All Issues

Issue #16 — July 2026

The Sixteen-Month Asymmetry

On June 29, 2026 the Council of the EU formally adopted the Digital Omnibus on AI. August 2, 2026 stands as the live date for the market surveillance authorities, Article 50 transparency, Article 4 AI-literacy compliance, and GPAI penalties. Standalone Annex III applicability stands at December 2, 2027. Sixteen months separate the two — and the authorities will spend that window reading evidence.

Published July 6, 2026 12 min read 7 Sections ASI Market Index W27 38.5 ↑ +0.9

On June 29, 2026, the Council of the European Union formally adopted the Digital Omnibus on AI, six days before this issue went to press. The legislative act amends Regulation (EU) 2024/1689 — the AI Act — and enters into force three days after publication in the Official Journal.12 The single most consequential provision: standalone Annex III high-risk system obligations move from August 2, 2026 to December 2, 2027, and Annex I embedded high-risk obligations move from August 2, 2027 to August 2, 2028.3 What did not move: Article 50 transparency obligations, Article 4 AI-literacy compliance, GPAI penalties, the full penalty regime, and market surveillance authority stand-up all apply from August 2, 2026 exactly as originally scheduled.13 The result is a 16-month span in which the collection and enforcement machinery is live and the specific standalone-Annex-III conformity obligations it will eventually apply against are not. That span is the surveillance window. On the US side, Rep. Nathaniel Moran’s AI Incident Reporting Act would build a parallel scaffold: frontier-model developers reporting dangerous capabilities, breaches including model-weight theft, and safety incidents to the Secretary of Commerce within seven days, with 48-hour congressional notification for the most serious incidents.4 Neither regime is enforcement yet. Both are discovery.

The distinction matters because discovery precedes enforcement by design, not by accident. A market surveillance authority that spends 16 months building capacity, deciding methodology, and reading whatever gets filed voluntarily is not idle during that period — it is forming the priors it will apply the day the standalone high-risk obligations actually bite. Deployers who treat the gap between August 2026 and December 2027 as dead time are making a category error. The authorities are watching now. The obligations start later. What gets read in between shapes what gets enforced after.

“Market surveillance is not enforcement, but market surveillance is discovery. The 16 months between August 2, 2026 and December 2, 2027 are when the surveillance authorities decide what the enforcement will look like.”

— ASI Intelligence Team observation, W27 2026

This edition examines what the Council-adopted Digital Omnibus locked and what it did not, what August 2, 2026 becomes now that the framework is legally certain, what the market surveillance authorities can request during the sixteen-month window that opens on that date, what the W27 reading at 38.5 (up 0.9) registers under the v3.1 methodology and why the deterministic ranker landed on the same regulatory pulse the horizon card was built around, how the June KEV cluster forms a concrete boundary-breach payload landing directly into the window, what the TeamPCP, jupyterlab-git, DuneSlide, and Perplexity-impersonation cluster reveals about the developer surface the authorities will read alongside the enterprise cluster, why the voluntary conformity file functions as the market’s first post-market monitoring output even though nothing requires it yet, and the five moves worth making before August 2, 2026 arrives.

The Council Adoption on June 29 and What August 2 Becomes

01

What the Council Locked on June 29, 2026

On June 29, 2026 the Council of the European Union formally adopted the Digital Omnibus on AI, the amendment package that had been under negotiation since the Commission tabled it in late 2025 and that the European Parliament voted through on June 16, 2026. The Council adoption closed the co-decision procedure. What remains is publication in the Official Journal and entry into force three days after. The framework is no longer a moving target: it is Council-adopted law awaiting publication.12 The Digital Omnibus made two structural moves inside the AI Act calendar. The first: it left August 2, 2026 in place as the date the market surveillance authorities become operational, the date Article 50 transparency obligations bind on providers and deployers of certain AI systems, the date Article 4 AI-literacy duties become compliance-relevant, and the date the full penalty regime attaches to General-Purpose AI obligations. The second: it postponed standalone Annex III high-risk applicability from August 2, 2026 to December 2, 2027, and Annex I embedded high-risk from August 2, 2027 to August 2, 2028.34

02

The Sixteen-Month Asymmetry That Follows

Read those two moves together and one number falls out. The market surveillance authorities are operational on August 2, 2026. Standalone Annex III applicability begins December 2, 2027. Sixteen months separate the date the authorities go live from the date the primary obligation they will eventually enforce becomes legally applicable. The authorities empowered to collect evidence are live sixteen months before the rules they will eventually apply that evidence against.3 This is not a re-peg in either direction — the anchor dates are Council-locked at both ends of the window. It is an asymmetry in what the authorities can do inside it. They will not spend those sixteen months doing nothing. They will spend them building capacity, settling on methodology, coordinating across member states, and reading whatever the market gives them — including the voluntary early submissions that arrive before anyone is required to file.

