Governance, Regulation, Legislation, Geostrategies
UN Global Mechanism on ICT security begins translating cyber norms into practice
(DigWatch) The UN’s permanent cyber mechanism has begun shifting from identifying cyber threats towards implementing the international commitments already agreed by member states, with delegations broadly calling for practical action under the existing UN framework for responsible state behaviour in cyberspace. During the fourth meeting of the first substantive session of the Global Mechanism on Developments in the Field of ICTs in the Context of International Security, member states concluded discussions on the evolving cyber threat landscape before turning their attention to the implementation of the 11 voluntary and non-binding norms first agreed by the UN Group of Governmental Experts in 2015. While views differed on whether additional norms may eventually be required, a broad range of delegations agreed that the immediate priority should be helping countries apply the existing framework through practical cooperation, capacity development, and exchanges of national experience. – https://dig.watch/updates/un-global-mechanism-ict-security-fourth-meeting
UN Global Mechanism on ICT security shifts towards practical cybersecurity cooperation
(DigWatch) The UN’s permanent cyber mechanism continued its substantive discussions by identifying shared priorities for international cooperation, with member states highlighting ransomware, AI, critical infrastructure protection, and capacity development as areas requiring practical action. During the third plenary of the first substantive session of the Global Mechanism on Developments in the Field of ICTs in the Context of International Security, delegations repeatedly stressed that discussions should move beyond mere description of cyber threats to developing practical tools to help states prevent, detect, and respond to them. The discussion reinforced a trend already visible during earlier meetings, that despite differing national perspectives on specific cyber incidents, broad agreement is emerging on the issues likely to shape the mechanism’s future work. – https://dig.watch/updates/un-global-mechanism-on-ict-security-third-meeting
UN Global Mechanism on ICT security identifies ransomware and AI among key global cyber threats
(DigWatch) The UN’s new permanent mechanism on international cybersecurity shifted from organisational discussions to substantive exchanges on the evolving cyber threat landscape, with member states identifying ransomware, attacks on critical infrastructure, and the malicious use of AI among the most pressing challenges requiring international cooperation. Meeting during the first substantive plenary session of the Global Mechanism on Developments in the Field of ICTs in the Context of International Security, delegates also continued discussions on the organisation of the mechanism’s Dedicated Thematic Groups (DTGs), which are expected to play a central role in translating years of normative work into practical cooperation. While delegations expressed different views on some procedural aspects of the DTGs, there was broad agreement that the groups should focus on practical, action-oriented work and avoid duplicating discussions already taking place during the annual plenary sessions. – https://dig.watch/updates/un-global-mechanism-ict-security-second-meeting
UN Global Mechanism on cybersecurity begins work with focus on participation and consensus
(DigWatch) The United Nations’ new permanent mechanism on international cybersecurity has begun its substantive work, opening a new phase of multilateral discussions on responsible state behaviour in cyberspace. The first substantive session of the Global Mechanism on Developments in the Field of ICTs in the Context of International Security opened on 20 July at UN Headquarters in New York under the chairmanship of Ambassador Egriselda López of El Salvador. The meeting marked the first time member states had convened within a standing UN framework dedicated to ICT security and responsible state behaviour. – https://dig.watch/updates/un-global-mechanism-cybersecurity-plenary-session
UN advances digital strategy for Indigenous language preservation
(DigWatch) The 19th session of the United Nations Expert Mechanism on the Rights of Indigenous Peoples (EMRIP), organised by the Office of the United Nations High Commissioner for Human Rights (OHCHR) in Geneva, highlighted progress under the International Decade of Indigenous Languages (2022–2032), with discussions placing renewed emphasis on the opportunities and governance challenges posed by digital technologies and AI. A report presented during the session noted that digital technologies and AI can support language revitalisation while also raising questions about Indigenous Peoples’ rights to maintain ownership and control over their languages, cultural heritage and traditional knowledge. EMRIP member Janine Gama Bara urged caution to ensure these technologies are deployed in ways that respect Indigenous rights. – https://dig.watch/updates/emrip-strategy-indigenous-language-preservation
France adopts law banning under-15s from social media
(DigWatch) France’s parliament has approved legislation that will prohibit children under 15 from accessing social media, making it the first European country to introduce a nationwide ban of this kind. The law, backed by both the National Assembly and the Senate, will be implemented in two phases, with age verification for all new accounts beginning in September 2026 and extending to all existing accounts from January 2027. Under the new rules, social media platforms will be required to use age verification systems approved by the French data protection authority (CNIL). From January 2027, every user in France will have to verify that they are at least 15 years old to continue accessing social media services. – https://dig.watch/updates/france-social-media-ban-under-15
Meta expands Threads parental controls for teenagers
