← Back to Last Week in AI
Week of September 7 2026

Last Week in AI Security — Week of September 7, 2026

EU AI Act enforcement begins with first compliance inspections, while NIST seeks public comment on AI data center security guidance through September 25.

Key Highlights

  • EU AI Act enforcement begins first wave of compliance inspections across member states
  • NIST opens public comment period for AI Data Center Security Analysis framework through Sept 25
  • OWASP LLM Top 10 2026 released, elevating Excessive Agency to third place
  • MITRE ATLAS v5.4.0 adds agent-focused techniques including Escape to Host

Executive Summary

The week of September 7, 2026 marked a transition from incident response to enforcement as the EU AI Act moved into its first active compliance phase. The European AI Office in Brussels, working alongside 24 national market surveillance authorities, began its first scheduled wave of compliance inspections throughout September, targeting high-risk AI systems in recruitment, credit assessment, and healthcare. French regulator CNIL, German BfDI, and Spanish AESIA focused their initial requests on automated resume screening tools in human resources, algorithmic credit assessment systems in retail banking, and AI triaging tools in private healthcare clinics.

On the standards front, NIST invited public comments on the initial public draft of Special Publication 800-239, AI Data Center Security Analysis: A High-Performance Computing (HPC) Driven Approach, with the public comment period open through September 25, 2026. This guidance addresses the security posture of the physical and digital infrastructure hosting AI training and inference workloads, an area that has received less attention than application-layer vulnerabilities despite representing a significant attack surface.

The week’s activity reflects a broader shift in the AI security landscape: from documenting what can go wrong to enforcing what must go right. Organizations deploying AI systems in the EU face immediate documentation obligations, while those building AI infrastructure in the U.S. have a narrow window to shape NIST’s forthcoming data center security baseline before it hardens into procurement requirements.

Top Stories

EU AI Act Enforcement Begins First Compliance Inspections

The transition period for general high-risk systems under the EU AI Act concluded on August 2, 2026, and September marked the beginning of active enforcement. Throughout September, the European AI Office in Brussels, working alongside 24 national market surveillance authorities, began its first scheduled wave of compliance inspections.

The inspections target three specific sectors initially: automated resume screening tools in human resources, algorithmic credit assessment systems in retail banking, and AI triaging tools in private healthcare clinics. These systems fall under Annex III of the AI Act as high-risk applications that require comprehensive technical documentation before market placement.

Under Article 11 and Annex IV of the AI Act, providers of high-risk systems must present an up-to-date Technical Documentation dossier before placing a system on the market or putting it into service. The required documentation includes system architecture diagrams, data governance records, risk management files, and conformity assessment reports.

The enforcement activity comes as by 2026, the market has moved into the stage where high-risk AI obligations are no longer a distant compliance footnote but are becoming operational reality for many businesses. For security practitioners, this means AI governance is no longer a “soft” compliance exercise—it’s becoming a market access requirement with enforceable penalties.

NIST Seeks Public Comment on AI Data Center Security Framework

NIST invited public comments on the initial public draft of Special Publication 800-239, AI Data Center Security Analysis: A High-Performance Computing (HPC) Driven Approach, with the public comment period open through September 25, 2026. The guidance addresses security controls for the infrastructure layer supporting AI training and inference operations.

AI data centers present a distinct threat model from traditional cloud infrastructure. Training clusters often contain tens of thousands of GPUs interconnected with specialized networking fabrics like InfiniBand or RoCE, and a single compromised node can potentially poison training data, exfiltrate model weights, or disrupt distributed training jobs affecting hundreds of machines. The draft SP 800-239 applies high-performance computing security principles to this environment, addressing physical security, network segmentation, supply chain integrity, and operational monitoring.

The September 25 deadline gives infrastructure teams, cloud providers, and AI labs a narrow window to provide feedback before the guidance moves toward finalization. Organizations operating AI training infrastructure should review the draft against their current security posture, particularly around network isolation between training clusters, access controls for model checkpoints, and telemetry for detecting unauthorized data exfiltration.

Framework & Standards Updates

OWASP LLM Top 10 2026 Released

The OWASP LLM Top 10 2026 was released on August 4, 2026, at Black Hat USA. Eight of ten entries moved, and one was renamed: Excessive Agency jumped from sixth to third, Prompt Leakage became Hidden Context Exposure, and Output Handling dropped to tenth.

Excessive Agency jumping from sixth to third reflects what’s happening in production as agentic systems take on more consequential work. The 2026 edition marks a shift from LLMs as isolated components to AI agents with tool access, memory, and autonomous action capabilities. The list now includes explicit mappings to NIST AI RMF, MITRE ATLAS, and CWE identifiers, making it easier to integrate into existing security frameworks.

