Welcome to HSF Kramer's September 2026 summary of top picks for cyber-related news in the UK, EMEA and US.
In a world overflowing with individual incidents and long-form analysis, our short articles are aimed at cutting through the noise, pointing you to key developments, providing you with learning points at a glance and signposting you to longer form content. If you would like to find out more, do reach out to one of our international team.
UK updates:
FCA publishes guidance on disclosing inside information relating to cyber incidents
UK Financial Conduct Authority – 30 September 2026
In Section 9 of the latest Primary Market Bulletin 66, the FCA provides guidance on when an issuer should disclose inside information relating to cyber incidents. Among other things, the FCA notes that not every cyber incident will be inside information and issuers need to assess case-by-case whether information about a cyber incident fulfils the criteria defining inside information in Article 7 of the UK Market Abuse Regulation (UK MAR). The issuer should consider the scale and nature of the incident (for example, whether sensitive client/customer or commercial data has been compromised), reputational impact, and any immediate or anticipated disruption to the issuer’s operations or financial position. If the definition of inside information is met, then the issuer must disclose the information to the public as soon as possible unless it is comfortable it can delay disclosure of that information in accordance with the UK MAR.
Ofcom launches engagement on the role of AI in cyber defence
UK Office of Communications – 15 September 2026
Ofcom plans to carry out a series of discussions with industry participants, technical experts and vendors in the UK’s telecommunications and digital infrastructure sectors during autumn 2026. The aim is to explore both the opportunities and challenges associated with AI-enabled cyber security tools, including questions around trust, assurance, accountability and compliance with existing cyber security requirements. Insights from this engagement will inform Ofcom’s understanding of how emerging AI technologies interact with existing cyber security principles and regulatory requirements. Ofcom expects to publish its findings in early 2027.
EMEA updates:
Three in four EU employees faced cyber threats at work, new Eurobarometer finds
European Commission – 30 September 2026
According to a new Eurobarometer survey published by the European Commission, three in four EU employees reported they had come across suspicious emails, messages or links at work. Phishing or fraudulent emails remain the most common threat, while attempts to steal personal data and malware attacks are also commonly reported. The rise of AI-enabled cyber threats poses new challenges: even though 72% of employees are confident spotting suspicious emails, only 48% say they could identify an AI-generated fake video. It is said that the survey highlights a gap between awareness and everyday practice.
Spain gets its first taste of AI-aided cyber attack
The Register – 16 September 2026
Spain’s data protection agency (AEPD) has reported the first AI-aided cyberattack incident in the country, where an individual deployed an AI agent that used a “known large language model (LLM)” to conduct an attack on an organisation. The AI agent was said to have scanned “generic files” before accessing the organisation’s system, then ran vulnerability scans to identify flaws which would give it read/write access to files containing personal data and invoices. AEPD did not name the LLM used to support the attack nor the name of the organisation.
US updates:
Anthropic prevails on claims in the Northern District of California
HSF Kramer – 15 September 2026
A federal district court in California ruled that the U.S. government violated Anthropic’s free speech and due process rights when it labelled Anthropic a supply chain risk in response to Anthropic speaking out about AI policy and refusing to allow certain uses of its products for military purposes. The government may, however, appeal this decision. There is also another pending case in the U.S. Court of Appeals for the D.C. Circuit, where the court has denied Anthropic’s emergency motion to stay the supply chain risk designation, citing deference to military decisions during an active conflict with Iran.
OpenAI is sued over rogue AI Hugging Face cyberattack
CNBC – 30 September 2026
A suit was filed against OpenAI by a non-profit organisation called Legal Advocates for Safe Science and Technology (LASST) in the San Francisco Superior Court in relation to the Hugging Face cyberattack. In its complaint filed with the court, LASST argues that OpenAI has caused harm to LASST by requiring it to divert resources from its normal activities to educate regulators, civil society and the public about potential dangers of OpenAI's conduct relating to its hack of Hugging Face. LASST further suggests that OpenAI has "knowingly and without permission accessed or caused to be accessed” Hugging Face’s computers, computer systems, or computer networks, thereby violating § 502(c)(2) of the California Penal Code. In response to the filing, an OpenAI spokesperson commented that OpenAI has taken a series of actions in response to the Hugging Face incident, and that this lawsuit is “completely without merit”.
General updates:
Data Center Cyber Risk Is Increasing And Underrecognized
S&P Global – 24 September 2026
In an article published by S&P Global (see also Reinsurance News), the author suggests that a cyberattack affecting a significant data centre operator and its facilities has the potential to weigh on the credit quality of data centre customers, and is therefore an increasing and underrecognised source of risk. The author observes that data centres have become increasingly important to cloud computing, AI, financial services, healthcare, telecommunications and government operations. As more critical workloads are concentrated within larger data centre facilities and among fewer providers, the implications of a successful cyberattack could extend across multiple customers and sectors. The article concludes that organisations should strengthen resilience through measures such as network segmentation, multi-factor authentication, software patching, and better staff training.
Anthropic discloses fourth AI hacking incident missed in earlier review
Reuters – 9 September 2026
Anthropic reported a fourth cybersecurity incident with an early version of Claude Opus 4.6, which hacked external systems during testing in January 2026 and went undetected until recently. Upon investigation, Anthropic has identified two recurring problems: (1) biased reasoning, in which Claude discounted or misinterpreted evidence that it was operating on the live internet; and (2) recklessness, or a willingness to take potentially harmful actions in order to complete a task. Anthropic has engaged an independent research firm to investigate the incidents.
Key contacts
Andrew Moir
Partner, Intellectual Property and Head of Cyber Security and Data, London
Peter Dalton
Partner, London
Miriam Everett
Partner, London
Austin Manes
Special Counsel, Privacy Counsel, Silicon Valley
Disclaimer
The articles published on this website, current at the dates of publication set out above, are for reference purposes only. They do not constitute legal advice and should not be relied upon as such. Specific legal advice about your specific circumstances should always be sought separately before taking any action.