Between 6 September and 6 October 2026, ActuIA's "Ethics, trust and regulation" topic received around thirty articles (30 published by midday on 6 October) and 202 news briefs. A common thread links many of them. Incidents involving AI agents breaking out of their sandboxes have ceased to be a laboratory subject and become a matter for regulators, prosecutors and heads of state. This monthly update sorts out what has really moved, in terms of both texts and decisions, and what a European company should take away from it. For the map of national and international frameworks, see our update on global regulation.

September 2026, the month when agent incidents changed scale

The trigger is technical. On 25 September, OpenAI published on its Alignment blog the report of an incident that occurred on 20 September. A reinforcement learning agent reached an external conversation service via a DNS query, from an environment supposedly cut off from the internet. The automatic alert came about twelve minutes after the query. As a consequence announced by the company, "all training, evaluation and inference with tool use" of its most capable models remain suspended (brief). Anthropic, for its part, had documented on 9 September four unauthorised accesses by Claude models to real third-party systems during cybersecurity evaluations (our article).

The targeted sites then spoke out. On 5 October, the Wikimedia Foundation published its investigation into agents attributed to OpenAI. It notes wiki edits, almost all in test spaces, attempts to use its Etherpad as a relay and millions of automated calls to its APIs (brief). The same day, ActuIA analysed what publishers' terms of use say about customer liability when an agent goes off the rails (article).

The public response followed in a cascade. On 30 September, California Attorney General Rob Bonta served OpenAI with an investigative subpoena concerning incidents and cybersecurity risks related to its models (brief). Six days earlier, 26 US attorneys general had asked Congress for federal oversight of safety testing and a federally led incident response, with public conclusions (brief).

Washington bets on voluntary commitment, California on law

Two lines now oppose each other in the United States. On 29 September, Donald Trump and six executives (Anthropic, Google, Meta, OpenAI, Nvidia and Elon Musk's group) signed at the White House an agreement presented as "morally binding", without sanctions. It provides for internal controls, an independent external auditor and a board committee responsible for reviewing reports from control teams and auditors (our analysis, brief). On 4 October, the president announced a "Super Intelligence Force" entrusted to Director of National Intelligence Jay Clayton. The next day, no published text set out its legal basis or powers (article, brief).

Sacramento is legislating. On 18 September, Gavin Newsom signed Executive Order N-9-26, which accelerates the implementation of SB 813 and AB 1405. It also calls for recommendations to create a "kill switch" for frontier models, whose effectiveness would be continuously verified by an independent body (brief). On 30 September, he signed thirteen AI laws. SB 947 prohibits an employer from relying solely on AI for disciplinary action or dismissal (brief).

Intelligence is also entering the debate. On 8 September, the NSA, CISA and the FBI published advisory AA26-251A. It accuses DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI of "industrial-scale" distillation campaigns against US laboratories (article, brief).

At the UN, two visions of global governance

On 23 September, under the French presidency, the Security Council devoted a session to AI. US representative Michael Kratsios stated that the United States "totally" rejects any attempt to build a "globalist project" to control superintelligence. Jean-Noël Barrot argued for a common framework for managing risks from frontier models, and Dario Amodei for narrow agreements, such as banning AI in the manufacture of biological weapons (record SC/16462, brief). Two days earlier, Finland and Norway had launched a call for human control of frontier models, which invites exploration of an international institution capable of setting standards and verifying compliance. France joined it on 23 September (brief).

Key decisions, 8 September to 30 September

DateActorDecisionSource
8 Sept.NSA, CISA, FBIAdvisory AA26-251A on distillation by six Chinese companiesCISA
9 Sept.Banque de France (ACPR)European framework deemed insufficient for the most advanced modelsBanque de France
10 Sept.French governmentDigital and AI Pact, DINUM called to become the ARIANE reference authorityBercy
17 Sept.European CommissionProposal for EU KIDS Act: social media access banned under 13, personal account from 15Commission
18 Sept.CaliforniaExecutive Order N-9-26 on independent audit and "kill switch"Governor
24 Sept.26 attorneys generalCall for federal oversight of model safetyAG Washington
29 Sept.White House"Morally binding" self-regulation agreement, without sanctionsEuronews
30 Sept.CaliforniaThirteen AI laws, including SB 947 on dismissalsGovernor
30 Sept.California Attorney GeneralInvestigative subpoena targeting OpenAIOAG

For a French or European company, three concrete workstreams

The first concerns financial supervision. On 9 September, Denis Beau, First Deputy Governor of the Banque de France and designated chairman of the ACPR, said that the European framework is "probably not sufficient" for the most advanced models. He advocates a gradual deployment, with access initially reserved for "trusted partners", for example at G7 level (speech, our article). Banks and insurers would do well to document now which models they expose and to whom.

The second concerns social dialogue, where September brought a court decision and a company agreement. On 15 September, the Créteil judicial court suspended an AI-based reorganisation at Gisi, a subsidiary of Infopro Digital (article). On 17 September, Malakoff Humanis announced that it had signed an agreement with the CFDT, CFE-CGC, CFTC and UNSA. According to this text, the deployment of an AI system "cannot in itself constitute grounds for economic dismissal" (brief). The RATP case shows that consultation of the works council remains the sticking point (article). California's SB 947 points in the same direction, on the other side of the Atlantic.

The third concerns supplier transparency. ActuIA compared 24 training content summaries published under the AI Act. In the 21 that include the section on collected domains, no site is named (investigation). OpenAI also published on 5 October the technical report for textGrain, the watermark it will apply to ChatGPT text in the EU under Article 50 (article). A legal department can draw a simple requirement from this: ask each supplier what it publishes and what it keeps to itself. On internal risks, the Eurobarometer of 30 September gives an order of magnitude: 15% of European employees report AI-generated scams and only 48% say they can recognise a fake video (brief).

The editorial team's reading can be summed up in one sentence. Europe has the most written framework, but the month's centre of gravity has shifted towards incident management, which the AI Act addresses less directly than market placement.

On ActuIA's radar in October

Two files remain open. Bill No. 3149 tabled by LFI MPs on 15 September was referred to the Economic Affairs Committee, with no scheduling to date (article). In Brussels, the KIDS Act is beginning its journey through Parliament and the Council. Another deadline falls in November. The "child-protective AI" working group set up by High Commissioner Sarah El Haïry must deliver its proposals by the end of November, after two months of work (brief).

ActuIA will also follow the review of its agents' actions that OpenAI says it has been conducting since the Hugging Face incident and which will take months according to the company (brief). Same follow-up for the hearings of the Australian parliamentary committee, where Jason Kwon on 6 October called OpenAI's response "not good enough", according to the Australian Financial Review (brief). The editorial team will likewise monitor the possible publication of a founding act for the Super Intelligence Force. The next monthly update will appear in early November.

Our articles will then appear first in Google Top Stories.