in California, these proposals and increased timelines will likely create additional compliance requirements and increase the role external organizations have when evaluating frontier models. Additionally, these new requirements could contribute to the broader debate regarding whether frontier AI systems should continue to be able to self monitor or whether independent or government agencies need to increase access.
The recommendations are currently set to be expected sometime around mid-November, after which California lawmakers will likely determine what proposals should be considered.
ShinyHunters claims to have hacked the FBI.
THE NEWS
On Tuesday, the cybercriminal group, ShinyHunters, announced that it has hacked the Federal Bureau of Investigation (FBI) and that it has allegedly stolen over two terabytes of sensitive employee data.
A spokesperson for the cyberhacker group stated:
“This is not financially motivated. We want the FBI to correct or retract their statements they made, which included substantial false allegations.”
To execute the attack, the group claims it exploited a zero-day vulnerability on the FBI jobs site that then allowed the group to use remote code execution on the servers. Afterward, the group defaced the site writing:
“This site has been seized by ShinyHunters.”
Alongside this exploit, the group has claimed that it moved laterally to steal data belonging to current, former, and prospective Bureau employees.
ShinyHunters stated that this effort was motivated by allegations that the group was using stolen data to harass, threaten, and swat victims, all of which the group claims is false.
The group’s spokesperson stated:
“I have been doing my very best to combat these allegations, and this is the best way to do it.”
Reuters has verified that the stolen data includes names, postal address details, and Social Security numbers, though it is unclear if this data came from the FBI systems as the hackers claim.
THE KNOWLEDGE
ShinyHunters’ claims that the FBI is making false claims about their behavior tie back to a previous hacking incident involving Canvas. In this incident, the group successfully targeted Canvas, a widely used education tool, and Instructure, Canvas’s parent company. During the hack, ShinyHunters exfiltrated sensitive student data from roughly 9,000 different schools.
This incident eventually ended with Instructure agreeing to pay ShinyHunters where all data was returned to the company and the hacking group’s copies were destroyed. Additionally, the company stated:
“No Instructure customers will be extorted as a result of this incident, publicly or otherwise…There is no need for individual customers to attempt to engage with the unauthorized actor.”
The incident prompted the FBI to issue a public advisory about ShinyHunters. The Bureau described the group as specializing in large-scale data breaches under extortion and warned that the group has used claims of stolen information, threatening communications, and, in some cases, swatting as pressure tactics against victims.
Those statements are now directly relevant to the FBI breach claim. ShinyHunters says its alleged attack was intended to force the Bureau to correct or retract those allegations.
THE IMPACT
If ShinyHunters’ claims are confirmed, information such as home addresses, phone numbers, and Social Security numbers could create risks well beyond the initial breach, including identity theft, targeted phishing, impersonation, and harassment.
The incident also highlights the difficulty of assessing a breach when the primary source of information is the threat actor itself. ShinyHunters has provided claims about the amount and type of data it says it accessed, but the FBI has not publicly confirmed the extent of the alleged compromise. Until investigators establish what systems were accessed and what information was actually taken, the reported scale of the incident remains uncertain.
For government agencies, the potential consequences are particularly significant. Employee and applicant information can provide attackers with details that may be useful for social engineering or targeting individuals outside the compromised system. The FBI has previously warned that ShinyHunters uses stolen information to create more convincing phishing and impersonation attempts.
This Week's Caveat Podcast: When digital tools get it wrong.
Dave Bittner and Ben Yelin look at a recent court ruling where a lower court has rejected limits on border searches on cell phones. Additionally, they look at another case where a US woman was falsely charged with bank theft due to an AI facial recognition error.
OTHER NOTEWORTHY STORIES
Irish privacy regulator fines Google.
What: Ireland’s Data Protection Commission fined Google $463 million following an inquiry into its processing of location data.
Why: On Monday, the European Union’s leading privacy regulator fined Google, alleging that the company violated the regional bloc’s General Data Protection Regulation (GDPR). Specifically, the Irish watchdog was concerned about three features: Web & App Activity, Location History, and Location Accuracy.
In response to the fine, a spokesperson for Google emphasized that the case focused on historical policies, and that it has since debuted new tools that improved its location data management practices.
This fine is the fourth largest ever levied by the watchdog.
SEPTEMBER 21, 2026 | Source: Reuters
Data sharing practices undermining EU cyber defences.
What: According to a recent report, EU efforts to combat cyberattacks are being undermined by a failure to share enough information.
Why: On Monday, the European Court of Auditors released a report emphasizing that cybersecurity efforts are suffering because member states are failing to share enough information regarding incidents.
The report wrote:
“When a serious cyber incident occurs, timely and actionable information is essential. Without it, networks and mechanisms lose much of their added value.”
The report noted that, despite a large-scale cybersecurity label being applied to any event impacting two or more nations, the label has not been used since 2016.
SEPTEMBER 21, 2026 | Source: Reuters