What the Market Surveillance Authorities Are Actually Looking At

03

Collection, Not Enforcement

Market surveillance is a distinct function from enforcement, and the distinction is the entire shape of the surveillance window. An operational market surveillance authority can request technical documentation, post-market monitoring outputs, incident reports, and conformity evidence from any actor in scope. It can open inquiries, request corrections, and coordinate with other member-state authorities. What it cannot do — because the underlying Annex III obligations do not apply yet — is penalize a deployer for failing to have produced a compliant high-risk file by August 2026. The authority is a collection layer operating sixteen months ahead of the enforcement layer it will eventually feed.

04

Reading for Patterns, Not Violations

During the August 2026 to December 2027 window, the question a market surveillance authority is positioned to answer is not "who is out of compliance" — nobody is, yet, on the Annex III standalone track. The question is "what does the market look like." Which deployers file a voluntary conformity narrative before they are required to. What those voluntary files actually contain. How the harmonised standards get anchored against in practice versus in theory, once real submissions exist to compare against the standards text. The voluntary conformity file becomes, functionally, the surveillance authority’s dataset for the intervening period — the only systematic evidence of market behavior available before the mandatory-filing population exists.

The W27 Reading Under v3.1 — The Reading Names the Theme

05

38.5, Up 0.9 from W26 — The Largest Single-Week Motion Under v3.1

The ASI Market Index reads 38.5 for Week 27, up 0.9 from W26’s 37.6. This is the third natural reading under the v3.1 methodology since it shipped at W25 — W25 moved +0.2, W26 moved −0.3, and W27’s +0.9 is the largest single-week composite motion the new aggregation scheme has produced to date. The public-signal readings for W27: VSS 55.1, TSS 51.5, AIRS 38.8. VSS holds flat against W26 — part of that flatness is itself a fidelity story, addressed directly below in the KEV discussion. TSS moves +3.1, the largest per-signal motion of the week, consistent with the supply-chain compromise cluster documented in this week’s sweep. AIRS is essentially flat, down 0.1. Signal of the Week: the regulatory-pulse reading, selected by the deterministic ranker at a score of 1.4375 on the Council-adopted Digital Omnibus cluster — the highest-coherence reading of the week by a wide margin.

The narrative alignment here is worth naming directly. This issue’s horizon card was drafted four weeks ago, before this week’s sweep existed and before the Council’s June 29 adoption formally closed the co-decision procedure. The deterministic Signal-of-the-Week ranker, running independently against this week’s public-record inputs with no awareness of the horizon card, landed on the same regulatory pulse: the Council-adopted Digital Omnibus cluster, scored highest of the week’s candidates. The reading did not need to be told what the theme was. It arrived at the same place the editorial calendar had already committed to — and the Council’s adoption on June 29 turned what had been a horizon read into a settled legal fact. That is the rare week where the horizon, the reading, and the legislative timetable converge. The full index page carries the W27 audit and the v3.1 methodology disclosure.

The KEV Adds: A Boundary-Breach Payload Landing Into the Sixteen-Month Window

06

Four Boundary Components, One June Batch

June 2026’s Known Exploited Vulnerabilities cluster names four components with a shared architectural role: they sit at a boundary. CVE-2026-48558 is an authentication bypass in SimpleHelp remote-monitoring-and-management software, under active exploitation for credential theft and malware delivery.56 CVE-2026-45659 is a deserialization remote-code-execution flaw in Microsoft SharePoint Server, exploitable by a low-privilege authenticated user.78 CVE-2026-8037 is an unauthenticated OS command-injection flaw in Progress Kemp LoadMaster, an edge load-balancing appliance; a public proof-of-concept landed on June 29 and eSentire’s Threat Response Unit observed active exploitation attempts the same day.910 And CVE-2026-11645 is an actively-exploited, now-patched out-of-bounds flaw in Chrome’s V8 engine.11 Remote support tooling, a collaboration server, an edge appliance, a browser: four different product categories, one common trait. Each is a boundary component a post-market monitoring output would have to name specifically, not describe in the aggregate, and each is the kind of entry the market surveillance authorities operational on August 2 will expect to see enumerated in the evidence a deployer produces during the sixteen-month window.

