Access & law

The US picture

US demand signal is real but less reliable than the EU's right now — the flagship defense compliance driver was just suspended.

evidence: medium10 minupd 2026-08-29uscmmccfaasecdarpafunding

The US gave this market its best public proof point — DARPA's AIxCC — and its most mature legal safe harbor for security research. It also just suspended the single compliance mechanism most likely to force US defense-industrial-base spending on security tooling in the near term. Compare that to the EU's hard, dated forcing functions and the US looks like the better place to build and to sell to, but the worse place to count on regulation for near-term revenue.

#DARPA AIxCC as government signal

AIxCC is the clearest public demonstration that autonomous vulnerability discovery-and-patching works at a meaningful capability level, and it came from the US government, not a lab press release. Two-year program, DEF CON 32 semifinals (2024) down to seven finalists at DEF CON 33 in August 2025, competing for an $29.5 million total prize pool. Final results: Team Atlanta 1st, $4,000,000; Trail of Bits 2nd, $3,000,000; Theori 3rd, $1,500,000. Across all finalists, competitors found 86% of 63 planted synthetic vulnerabilities and patched 68% of what they found (DARPA — AI Cyber Challenge; aicyberchallenge.com). All seven finalist Cyber Reasoning Systems were open-sourced immediately after the finals, by design — DARPA's stated goal was seeding the open ecosystem, not producing a classified capability. Full mechanics, architecture comparison, and what the real-world (not synthetic) results say are in AIxCC: the closest thing to a proof.

The competitive implication for a startup: baseline autonomous find-and-patch capability at a real level is now public and free. Differentiation has to come from integration, enterprise workflow, scale, or capability meaningfully beyond what the AIxCC CRSs demonstrated — "we have an LLM that finds bugs" stopped being a novelty claim in August 2025.

[Unverified] — what followed. DARPA's specific follow-on plans — a next-phase competition, a CISA transition-to-operations effort, or procurement built directly on AIxCC's outputs — could not be confirmed against a primary source in the underlying research pass. Check DARPA's AI Cyber program page directly before relying on a specific follow-on claim.

#CISA secure-by-design, the executive-order picture, federal AI policy

CISA Secure by Design, launched 2023 as a voluntary pledge (250+ signatories by 2024–2025 per prior reporting) committing manufacturers to measurable goals — MFA by default, eliminating default passwords, memory-safe roadmaps, SBOM practices, vulnerability disclosure programs. Its current 2026 operational status is [unverified]: live-fetch attempts against CISA's pledge page returned errors, and public reporting through 2025 described broader CISA budget and staffing reductions alongside some mission narrowing. Do not assume Secure by Design is running at 2024 intensity without checking cisa.gov directly.

EO 14144, Biden's "Strengthening and Promoting Innovation in the Nation's Cybersecurity," signed 16 January 2025, covered NIST secure-software-development attestations, an AI-in-critical-infrastructure-defense pilot, post-quantum migration acceleration, digital-identity guidance, sanctions-authority updates, and IoT device labeling (the Cyber Trust Mark). [Unverified]: widely reported but not independently confirmed in the underlying research pass is a follow-on June 2025 executive order that rescinded the digital-identity provisions and narrowed some AI-critical-infrastructure and sanctions directives, while explicitly retaining post-quantum and IoT labeling work. The direction — selective rollback, not wholesale repeal — is the safer planning assumption than either extreme, but treat the specific EO number, title, and date as unconfirmed.

America's AI Action Plan ("Winning the Race"), released by the White House OSTP 23 July 2025, explicitly frames AI-for-cyber-defense as a national priority and cites AIxCC as a model initiative, while pushing AI-infrastructure deregulation and export of US AI stacks to allies. It is a policy statement, not law — track specific implementing actions (agency directives, procurement rule changes) individually rather than assuming the plan itself has force.

#SEC disclosure, FedRAMP, and CMMC's suspension

SEC Item 1.05 (Form 8-K) requires public companies to disclose material cybersecurity incidents within four business days of a materiality determination, adopted July 2023, compliance from 18 December 2023 (SEC adopting release). No confirmed amendment or repeal since 2023 was found — treat it as still in force, though current SEC leadership has been reviewing disclosure-rule burdens generally.

FedRAMP 20x, GSA's initiative to modernize the historically 12–18+ month FedRAMP authorization process through automation and continuous machine-readable evidence, is [unverified] in this pass — primary GSA/fedramp.gov sources could not be fetched. Directly relevant to a federal SaaS go-to-market timeline; confirm at fedramp.gov before planning around it.

