Weekly AI Governance Brief: 28 September–4 October 2026

Share

Bringing you the latest developments in the AI governance world.

Canada turns frontier-AI cyber risk into operational security requirements

On 1 October, Canada's government brought into effect a new Security Policy Implementation Notice addressing federal cybersecurity readiness in what it describes as the frontier-AI era.

The direction is based on existing federal security and digital-policy requirements but establishes a more specific operational response to AI-enabled threats. It identifies autonomous vulnerability discovery, generation of zero-day exploits, and orchestration of multistage cyberattacks as capabilities that advanced AI systems can enable.

Federal departments and agencies are consequently directed to identify critical services and maintain current inventories of the applications and infrastructure supporting them. For department-developed software supporting critical services, the direction calls for maintenance of software bills of materials to improve visibility into supply-chain dependencies.

Vulnerability management is another focus. Departments must use risk-based patching processes, prioritise critical and internet-facing systems, and use compensating controls where remediation cannot occur quickly enough. The direction also permits defensive AI tools to be used to identify vulnerabilities and review software code for security weaknesses.

The identity-management provisions extend explicitly to AI agents. Non-person entities, including machine identities and AI agents, are expected to have documented owners and business purposes, lifecycle management and regular privilege reviews. Persistent access and static credentials should be minimised.

The direction also requires stronger logging, network segmentation and incident-response preparation. Departments must operate from an “assume breach” position intended to limit lateral movement and the potential impact of AI-enabled attacks.

Why this matters

Canada's direction is notable because it moves frontier-AI cybersecurity from general risk recognition into operational government requirements.

It also illustrates how AI governance can be implemented through existing cybersecurity frameworks rather than a dedicated AI statute. The underlying security obligations remain grounded in federal government policy, while the new direction changes how those obligations should be prioritised in light of AI-enabled threats.

The treatment of AI agents is particularly relevant. By placing agents within machine-identity governance, the direction connects emerging autonomous systems with established controls around ownership, credentials and access privileges.

White House initiates a change to the federal definition of AI

On 29 September, the White House issued Executive Order 14434, Inaugurating the Era of Super Intelligence.

The order directs federal executive departments and agencies to replace the terms “Artificial Intelligence” and “AI” with “Super Intelligence” and “SI” in official correspondence, public communications, websites, reports and other non-statutory materials.

For current implementation, however, the terminology change does not create a new substantive legal definition. The order states that “Super Intelligence” continues to mean technologies falling within the existing statutory definition of artificial intelligence under 15 U.S.C. § 9401(3).

The more consequential provision concerns what happens next. Within 60 days, the Assistant to the President for Science and Technology must submit proposed legislative language establishing a federal definition of Super Intelligence.

That exercise must examine whether the new definition should modify, expand, or supersede the existing statutory AI definition. It must also identify potential amendments to existing statutory references and recommend additional executive action where necessary.

The order expressly states that previously issued regulations, presidential actions, contracts and grants do not need to be altered merely because of the terminology change.

Why this matters

For organisations subject to U.S. federal requirements, the immediate terminology change should be distinguished from a change in legal scope.

Existing statutory definitions remain operative. The governance significance lies instead in the formal process now underway to develop replacement legislative language.

Definitions determine which technologies fall within regulatory obligations. A future change to the statutory definition could therefore affect the perimeter of AI-related federal rules even though the current Executive Order does not itself produce that result.

Florida asks court to impose third-party controls on OpenAI development

On 28 September, Florida Attorney General James Uthmeier escalated the state's existing litigation against OpenAI and CEO Sam Altman by filing a motion for a temporary injunction.

Florida's underlying civil case was filed in June and alleges that OpenAI engaged in deceptive practices and failed adequately to address risks associated with ChatGPT. Those allegations remain disputed and have not been established as findings by the court.

The new motion seeks substantially more intrusive interim controls.

Among the requested measures is an order preventing OpenAI from developing new AI models without independent third-party safeguards and approval while the litigation continues. Florida also seeks restrictions concerning access to ChatGPT by minors, collection of children's data, and representations concerning the system's safety and reliability.

The state is therefore asking the court to intervene not only in how an AI product is marketed or operated, but also in the governance process surrounding development of future models.

The requested measures are not currently binding on OpenAI. They are proposals before the court, which has not granted the temporary injunction.

Why this matters

The motion provides an unusually direct example of conventional consumer-protection litigation being used to seek controls over frontier-model development.

Independent AI evaluation has appeared elsewhere as a legislative or voluntary governance mechanism. Florida's motion takes a different route by asking a court to make third-party oversight a condition of continued model development while litigation is pending.

The distinction between the request and an actual court order is important. At this stage, the development signals an attempted expansion of enforcement remedies into AI-development governance rather than an established compliance obligation.

Looking ahead

The developments of 28 September–4 October show AI governance intersecting with established institutional frameworks in different ways.

Canada has incorporated frontier-AI threats into government cybersecurity controls, including explicit requirements concerning AI-agent identities. The U.S. Executive Order begins a federal process around the terminology and statutory definition of AI, while Florida's litigation tests whether consumer-protection enforcement can support direct judicial oversight of model-development safeguards.

The common feature is institutional adaptation. Rather than relying exclusively on comprehensive AI legislation, governments are applying cybersecurity policy, executive authority, and existing enforcement mechanisms to increasingly specific questions about advanced AI systems.

Sources

Government of Canada direction on cybersecurity readiness in the frontier-AI era: canada.ca

White House Executive Order 14434, Inaugurating the Era of Super Intelligence: whitehouse.gov

Florida Attorney General announcement establishing the underlying enforcement case against OpenAI: myfloridalegal.com

Read more