Security

US-EU AISS Framework Signed + iOS 26.6 Emergency Patch Fixes 87 Vulnerabilities

The US and EU have signed their first transatlantic AI Safety Framework, requiring independent third-party audits for 'foundational' and 'high-risk' AI systems. Separately, iOS 26.6 ships fixes for 87 vulnerabilities, including WebKit RCE and kernel escalation bugs.

R
By Ravi Menon Security Correspondent
July 29, 2026 / 6 min read

Two consequential security stories landed within hours of each other this week. The U.S. and EU signed the Artificial Intelligence Safety Shield (AISS) framework, requiring independent third-party audits before 'foundational' and 'high-risk' AI systems can be deployed. Apple simultaneously shipped iOS 26.6, fixing 87 vulnerabilities including a WebKit remote code execution bug and a kernel local privilege escalation.

What AISS Actually Requires

The framework is the first binding transatlantic agreement covering AI deployment. Under its terms:

  • Foundational AI systems (those trained with more than 10^26 FLOPs of compute or comparable capability thresholds) must complete an independent third-party audit before deployment in either jurisdiction.
  • High-risk AI systems (those used in critical infrastructure, employment, education, credit, law enforcement, or healthcare) must also pass an audit and disclose audit results to regulators.
  • Mutual recognition: audits performed under either jurisdiction's accredited scheme count for both, eliminating duplicate compliance work.
"Today, 800 million people on both sides of the Atlantic live under a single AI safety baseline. That has never existed before," said a senior European Commission official at the signing.

Who Is Left Out

Notably absent from the framework: China. AISS applies only to AI systems deployed in the U.S. or EU. Models trained or operated in third countries that serve U.S. or EU users are in scope, but providers headquartered in China are not parties to the agreement.

iOS 26.6 in Detail

Apple's iOS 26.6 is a substantial security release:

  • CVE-2026-4127 (WebKit): a remote code execution vulnerability triggered by maliciously crafted web content. Apple says it is "aware of reports" the bug was exploited in the wild.
  • CVE-2026-4131 (Kernel): a local privilege escalation allowing a malicious app to escape its sandbox. Rated high severity.
  • 87 total CVEs addressed, with 12 rated critical and 29 rated high.
"The WebKit issue is the most concerning. A user just visiting a malicious page could end up running attacker code, with no further interaction," said one iOS security researcher.

Who Needs to Patch

iOS 26.6 supports iPhone 13 and later. Devices older than that have moved to a security-only branch and are receiving a smaller patch. Apple has separately shipped Safari 18.6 and macOS 15.6 with the same WebKit fix.

Why These Two Stories Belong Together

The AISS framework and iOS 26.6 are both about closing trust gaps. AISS asks: can we trust a deployed AI system to behave predictably? iOS 26.6 asks: can we trust a deployed mobile operating system to keep its sandbox intact? The answer in both cases depends on independent verification before deployment - which is exactly what AISS codifies and exactly what iOS users can now get by updating.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.