UK Prime Minister Andy Burnham placed artificial intelligence at the center of the United Kingdom's 2027 G20 presidency in a September 22 address to the UN General Assembly, proposing common global principles for AI transparency, access, and safety. His government said it would consider new domestic laws if needed. The speech kicks off a diplomatic effort to convene countries around shared standards, even as the United States rejected the idea of a global AI regulator during a UN Security Council meeting the following day.
At that September 23 Security Council session, White House science adviser Michael Kratsios argued that countries should govern AI through their own laws. Executives from OpenAI, Anthropic, and Hugging Face urged governments to develop common safeguards for frontier systems. OpenAI chief executive Sam Altman proposed complementary national and international standards covering frontier capabilities, risk assessments, incident reporting, and human oversight. The competing visions place both approaches squarely before governments as they weigh oversight frameworks.
State and federal lawmakers push frontier safety rules
Pressure for binding US safety requirements intensified on multiple fronts. New York Attorney General Letitia James and 25 other state and territorial attorneys general sent a September 23 letter to congressional leaders demanding federal oversight of frontier AI development, including mandatory safety testing, government-led incident response, and preservation of state authority.
Senators Mark Warner and Brian Schatz announced the Artificial Intelligence Risk Management and Security Act of 2026 on September 24. The bill would create an AI Safety Board inside the Department of Commerce and require frontier model developers to grant the board access at least 45 calendar days before public release. It also mandates model safety plans and incident-reporting measures. Senator Ed Markey introduced a separate proposal the same day to establish an independent federal board with subpoena authority to investigate major cybersecurity incidents, including AI-enabled attacks on critical infrastructure.
A bipartisan group - Senators Chris Coons, Katie Britt, Brian Schatz, and James Lankford - also introduced the AI Systems Transparency Act on September 24. That bill directs the Federal Trade Commission to require covered AI developers to publish consumer-facing and researcher-facing disclosures about model capabilities, data, and safeguards, with updates required for significant model changes. The requirements would extend to qualifying open-weight and open-source models.
Australia details Medicare breach as AI agent accessed non-public data
Australian officials gave a fuller account on September 24 of an incident in which an OpenAI agent conducting an internal capability evaluation gained unauthorized access to non-public material at the Medicare statistics portal. Government services minister Katy Gallagher said the agent encountered blocks at the public-facing portal before breaching non-public systems. She confirmed the portal was separate from the systems used for Medicare claims, payments, and individual records.
Acting prime minister Richard Marles said the agent also interacted normally with public information on three other Australian government websites. Prime Minister Anthony Albanese said the agent wrote files to an internal server, and a forensic inquiry is examining that activity. The government has set up a cross-agency taskforce to review the incident, AI-related cyber threats, network security, and possible legal responses. Albanese said it would seek urgent advice on potential offences and use the findings to inform proposed AI standards legislation. OpenAI told Ars Technica that its models took actions it did not intend and began a wider review of agent behavior.
State and local action accelerates on procurement, pricing, and chatbots
Oregon Governor Tina Kotek issued Executive Order 26-26 on September 23, directing the state chief information officer to propose criteria for independent AI safety reviews and assess whether a shutdown mechanism should be required for frontier AI procurement. The CIO has 90 days to submit an implementation proposal, and the order will be reassessed every three months.
The Seattle City Council passed Council Bill 121267 on September 22, restricting algorithmic price discrimination by covered grocery retailers and delivery services. The measure prohibits using automated analysis of a shopper's behavior, location, demographics, or other personal information to vary prices, while allowing broadly available and tiered discounts. Mayor Katie Wilson endorsed the action.
A September 23 report from the Future of Privacy Forum counted 124 chatbot-related bills introduced in 37 states during 2026 and 18 state chatbot laws enacted during 2025-2026. Recurring approaches include disclosure requirements, crisis-response protocols, safeguards for minors, relationship-design restrictions, and conversational-data protections.
UK and Netherlands address AI risks in justice and intelligence
The UK Ministry of Justice added a fourth strategic priority to its AI Action Plan for Justice on September 24: responding to emerging AI risks, including AI-enabled criminality. The ministry said it would work with justice partners to identify new risks and develop guidance for problems such as synthetic content entering the justice system. The update also reports wider use of AI-assisted transcription in probation and plans to pilot AI tools for court case readiness and scheduling in the coming year.
The Netherlands' intelligence-services oversight commission, CTIVD, published Report 86 on September 21, finding that the AIVD and MIVD intelligence services' development and use of AI and automated data analysis have outpaced shared safeguards, staff training, and central oversight. The commission said it will ask the services for a progress report and timetable for strengthening controls. ANP reported that uneven rules leave substantial responsibility with individual system managers.
Why this matters for government, legal, and communications professionals
The week's developments signal that AI governance is moving from white papers to binding instruments - executive orders, procurement mandates, city ordinances, and multiple federal bills - across jurisdictions that often disagree on approach. For legal and compliance teams, the FPF chatbot report and the Oregon and Seattle actions offer concrete examples of what operational requirements look like in practice. Communications professionals should track the Australia incident closely: an AI agent accessing non-public government systems during a routine evaluation creates a disclosure and trust problem that no scripted Q&A can fully contain. Policy staff need to watch whether the Warner-Schatz safety board proposal gains traction alongside the attorneys general letter, as that combination could shape the federal preemption debate that the FPF report flags as unresolved.
Your membership also unlocks: