As President Donald Trump moves to sign an executive order on AI oversight, the policy conversation is dominated by national security and enterprise risk — but consumer-facing AI platforms, where users are trusting AI with something as personal as their social lives and relationships, are barely part of the debate. The order raises a critical question: who sets the standard for emotional safety, transparency, and user consent in AI that mediates human connection?
Gidi Cohen, CEO & Co-founder, Bonfy.AI had this to say:
“The reported shift toward federal oversight of frontier AI models reflects something the security community has been watching develop for some time: the recognition that AI systems are no longer just productivity tools — they are infrastructure.
What’s notable about this moment isn’t the regulatory instinct. It’s what’s driving it. Reports of AI models autonomously discovering software exploits and scaling cyber operations aren’t abstract risks. They’re demonstrations of the same challenge we see playing out inside enterprises every day: AI systems that behave in ways their deployers didn’t anticipate, at speeds that outpace human review.
At Bonfy, we call this the “Shady AI” problem — not unauthorized AI, but sanctioned AI behaving in ways that violate policy or intent. The national security version of this problem is just the frontier model at civilizational scale.
The instinct to require pre-release government review of frontier models makes sense if you frame it the way Washington now appears to: as dual-use technology with offensive capability, not software. But a 90-day review window won’t solve the underlying challenge. The risk isn’t just in what a model can do before deployment — it’s in how it behaves when embedded in workflows, connected to tools and data, and operating semi-autonomously at machine speed.
That’s the architectural reality facing enterprise security teams today, and it’s why data security can no longer rely on perimeter controls and metadata. When AI agents are the actors, you need visibility into the data flowing through them — not just the permissions around them.
The government is arriving at a conclusion that security practitioners have been working through in parallel: that AI requires a different kind of oversight, one grounded in behavior and context, not just access configuration.”
For measures to be effective, they have to cover as many use cases as possible. This measure doesn’t do that, which means it may not have the intended effect at the end of the day.
U.S. imposes visa restrictions on foreign cyber scammers
Posted in Commentary with tags USA on July 27, 2026 by itnerdThe U.S. State Department announced a new visa restriction policy targeting foreign individuals responsible for or complicit in cybercrime and cyber-enabled crimes.
The restrictions may also apply to the immediate family members of those involved and are intended to disrupt overseas criminal networks.
The policy follows President Trump’s March executive order on combating cybercrime and fraud. According to the State Department, cyber scam operations cost Americans an estimated $10 billion in 2024.
John Carberry, Solution Sleuth, Xcape, Inc. had this comment:
“Deploying diplomatic tools like targeted visa denials raises the personal stakes for transnational cybercrime syndicates, even if it seems odd that a dedicated policy was necessary to keep known criminals out of the country in the first place. By extending travel restrictions to immediate family members under Executive Order 14390, the State Department squeezes the mobility and secondary benefits of operators working from non-extradition jurisdictions. While federal sanctions target overseas infrastructure over time, enterprise security leaders cannot rely on immigration enforcement for threat mitigation. Executives must prioritize immediate technical controls, including strict identity verification, automated transaction monitoring, and robust inbound communication filtering to defeat cyber-enabled fraud at the edge.
“Critical Takeaways
“While denying visas to transnational scammers is a welcome step, it is remarkable that keeping international criminals out required a new policy in the first place.”
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs had this to say:
“The State Department’s new visa restrictions on cybercriminals target people who chose their operating model specifically to avoid US jurisdiction. Scam compound operators in Cambodia, Myanmar, and Laos aren’t applying for US visas. They built fortified facilities in countries with weak governance because distance from Western oversight is the product feature.
“This is industrialized crime running on franchise economics, shared financial infrastructure, trafficking pipelines, specialized service divisions. Rubio cited $10 billion in US losses for 2024. Regional losses hit $88-114 billion in 2025, tripled from 2023. You don’t get to that number with individual bad actors. You get there with an industry.
“DOJ’s June seizure of Huione Group assets showed what effective disruption looks like at this scale, going after shared financial architecture that multiple franchises depend on. Visa restrictions are an individual-accountability tool applied to a problem that has outgrown individual accountability. The industry keeps running regardless of which operators can board a flight to JFK.”
This is an important step forward for sure. I for one would love to see it go further. Like arrest people that are involved in cybercrime and arrest their relatives in exchange for the criminals turning themselves in. That way either people don’t get involved in cybercrime, turn in the perpetrators, or distance themselves accordingly letting the authorities know about it. And other countries should follow suit.
Leave a comment »