AI Security Weekly
Issue #14 — June 2026
What the Underwriting File for High-Risk AI Actually Contains
Once Article 50 documentation exists, the treaty market and the conformity auditor are asking the same form to be filled out: conformity narrative, post-market monitoring outputs, incident classifications, defensive-AI disclosure. This week assembles the line items in one place and walks AIRS through how each one maps to the file a syndicate will price against.
JetBrains and the Credential Boundary; Copilot SearchLeak and the One-Click Exfiltration Class
The JetBrains 15-plugin AI-credential exfiltration campaign and the M365 Copilot SearchLeak prompt-injection chain together describe how a high-risk AI file has to carry both credential-scope discipline and runtime containment evidence. The Splunk KEV-relevant CVE on the same week makes operational vulnerabilities the supporting documentation, not a separate disclosure.
Article 50 Re-Pegged to December 2027 — Market Index W25 and the v3.1 Methodology Release
The EU AI Act applicability shift extends the conformity runway without retiring the file. Market Index W25: 37.9 ↑ +0.2 — the first composite movement since W18. The v3.1 EWMA methodology shipped this week (α=0.3, 8-week rolling window), W22 backfilled, rounding bug retired. Signals named in public copy: VSS 55.1, TSS 49.8, AIRS 38.9.