CMMC Phase II was suspended on 14 July 2026 by the Department of War — this is confirmed, and "Department of War" is the real current name for the former Department of Defense (war.gov is live and self-identifies with "Secretary of War" nomenclature). CMMC Phase II requirements had been scheduled to begin appearing in DoD solicitations from 10 November 2026; Phase I self-assessment requirements remain in place pending a stated comprehensive review (DoD CIO — CMMC; trade press corroboration via govconwire.com, with follow-up coverage through mid-August 2026 describing an ongoing pause).

Caution

A business plan that assumed CMMC Level 2/3 third-party-assessed certification would create a hard compliance deadline forcing defense-industrial-base primes and subs to buy security tooling in the second half of 2026 needs revising. That forcing function has been paused, not delayed to a known date. Compare this directly to the EU side of the ledger in EU regulation as a demand engine — CRA Article 14 goes live 11 September 2026 on schedule, while the closest US equivalent just got suspended. As of today, the EU's regulatory calendar is the more reliable near-term demand driver of the two.

DoD/DIU AI-cyber programs. DIU uses Commercial Solutions Openings and Other Transaction Authorities to contract quickly with non-traditional technology companies — including some foreign-affiliated ones, subject to case-by-case review — and continues to run AI-and-cyber-relevant solicitations, one of the faster non-SBIR paths into US federal revenue for a foreign-majority-owned company (see below).

NSA/CISA AI security guidance, most notably "Deploying AI Systems Securely" (NSA's AI Security Center, CISA, FBI, and Five Eyes partners, April 2024), is a useful design-partner reference for a product roadmap, independent of any specific procurement mandate.

#Liability: CFAA, autonomous agents, and DMCA 1201

CFAA (18 U.S.C. § 1030) remains the primary US federal criminal statute for unauthorized computer access, narrowed by the Supreme Court in Van Buren v. United States, 593 U.S. 374 (2021), which adopted a "gates-up-or-down" reading of "exceeds authorized access": a person exceeds authorized access only by entering parts of a system entirely off-limits, not by misusing legitimately held access for an improper purpose. That is meaningfully favorable for legitimate security tooling generally — it curbs the risk of routine scope creep during authorized testing being treated as a felony — but it does not resolve the problem that matters most for this business: an autonomous offensive agent that, during an authorized engagement, follows a discovered link or pivots to a system outside the signed scope of work has gone through a gate it was never given a key to, and Van Buren's own logic suggests crossing an explicit access boundary — even via autonomous action rather than a human decision — remains squarely within CFAA's reach.

The genuinely unresolved question: whose authorization state controls when an AI agent, not a human, takes the action — zero tolerance for drift from the operator's scope, or some emerging doctrine of reasonable diligence? No appellate authority squarely addresses autonomous-agent CFAA liability as of this writing [unverified — no case law identified]. Treat this as live legal risk requiring hard technical scope enforcement, not policy-level prompting — the same conclusion Dual-use risk and what it costs you reaches from the safety-engineering side.

DMCA § 1201 security-research exemption. Unlike Germany's §202c (see Germany: §202c and the Berlin question), the US has a codified, if narrow, safe harbor: 17 U.S.C. § 1201(j) exempts good-faith security testing under specific conditions (authorization, no other law violated, results used to promote security rather than facilitate infringement). Separately, the triennial Section 1201 rulemaking has, since 2016 and renewed through the 8th triennial rulemaking (effective October 2024), carried a broader regulatory exemption (37 CFR 201.40) for good-faith security research on lawfully acquired devices in a controlled environment. Exact 2024 rulemaking scope language should be checked at copyright.gov before relying on it for a specific product's legal posture, but the structural point holds regardless.

So what

For anything touching offensive capability — exploit generation, autonomous pentesting agents, benchmark datasets with working exploits — the US legal environment (Van Buren-narrowed CFAA plus a real, periodically-renewed DMCA research exemption) is measurably more mature and more favorable to legitimate security research than Germany's unreformed §202c StGB, even though neither jurisdiction has fully solved the autonomous-agent authorization question. This is the single strongest argument for routing the offensive-capability product line through a US entity regardless of where the company is headquartered.

Export-control exposure applies on both sides of the Atlantic and is under-covered here deliberately: publishing exploit code or offensive tooling openly, or transferring it to non-US collaborators, can implicate Commerce/BIS export administration rules including evolving AI-model-weight controls. This area churned through 2024–2026 and needs export-control counsel before any public release of exploit-capable weights — not an assumption that "it's just a research release" exempts it.