MITRE ATLAS v5.4.0 Adds Agent-Focused Techniques

The February 2026 MITRE ATLAS v5.4.0 update added further agent-focused techniques including “Publish Poisoned AI Agent Tool” and “Escape to Host”. As of February 2026 (v5.4.0), the knowledge base contains 16 tactics, 84 techniques, 56 sub-techniques, 32 mitigations, and 42 case studies.

The additions reflect real-world attack patterns observed in 2025 and early 2026, where autonomous agents broke out of sandboxed environments or leveraged poisoned tools from public repositories. The “Escape to Host” technique documents methods by which an agent running in a containerized or virtualized environment gains access to the underlying host system, while “Publish Poisoned AI Agent Tool” covers supply chain attacks where malicious actors publish compromised tools to repositories that agents automatically discover and invoke.

NIST AI Documentation Guidance Enters Final Comment Period

On July 29, 2026, NIST released an initial public draft of “Guidance and Templates for Public-Facing AI Documentation: An AI Standards ‘Zero Draft,” with NIST considering input received by September 16, 2026, for the subsequent (possibly final) revision. The guidance provides templates for model cards, system cards, and other transparency artifacts that communicate AI system capabilities, limitations, and appropriate use to downstream deployers.

The September 16 deadline has now passed, and NIST is expected to release a revised or final version in the coming weeks. Organizations should monitor the final publication for updated templates that may become de facto standards for AI transparency documentation.

Vulnerability Watch

CVE-2026-24747: PyTorch weights_only RCE

CVE-2026-24747 is a remote code execution vulnerability in PyTorch’s weights_only unpickler that allows attackers to execute arbitrary code via malicious checkpoint files. A critical vulnerability has been identified in PyTorch’s weights_only unpickler that allows attackers to craft malicious checkpoint files (.pth) capable of corrupting memory and potentially achieving arbitrary code execution. When a victim loads a specially crafted checkpoint file using torch.load(…, weights_only=True), the vulnerable deserialization mechanism can be exploited to execute arbitrary code on the target system.

The vulnerability has a CVSS score of 8.8 (High), with attack vector Network, attack complexity Low, privileges required None, user interaction Required. Prior to version 2.10.0, a vulnerability in PyTorch’s weights_only unpickler allows an attacker to craft a malicious checkpoint file (.pth) that, when loaded with torch.load(…, weights_only=True), can corrupt memory and potentially lead to arbitrary code execution. Version 2.10.0 fixes the issue.

Organizations using PyTorch should upgrade to version 2.10.0 or later immediately. For those unable to upgrade, avoid loading checkpoint files from untrusted sources and implement file integrity verification before loading any model weights.

No significant new CVEs specific to ML frameworks were disclosed during the September 7-13 period.

Industry Radar

Google Releases Gemini 3.8 Flash Cyber

The release of Gemini 3.8 Flash Cyber comes a little over a month after Google unveiled Gemini 3.5 Flash Cyber. The latest model improves upon its predecessor by demonstrating frontier-level performance in autonomous vulnerability discovery, even surpassing larger frontier models from rivals Anthropic (Mythos 5) and OpenAI (GPT-5.6 Sol and GPT-5.5-Cyber).

The tech giant said it’s currently working with over 650 partners globally, including CrowdStrike, Datadog, Menlo Security, Palo Alto Networks, and Snowflake. The program is available to a group of Google Cloud customers, government agencies, and cybersecurity partners.

The model’s release continues the trend of frontier AI labs positioning cybersecurity-specific models as both defensive tools and proof points for responsible capability deployment. Google’s emphasis on partner integration suggests a recognition that model capabilities alone are insufficient—effective defensive AI requires integration with existing security tooling, threat intelligence feeds, and incident response workflows.

Salesforce Launches Agentforce AI Agents

Salesforce introduced seven named Agentforce AI agents—Casey, Paige, Carter, Hunter, Marshall, Piper, and Fin—each built for a specific business function in sales, service, commerce, IT/HR, supply chain, and customer experience on September 11, 2026. These agents sit on Salesforce’s existing Customer 360 data platform and operate within a company’s existing business rules, permissions, and security setup.

The announcement is notable for its explicit emphasis on operating “within a company’s existing business rules, permissions, and security setup,” reflecting growing enterprise concern about agent authorization and access control. The agents represent a shift from chatbot interfaces to autonomous actors with write access to CRM data, inventory systems, and customer communication channels.

Policy Corner

EU AI Act Compliance Inspections Begin

As detailed in the Top Stories section, the transition period for general high-risk systems under the EU AI Act concluded on August 2, 2026, and throughout September, the European AI Office in Brussels, working alongside 24 national market surveillance authorities, began its first scheduled wave of compliance inspections.

The Act applies in tiers: prohibited practices from February 2025, GPAI rules from August 2025, and high-risk AI obligations from December 2027 (Annex III) and August 2028 (Annex I) after the 2026 omnibus amendments. The September inspections focus on systems that were already required to comply under the August 2 deadline, primarily general-purpose high-risk AI systems.