07

The Payload Landing Into the Window, and the Feed That Missed It

Frame this cluster as the concrete VSS payload landing directly into the sixteen-month window opening on August 2: these are exactly the boundary-exposure entries a market surveillance authority will expect a post-market monitoring output to enumerate once the obligation exists, and exactly the entries a reinsurance treaty desk will ask about well before that. There is a fidelity problem sitting underneath all four, though. The public CISA KEV JSON feed, as read during this week’s sweep, reports catalogVersion 2025.09.30 — a version stamp that predates the entire 2026 KEV year and does not reflect any of the four additions named above.12 A surveillance regime that depends on that feed being current is, by construction, working from a stale baseline. The staleness is not a footnote to the vulnerability story. It is itself a surveillance-quality signal: a monitoring program that reads the mirror instead of the canonical source will miss precisely the entries this section names, on a timeline it cannot predict in advance.

The Developer Surface: TeamPCP, jupyterlab-git, DuneSlide, and Impersonation

08

Four Compromise Classes on the Developer Side

Where the KEV cluster above covers the enterprise boundary, this section covers the developer boundary — a surface the market surveillance authorities will read alongside the KEV cluster, not instead of it. The TeamPCP supply-chain compromise cluster targets developer and security tooling directly. The FBI issued a July 2, 2026 advisory naming TeamPCP as a cyber-criminal group behind a self-propagating campaign against npm and GitHub Actions ecosystems, with mitigation guidance converging on pinning workflows to verified commit SHAs, rotating CI/CD secrets, and enforcing least-privilege on publishing tokens.13 A stored cross-site-scripting flaw in jupyterlab-git — unsanitized innerHTML rendering in its PlainTextDiff.ts component — gives an attacker a path from a crafted diff view to remote code execution inside an analyst-facing interface.14 A malicious npm package, grafana-lokiexplore-app version 90.99.99 (OSV ID MAL-2025-5612), warrants a full-compromise assumption and secret rotation for anyone who installed it.15

09

DuneSlide and the Prompt-Layer Bridge, Plus the Impersonation Class

The Cursor AI IDE’s “DuneSlide” vulnerabilities — CVE-2026-50548 and CVE-2026-50549, both rated CVSS 9.8 by Cato AI Labs and disclosed on July 1, 2026 — chain a prompt-injection vector into a sandbox escape and ultimately remote code execution; both are fixed in Cursor 3.0, released April 2, 2026.1617 DuneSlide is the clearest example this quarter of the LLM prompt layer functioning as a bridge into host execution rather than a contained interaction surface, and it is precisely the kind of vulnerability class a harmonised standard has no existing vocabulary for yet. Finally, a Chrome extension impersonating Perplexity — distributed as “Search for perplexity ai” under extension ID flkebkiofojicogddingbdmcmkpbplcd — routed user searches to perplexity-ai[.]online before redirecting to genuine results. Microsoft Threat Intelligence disclosed the extension on June 29, 2026 and Google removed it from the Chrome Web Store following that responsible disclosure.18 AI-brand impersonation is not an isolated incident; it is now a durable threat class, and the surveillance authorities reading the developer surface alongside the enterprise KEV cluster will need to account for both the enterprise stack and the developer stack in the same monitoring output.

The Voluntary Conformity File as the Market’s First Post-Market Monitoring Output

10

Not Required Until 2027, Read Starting Now

Nothing in the Annex III standalone track requires a conformity file from any deployer until December 2, 2027. But the deployers who produce one voluntarily during the intervening window are creating the only corpus that exists for the market surveillance authorities to read during the gap — and, separately, the corpus the reinsurance treaty market will read at the January 2027 renewal. The two readers converge on the same artifact for different reasons: one is testing methodology ahead of enforcement, the other is pricing aggregate AI-related exposure to loss ahead of a binding cycle. Both are reading a document nobody is required to produce yet.

11

Procurement Is Where the File Becomes a Market Signal

The intersection that turns the voluntary file from a compliance placeholder into something with present-tense value is procurement. Enterprise buyers already ask for conformity narrative inside RFPs, well ahead of any legal requirement to produce one. During the sixteen-month window that opens on August 2, 2026, the voluntary file is not a compliance artifact — it is a market signal, the same way an early SOC 2 report functioned as a market signal years before any buyer required it contractually. The AIRS standard’s conformance language is the discipline the voluntary file borrows most directly; this is a case where naming AIRS is appropriate because the reference is to the standard’s own conformance vocabulary, not to editorial commentary attributed to it. Issue #17’s horizon card, “The Voluntary Conformity File,” will treat this artifact at length; this issue registers the mechanism. The urgency is not merely regulatory. A UN independent panel warned this week that AI capabilities are outpacing scientific understanding, with task complexity in agentic systems doubling every four to seven months — a systemic-risk backdrop that makes the voluntary file less an act of anticipatory compliance and more a hedge against a capability curve regulators are themselves struggling to track.19

