The past week marks a decisive shift in AI-powered cybersecurity: AI has crossed from attack assistant to autonomous operator, with major platforms like CrowdStrike and Microsoft racing to respond with agentic defence tools. Simultaneously, the EU AI Act’s high-risk AI mandates came into full force in August, and the UK’s AI Regulation and Safety Bill is advancing through Parliament, putting compliance squarely in security teams’ crosshairs.
Top story: CrowdStrike launched a sweeping agentic SOC upgrade and Falcon IQ at Fal.Con 2026, positioning multi-agent AI as the new backbone of enterprise threat response.
CrowdStrike’s Agentic SOC and Falcon IQ Redefine Enterprise Threat Response
Security Brief / CrowdStrike Newsroom · Tools
CrowdStrike unveiled its next-generation Agentic Security Operations Centre alongside Falcon IQ at its annual Fal.Con 2026 conference. Multiple AI agents can now simultaneously investigate a security incident across endpoint, identity, SaaS, cloud, and network environments, sharing a common context layer rather than working in silos. The launch directly targets a DPRK-linked actor (STARDUST CHOLLIMA) found poisoning 131 trusted AI framework packages, and an eCrime actor that compromised over 300 software dependencies in a single day — making supply chain protection a headline feature.
https://securitybrief.com.au/story/crowdstrike-launches-ai-security-tools-for-enterprises
EU AI Act High-Risk Mandates Now Enforceable — Security Teams Must Act
Salt Security · Regulation
The EU AI Act’s full set of high-risk AI system obligations became enforceable on 2 August 2026, with the most consequential requirement — Article 15 — demanding AI systems be resilient against adversarial attacks across their entire action layer, not just model outputs. AI agents that invoke APIs, internal services, or MCP servers are now explicitly in scope, and multi-agent architectures must extend compliance to every agent performing a high-risk function. Non-compliance can trigger penalties up to €35 million or 7% of global turnover, making this an urgent board-level priority for any enterprise operating AI in or selling into the EU.
UK AI Regulation and Safety Bill Advances to Lords — NCSC Urges Action Now
Cubbbix / Policy Pros · Regulation
The UK’s AI Regulation and Safety Bill will reach its House of Lords committee stage on 22 September, with Royal Assent anticipated by 15 October 2026. The bill will codify statutory powers for the UK AI Security Institute. Separately, the UK Government and NCSC are already urging firms to treat AI systems as part of their attack surface, align with the AI Cyber Security Code of Practice, and tighten patch timing and access controls — signalling that voluntary compliance expectations are hardening ahead of formal legislation.
https://cubbbix.com/blog/ai-regulation-september-2026-global-update
Check Point Research: AI Has Crossed From Assistant to Attack Operator
Check Point Research · Risk
Check Point’s AI Security Report 2026 documents a landmark shift: AI is no longer just helping attackers prepare — it is now running live intrusions autonomously, generating thousands of exploitation commands with minimal human direction. Indirect prompt injection detections have risen roughly fivefold between March and May 2026, approaching 1% of all observed prompts, while high-risk enterprise prompts have doubled from 2% to 4% year-on-year. The report warns that nation-state actors and ordinary cybercriminals alike are now deploying AI to build deployment-ready malware and conduct full-cycle attacks without human intervention.
https://research.checkpoint.com/2026/ai-security-report-2026/
Critical Azure OpenAI SSRF Flaw Opens Lateral Movement Path for Attackers
Techmaniacs / Microsoft Advisory · Risk
A critical server-side request forgery (SSRF) vulnerability in Azure OpenAI — tracked as CVE-2026-45499 — allows any authenticated attacker to escalate privileges and move laterally across organisational cloud environments, potentially exfiltrating data and compromising AI models beyond their original access scope. Microsoft issued an emergency patch and security teams are advised to apply it immediately and segment Azure OpenAI endpoints using network security groups. The flaw is particularly significant because it turns the AI infrastructure layer itself into a lateral movement vector — a new class of risk that conventional network security tools are not designed to detect.
https://techmaniacs.com/2026/09/02/ai-security-daily-briefing-september-02-2026/
