Skip to main content

Cyber Regulation Report 2026

Released on 9 June 2026

As the UK’s House of Commons prepares for the third reading of the UK’s Cyber Bill, OpenUK shares an overview of global Cyber Regulation, including the 5 June Trump Memo calling out open source in AI. The report sets the context of this in a world of Agentic AI and the Anthropic Mythos Language Model’s effect.

Report Includes:

Thought Leadership:

  • Software Bills of Materials and the UK’s Supply Chain Blind Spot – Sal Kimmich, Security Architect and Policy Manager, OpenUK
  • AI Agents and Identity: The Next Evolution of Enterprise Trust – Matt Barker, CEO, BoltMCP
  • Introduction: The Mythos Effect – Andrew Martin, CEO ControlPlane and CISO OpenUK
  • The UK Public Sector and National Health Service Response to Mythos – Clare Schramm, Technology Platforms MD, Lloyds
  • Conclusion – Dr Jennifer Barth, OpenUK Research Director

Panel Sessions from SOOCon26 on 8 June:

  • Agentic, Identity and Second
  • The Mythos Effect

Regulatory Update:

  • Global overview of cyber regulation impacting open source
  • Deep dive into the EU’s Cyber Resilience Regulation, probably the most significant regulation of open source, introducing the concept of Stewards and shifting liability to creators of open source.
  • US regulation through the June 26 Executive Order and Memo, along with SBOM related Executive Order

And an update on the UK Cyber Regulation.

Download the report

Cyber Regulation Report 2026 Press Launch

Speakers

Professor Amanda Brock, CEO, OpenUK & OpenHQ

Andrew Martin, CEO, ControlPlane

Dr Jennifer Barth, CRO, OpenUK

Karan Saini, Research Manager, OpenHQ

Matt Barker, CEO & Co-Founder, BoltMCP

Tuesday 9 June 2026, 08:30 – 09:30 AM, Thanks to FieldFisher

Executive Summary

Open source software underpins the modern digital economy and is present in almost every codebase, yet its security has remained a largely unregulated space. This report examines how cyber regulation worldwide is — or isn’t — adapting to that reality, and how the arrival of frontier AI is reshaping the risk landscape faster than the law can follow.

The regulatory landscape and the open source blind spot

  • Cyber regulation splits into two families: organisation-centric regimes imposing duties on critical-infrastructure operators (NIS2, Singapore, India, the UK’s forthcoming Bill) and product-centric regimes attaching obligations to software itself
  • Of 23 jurisdictions surveyed, only the EU and the US substantively address open source in regulation
  • Elsewhere, pressure reaches maintainers indirectly through supply-chain obligations — a regulatory perimeter built around the ecosystem rather than with it
  • The 5 June Presidential Memo directs US national security agencies to adapt the best commercial and open source technologies for mission use; the preceding Executive Order requires 30-day voluntary notification of frontier models pre-release

The EU Cyber Resilience Act in depth

  • The CRA is the central case study: its first draft pushed liability onto foundations and volunteer maintainers who neither sell nor profit from their code
  • An eighteen-month corrective effort led by the Linux Foundation, Eclipse, Rust, Python and Apache produced the “Open Source Software Steward” — the first recognition of non-commercial open source organisations in any major legislation, anywhere
  • Concerns remain where broad “commercialisation” definitions could catch individuals and innovators who monetise services around freely distributed code
  • The steward category remains untested until its standards and enforcement are settled

AI, the Mythos Effect and open source under strain

  • Frontier models trained on the entirety of available code have collapsed the time between latent vulnerability and exploit — surfacing over 10,000 critical CVEs in a single month (“vulnpocalypse”) and overwhelming project patching capacity
  • The report examines defensive over-reactions, including sovereign forks and the NHS decision to close-source hundreds of repositories, arguing withdrawal from the commons negates open source’s collaborative security benefits
  • GDS guidance repudiates the “flip the visibility switch” instinct: private repositories create a false sense of security; open by default stands

SBOMs, provenance and the engineering response

  • Static, checkbox SBOMs are obsolete: effective practice requires build-time generation, VEX enrichment and verifiable provenance (SLSA, Sigstore)
  • The UK has strong international engagement (co-authoring the G7 SBOM for AI framework) but no domestic statutory mandate — G-Cloud procurement is the most immediate, addressable lever

The UK’s position

  • The Cyber Security and Resilience Bill extends NIS-style duties to managed service providers and data centres but makes no mention of open source
  • The report’s recurring conclusion: understand open source as critical, fragile, communal infrastructure — and regulate with the ecosystem, not around it

OpenUK Annual Survey

Contribute to our Research by sparing 30 minutes to complete our survey in partnership with our Economists in Residence, The PSC – wherever in the world you are, whether you are working or not and whatever sector you might work in.

Survey

Scroll to top of the content