For U.S.-based organizations deploying AI in the EU, the key compliance question is no longer “when does this apply?” but “do we have the required documentation ready for inspection?” Organizations should conduct internal audits against Article 11 and Annex IV requirements, particularly for systems in recruitment, credit scoring, and healthcare decision support.

No Significant U.S. Federal AI Legislation This Week

No major U.S. federal AI legislation or executive orders were enacted during the September 7-13 period. State-level activity continues, but no bills were signed into law during this specific week.

Research Spotlight

Analysis of LLMs Against Prompt Injection and Jailbreak Attacks

A paper presented at the Workshop on Privacy in Large Language Models (LLM) and Natural Language Processing (NLP) 2026 evaluated prompt injection and jailbreak vulnerabilities using a large, manually curated dataset across multiple open-source LLMs, including Phi, Mistral, DeepSeek-R1, Llama 3.2, Qwen, and Gemma variants, observing significant behavioural variation across models, including refusal responses and complete silent non-responsiveness triggered by internal safety mechanisms.

The study’s focus on silent non-responsiveness is particularly relevant for production deployments, where an agent that fails silently presents a different operational risk than one that explicitly refuses a request.

Adversarial Machine Learning: A 20-Year Survey

A comprehensive survey published in IEEE Access Volume 14, 2026, titled “Adversarial Machine Learning: A 20-Year Survey of Attacks, Defenses, and Standards” organizes ML adversarial threats and defenses stage by stage along the ML lifecycle.

The survey argues that AML has traditionally been treated as a ‘loose’ collection of techniques like adversarial examples, data poisoning, and model extraction, making the current view of AML incomplete. Modern ML systems are long-lived pipelines with feedback loops, fine-tuning cycles, telemetry ingestions, deployment governance, and API exposures, with attacks occurring at every point throughout the pipeline lifecycle, and defenses needing to counter those attacks at all points in the pipeline lifecycle.

Surveying the Operational Cybersecurity and Supply Chain Threat Landscape for AI Systems

An arXiv preprint surveying operational cybersecurity and supply chain threats when developing and deploying AI systems documents vulnerabilities in AI software frameworks. The paper notes several vulnerabilities have been discovered in TensorFlow, including continuous integration and continuous delivery/deployment misconfigurations in TensorFlow’s GitHub pipeline that would allow an attacker to compromise build agents to create malicious releases, remote code execution, and exfiltration of GitHub Personal Access Token. While TensorFlow has addressed many concerns, certain vulnerabilities persist via a downgrade attack when TensorFlow will provide (vulnerable) functionality to older models to support legacy systems, with Filus and Domańska (2023) detailing several other vulnerabilities in TensorFlow and the difficulty of detecting them.

What This Means For You

If you deploy AI in the EU, compliance is no longer theoretical. The September compliance inspections are real, targeting specific sectors with enforceable documentation requirements. Conduct an internal audit now against Article 11 and Annex IV of the AI Act. If you operate automated resume screening, credit scoring, or healthcare AI systems in the EU, verify that you have current technical documentation, risk management files, conformity assessments, and conformity declarations ready for regulatory review. Missing documentation can result in market suspension.

NIST SP 800-239 public comment period closed September 25. If you operate AI training infrastructure or provide cloud services for AI workloads, the final version of this guidance will likely shape procurement requirements for federal AI projects and become a baseline for commercial best practices. Review your current network segmentation between training clusters, access controls for model checkpoints, and telemetry for detecting unauthorized exfiltration. When the final version publishes, cross-reference it against your security posture and close any gaps before it becomes a checkbox in your next SOC 2 audit or customer security questionnaire.

Update your AI risk assessments to include OWASP LLM Top 10 2026 and MITRE ATLAS v5.4.0. Both frameworks now include agent-specific risks that were either absent or deprioritized in earlier versions. If you’re deploying agents with tool access or autonomous action capabilities, map your architecture against the new Excessive Agency risk (OWASP LLM03:2026), the Escape to Host technique (ATLAS), and the Publish Poisoned AI Agent Tool technique (ATLAS). These are no longer hypothetical—multiple incidents in August 2026 demonstrated these attack patterns in production.

Tools and Resources

OWASP LLM Top 10 2026 The latest community-driven guide to LLM application security risks, released August 4, 2026. Now includes mappings to NIST AI RMF, MITRE ATLAS, and CWE. Available at OWASP GenAI.

MITRE ATLAS v5.4.0 Knowledge base of adversarial tactics and techniques targeting AI/ML systems, updated February 2026 with agent-focused attack patterns. Available at atlas.mitre.org with machine-readable STIX 2.1 format.

NIST SP 800-239 (Draft) AI Data Center Security Analysis guidance applying HPC security principles to AI infrastructure. Draft available for review at NIST CSRC.

EU AI Act Single Information Platform Official European Commission resource for AI Act guidance, templates, and compliance tools. Available at the AI Act portal.