#US federal money, and the blunt fact about SBIR

DARPA, DIU, IARPA, NSF, In-Q-Tel. DARPA (AIxCC being the headline example) and IARPA fund cutting-edge cyber-AI research, generally through contracts open to US-performing entities. DIU is the fastest commercial-contracting path, covered above. In-Q-Tel (IQT), the CIA-affiliated strategic investor, makes equity investments in dual-use technology — cyber and AI squarely included — and has a track record of investing in non-US-origin companies that establish or commit to meaningful US operations, making it a more realistic entry point for a Berlin-founded company than SBIR.

SBIR/STTR is effectively closed to a majority German-owned company. SBIR/STTR awards generally require the awardee to be more than 50% owned and controlled by US citizens or permanent residents (STTR carries a 2022 carve-out allowing majority ownership by US venture capital/hedge fund/private equity entities instead), and the principal investigator's primary employment must generally sit with the awardee business in the US. A Berlin-founded, majority-founder-owned company cannot access SBIR/STTR directly without restructuring majority ownership into US hands — often impractical for an early-stage founder who wants to retain control. Exact current percentage thresholds and the STTR carve-out's precise applicability should be checked against sbir.gov before any structuring decision, but the general rule is stable and well-established.

The paths that remain: DIU's OTA/CSO mechanism and IQT's equity path, both of which tolerate non-US-majority ownership under case-by-case national-security review in a way SBIR's statutory ownership test does not, plus — once the company has scale — standing up a majority-US-owned subsidiary specifically to pursue SBIR later. See Who funds this and at what price for how this compares to the EU non-dilutive picture.

#Verdict: EU vs US

Sell first into Germany/the EU; consider a US-anchored structure for capital and for the offensive-capability product line specifically. This is one instance of the broader incorporation-and-market-entry call made across The three ideas, judged.

The EU compliance-driven demand signal is not hypothetical the way much of the current US signal is: NIS2 is already in force in Germany with personal management liability attached, DORA has been live for financial entities and their vendors since January 2025, and CRA Article 14 reporting goes live within weeks of this writing — while CMMC Phase II, the equivalent flagship US forcing function, was just suspended. That asymmetry, plus the founder's Berlin location, German-language sales motion, and EU non-dilutive funding access (see EU regulation as a demand engine and Germany: §202c and the Berlin question), compounds in favor of EU-first go-to-market for the first 12–24 months.

For capital and for anything offense-adjacent, the US case is separately strong: US venture and strategic capital — including In-Q-Tel- and DIU-adjacent dual-use investors — is deeper and faster than EU equivalents at this stage, and a Delaware C-corp (or a German-parent/US-subsidiary flip structure) is close to a precondition for accessing it cleanly. Combined with the more mature CFAA/DMCA legal environment for security research, a pragmatic structure is a German GmbH for EU sales, EU-funding eligibility, and defensive/compliance R&D, paired with a US entity holding IP and go-to-market for any offensive-capability product line.

This flips under a few conditions worth tracking explicitly: if CMMC Phase II resumes on a firm date, the US defense-compliance forcing function becomes competitive with the EU's again; if §202c reform in Germany actually passes (see Germany: §202c and the Berlin question), the case for routing offensive capability through a US entity weakens; and if EU "buy European" sovereignty procurement preferences harden further, EU-domiciled structure becomes more valuable even for products that would otherwise sit in the US entity. Track all three in Open questions and the research backlog.

#What this means for us

  • Do not model US federal defense-compliance demand as a near-term revenue driver — CMMC Phase II's suspension removed the clearest hard deadline, with no confirmed resumption date.
  • AIxCC set the public capability bar; competing on "we have an LLM that finds bugs" alone is no longer differentiated after August 2025 — see AIxCC: the closest thing to a proof and What could actually be defensible.
  • Route the offensive-capability product line through a US entity to capture the CFAA/DMCA legal-maturity advantage over Germany's unreformed §202c, while keeping EU sales and compliance-tooling R&D German-domiciled.
  • SBIR is not a realistic funding path without US-majority restructuring; plan around DIU's OTA/CSO mechanism and IQT instead.
  • Build hard technical scope-fencing into any autonomous offensive agent now — the CFAA authorization question for autonomous agents is unresolved in the US just as it is in Germany, and no jurisdiction currently gives you a clean answer.
  • Re-check CMMC's status, EO 14144's actual fate, and CISA Secure by Design's 2026 operational posture before this page's confidence moves from medium to high — see Verification ledger.