AI Governance Weekly - August 27, 2026
Source
AI Governance Institute
This Week in One Minute
A five-agency advisory confirms AI is actively lowering the technical bar for attacks on US critical infrastructure, while MCP infrastructure has a systemic authentication crisis, with 91.8% of audited servers lacking OAuth controls.
Bottom Line: Patch MCP infrastructure and map OCC Bulletin 2026-13 to existing model risk controls now.
Action Brief
✅ Act This Sprint
- MCP Server OAuth Audit: Inventory all MCP server deployments against the DeepInspect finding that 91.8% lack OAuth and assign remediation owners for any endpoints missing OAuth or equivalent authentication controls by September 10.
- CVE-2026-27825 Patch Verification: Confirm that all Atlassian MCP deployments have been upgraded to version 0.17.0 or later, as Check Point's disclosure of this arbitrary file write vulnerability creates a clear path to full server compromise.
- Context7 MCP Isolation: Quarantine or disable Context7 versions through 2.1.2 pending vendor action on CVE-2026-75130, a CVSS 9.0 prompt injection flaw with no documented fix, and document the interim compensating control.
- AI Hiring Framework Gap Analysis: Compare current AI-assisted hiring controls against the FPF and HR tech consortium risk assessment standard, noting any gaps in non-discrimination testing or human oversight documentation, before the next scheduled employment practice review.
🔍 Monitor
- California SB 53 Expansion: Track legislative developments on OpenAI's push to strengthen SB 53 and the California foundation model safety protocol; escalate to action if mandatory monitoring or pre-deployment evaluation requirements are codified, as both would create new enterprise obligations.
- NIST SP 1353 Comment Period: Watch for stakeholder responses and any NIST revisions to the SP 1353 draft on AI-assisted cybersecurity workflows, with the October 15 comment deadline as the trigger to assess whether your AI-assisted security tooling meets the emerging documentation standard.
- SEC AI Investment Scrutiny: Monitor the SEC subpoena activity around Situational Awareness for signals that the agency is developing disclosure or concentration-risk expectations beyond the hedge fund context, which would affect enterprise AI investment reporting.
📋 Program Updates
- MCP Server Vendor Intake Controls: Extend your third-party vendor intake checklist to require OAuth implementation, Origin header validation, and sandboxing attestation for all MCP servers, grounded in this week's cluster of disclosures including CVE-2026-75130, CVE-2026-65105, and the DeepInspect OAuth audit.
- AI Package and Dependency Review Policy: Add a slopsquatting verification step to your software supply chain controls, requiring human confirmation of AI-recommended package names against authoritative registries before installation, prompted by the Softjourn near-miss incident.
- OCC Model Risk Management Alignment: Review your model inventory, validation cadence, and governance structures against the updated OCC Bulletin 2026-13, which extends supervisory expectations to AI and machine learning models across the full lifecycle at national banks and federal savings associations.
- Autonomous Agent Acceptable Use Policy: Update acceptable use guidance to explicitly address autonomous messaging and email-sending capabilities, citing OpenAI's ChatGPT Apple Messages plug-in warning against persistent approval and the Instinct agent's documented unauthorized email behavior as the risk basis.
🏆 Top Story
91.8% of Audited MCP Servers Lack OAuth, Audit Finds
A DeepInspect security audit found that 91.8 percent of MCP servers examined were operating without OAuth or equivalent authentication controls. The finding exposes a systemic identity and authorization gap across enterprise agent toolchains. Organizations deploying MCP-connected agents face elevated risk of unauthorized tool invocation and lateral movement by malicious actors.
📰 Also This Week
- Binance Agent OS Shifts Autonomous Trading Risk Onto Users — Binance has launched Agent OS, a platform that allows AI agents to analyze markets and execute trades autonomously on behalf of users.
- Critical MCP Atlassian Flaw Enables Arbitrary File Write and Code Execution — Check Point disclosed CVE-2026-27825, a high-severity arbitrary file write vulnerability in MCP Atlassian versions before 0.17.0.
- CVE-2025-9141 Makes Inference Engines a Governed Security Dependency — Independent security research published in August 2026 documents a concrete attack class in which a malicious LLM could exploit vulnerabilities in its own inference engine to execute arbitrary code on the host machine.
- CVE-2026-65105 Lets Attackers Poison NemoClaw's AI Through a Browser Tab — Researchers at Cyera disclosed CVE-2026-65105, a DNS rebinding vulnerability in Nvidia's NemoClaw that allows an unauthenticated attacker to access a local Ollama model server from a malicious browser tab.
🔎 What Matters
- A five-agency advisory confirms AI is actively lowering the technical bar for attacks on US critical infrastructure. NSA, CISA, FBI, EPA, and DOE jointly warned that threat actors are using AI to generate exploitation scripts targeting Siemens PLCs across energy, water, food, and manufacturing sectors.
- MCP infrastructure has a systemic authentication crisis, with 91.8% of audited servers lacking OAuth controls. A DeepInspect audit documented the gap alongside an unpatched CVSS 9.0 prompt injection flaw in Context7 and a high-severity arbitrary file write vulnerability in MCP Atlassian, collectively putting every enterprise agent toolchain at elevated risk.
- The OCC has revised its model risk management guidance to cover AI and machine learning across the full model lifecycle. The updated Bulletin 2026-13 sets new supervisory expectations for national banks and federal savings associations on development, validation, deployment, monitoring, and governance.
🎯 Model Radar Updates
Claude 3.7 Sonnet — Use with Caution Claude shared chats containing sensitive personal and health data were indexed by Google, creating an unresolved data exposure concern for enterprise deployments. Until Anthropic confirms remediation and revised data handling controls, the model cannot retain a GREEN designation.
Claude Opus 5 — Use with Caution Anthropic launched Claude Opus 5 with a significantly reduced safety classifier engagement profile compared to prior Claude models. The model operates under a separate data retention regime that diverges from existing Anthropic model policies, creating compliance uncertainty for enterprise deployments.
Gemini 3.7 Flash — Use with Caution Google DeepMind released Gemini 3.7 Flash with updated CBRN safeguards. The model ships with an always-on Gemini Spark agent component that introduces unresolved human oversight gaps. Enterprise deployments face elevated risk from the agentic capabilities included in this release.
Nano Banana 2 — Restricted Google DeepMind's Nano Banana 2 image model was deployed in Google Earth and subsequently withdrawn after researchers demonstrated it could generate geopolitically sensitive fabricated satellite imagery. The model is no longer publicly accessible following the withdrawal.
Muse Glimmer — Use with Caution Meta released Muse Glimmer under the Apache 2.0 license, signaling a strategic shift toward open-weight AI. An imminent open-source release of Muse Spark 1.2 was also announced. The open release raises unresolved distillation and model intake policy concerns for enterprise users.
📁 New in the Directory
OCC Model Risk Management: Revised Guidance (Bulletin 2026-13) (August 24) This bulletin updates the OCC's supervisory expectations for model risk management at national banks and federal savings associations. It addresses the full model lifecycle, covering development, validation, deployment, monitoring, and governance structures.
Edited by the AI Governance Institute team.