The Bottom Line — Five Moves Before August 2, 2026

Watchlist — Preparing for the Sixteen-Month Window Before It Opens

July 6, 2026
01

Enumerate the boundary exposure the June KEV cluster names

Every KEV entry in the June 2026 batch — CVE-2026-48558, CVE-2026-45659, CVE-2026-8037, CVE-2026-11645 — that intersects the stack gets a remediation date, a residual-exposure window, and a monitoring cadence. This is what the market surveillance authority will ask for after August 2, and what the reinsurance treaty desk will ask for before January.5

02

Draft the voluntary conformity file now

Not because December 2, 2027 requires it. Because the sixteen months between August 2, 2026 and December 2, 2027 are the window in which the file becomes a competitive procurement signal, and because a treaty submission that includes it in autumn 2026 is a different underwriting artifact than one that doesn’t.

03

Instrument post-market monitoring outputs against the four AI-adjacent CVE classes of 2026

The prompt-injection-to-RCE class (DuneSlide). The developer-toolchain compromise class (TeamPCP). The analyst-UI compromise class (jupyterlab-git). The AI-brand impersonation class (the Perplexity-impersonating extension). A monitoring pipeline that names these classes and produces evidence at cadence is the shape the harmonised standards will eventually converge on. Building it now positions ahead of the standard rather than behind it.16

04

Read the CISA KEV feed directly, not through cached mirrors

The public JSON feed showed catalogVersion 2025.09.30 during the July 6 sweep. A surveillance program that depends on catalog-mirror freshness is going to miss the June batch by a variable delta. Pull KEV directly, on cadence, and treat any feed-staleness reading as a monitoring incident of its own.12

05

Anchor the AI-risk section of the autumn treaty submission against standards that will still be current at December 2, 2027

The AI Act standardisation page is a moving target. A submission that anchors to a standard that will still be in force at applicability is a submission that ages well across the sixteen-month window. A submission that anchors to a standard that gets superseded before December 2, 2027 is a submission the treaty desk has to re-price at renewal.1

Subscribe for Weekly Intelligence

Every Monday. The AI security developments that shape enterprise risk, insurance, and governance — curated by our intelligence team.

Subscribe Free

Read Issue #15: The Reinsurance Treaty Cycle Meets AI

Sources

European Commission — "Regulatory framework for artificial intelligence", 2026.

Addleshaw Goddard — "EU AI Act: AI Omnibus Formally Adopted", 2026.

Gibson Dunn — "EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes", 2026.

Rep. Nathaniel Moran — "AI Incident Reporting Act" press release, 2026.

Canadian Centre for Cyber Security — Advisory AV26-642, "SimpleHelp Security Advisory", 2026. CVE-2026-48558 authentication-bypass, active exploitation.

Arctic Wolf Labs — "CVE-2026-48558: Critical Authentication Bypass Vulnerability in SimpleHelp RMM Exploited for Credential Theft and Malware Delivery", 2026.

National Vulnerability Database — CVE-2026-45659, 2026. Microsoft SharePoint Server deserialization RCE, KEV-listed.

Canadian Centre for Cyber Security — Alert AL26-015, "Critical Vulnerability Impacting Microsoft SharePoint Server (CVE-2026-45659)", 2026.

Trend Micro Zero Day Initiative — ZDI-26-341, 2026. Progress Kemp LoadMaster command-injection, CVE-2026-8037.

eSentire Threat Response Unit — "Progress Kemp LoadMaster Vulnerability Targeted (CVE-2026-8037)", 2026.

Google Chrome Releases blog — "Stable Channel Update for Desktop", June 2026. Actively-exploited V8 out-of-bounds, CVE-2026-11645.

CISA Known Exploited Vulnerabilities JSON feed, 2026. Read July 6, 2026 at catalogVersion 2025.09.30.

FBI Internet Crime Complaint Center — Cybersecurity Advisory CSA 260702, 2026. "TeamPCP" supply-chain compromise campaign.

GitLab Advisory Database — jupyterlab-git-core, 2026. Stored XSS via PlainTextDiff.ts innerHTML rendering.

Open Source Vulnerabilities database — MAL-2025-5612, 2026. Malicious npm package grafana-lokiexplore-app 90.99.99.

National Vulnerability Database — CVE-2026-50548, 2026. Cursor AI IDE "DuneSlide" prompt-injection to RCE chain.

Cato Networks — "DuneSlide: Two Critical RCE Vulnerabilities", 2026.

Microsoft Security Blog — "Chromium extension uses AI-related branding to redirect browser search", June 29, 2026.

Reuters — "Unchecked AI progress may pose catastrophic risks, UN panel warns", July 1, 2026.