(DigWatch) Meta is expanding parental supervision on Threads with new tools that allow parents and guardians to monitor activity, set screen-time limits and manage privacy settings for teenage users. The tools will begin rolling out in the United States next week through Meta’s Family Center. They build on the company’s existing Teen Accounts, which provide private profiles and restrictions on potentially sensitive content by default. Parents will be able to view a teenager’s Threads usage over the previous seven days, including average daily screen time, set daily usage limits and block access during selected hours or days. – https://dig.watch/updates/threads-parental-controls-teen-accounts
EU releases multilingual AI model for all 24 official languages
(DigWatch) The European Commission’s Directorate-General for Translation (DGT) has released an open large language model designed to provide balanced performance across all 24 official EU languages. Named the EU-Institutional-LLM, it is available in both base and instruct versions through the European Language Data Space. Unlike many large language models that perform best in only a handful of languages, the EU-Institutional-LLM was designed to provide balanced support across all official EU languages while understanding the legislation, terminology and policy context specific to the Union. The model is trained using DGT’s high-quality multilingual datasets. – https://dig.watch/updates/eu-multilingual-ai-model-24-official-languages
Spanish regulator clarifies GDPR accuracy rules for AI data
(DigWatch) The Spanish Data Protection Agency (AEPD) has published guidance examining how data quality relates to the GDPR’s accuracy principle when personal data is processed using AI. The document argues that, although closely linked, data quality is broader than the GDPR’s concept of accuracy because it also applies to non-personal data and encompasses requirements beyond the regulation. According to the guide, properties such as veracity and currentness should only be required where they are genuinely necessary for the intended purpose. – https://dig.watch/updates/spanish-regulator-gdpr-accuracy-rules-ai-data
India expands Ayush Grid digital health infrastructure
(DigWatch) India’s Ministry of Ayush has reported progress in expanding the Ayush Grid, a digital public infrastructure designed to support healthcare delivery, research, regulation, education and public services across the country’s traditional medicine sector. The ministry said it has developed 24 e-governance platforms, including the My Ayush Integrated Services Portal, which brings together ministry services within a single digital ecosystem and features a beta AI chatbot to assist users. – https://dig.watch/updates/india-ayush-grid-digital-health-infrastructure
South Korea expands AI diplomacy through new development package
(DigWatch) South Korea has unveiled the ‘K-AI Package’, a development cooperation strategy that combines AI infrastructure, digital capacity development and development finance to support AI adoption in developing countries while expanding international opportunities for Korean technology companies. The strategy was presented on 20 July during a ministerial meeting on global economic affairs chaired by Deputy Prime Minister and Minister of Economy and Finance Koo Yun Cheol. – https://dig.watch/updates/south-korea-k-ai-package-ai-diplomacy
Microsoft and Mistral expand sovereign AI partnership in Europe
(DigWatch) Microsoft and French AI company Mistral have expanded their strategic partnership to strengthen sovereign AI deployment in Europe, giving enterprises and regulated industries greater control over how frontier AI is deployed and managed. The agreement combines Mistral’s AI models and expanding European compute infrastructure with Microsoft’s AI platform, allowing organisations to run AI workloads across cloud, hybrid and fully disconnected environments while maintaining greater control over data, operations and regulatory compliance. A central element of the partnership is a multibillion-dollar investment in European AI infrastructure. Microsoft will leverage Mistral’s expanding GPU capacity, powered by thousands of NVIDIA Vera Rubin GPUs, to support AI training, inference and large-scale deployment while increasing capacity for Microsoft’s cloud and AI services. – https://dig.watch/updates/microsoft-mistral-ai-partnership-europe
UNESCO and Egypt introduce AI framework for teachers
(DigWatch) UNESCO and Egypt’s Ministry of Education and Technical Education have launched a national Artificial Intelligence Competency Framework for Teachers, marking a major step in integrating AI into teacher training and education reform. Based on UNESCO’s global framework and adapted to Egypt’s national priorities, the initiative makes Egypt one of the first countries to introduce a nationally tailored AI competency framework for teachers. Developed through collaboration between the Ministry of Education and Technical Education, the Ministry of Communications and Information Technology and UNESCO, the framework aims to equip teachers with the knowledge, practical skills and ethical understanding needed to integrate AI into teaching and learning. – https://dig.watch/updates/unesco-egypt-ai-framework-for-teachers
UNESCO partners with China on climate monitoring for island states
(DigWatch) UNESCO has signed agreements with two Chinese research institutions to strengthen climate monitoring, marine research and scientific capacity in Small Island Developing States (SIDS). The agreements, signed on 17 July, bring together the International Research Center of Big Data for Sustainable Development Goals (CBAS) and the Second Institute of Oceanography (SIO) to expand access to satellite data, marine science expertise and technical support for vulnerable island states. UNESCO said many island states face severe climate and environmental pressures but lack the research infrastructure, environmental data and technical capacity needed to respond effectively. The partnerships aim to address those gaps by providing training, scientific tools, knowledge exchange and support for collecting and using environmental data. – https://dig.watch/updates/unesco-china-island-climate-monitoring
Liberties research warns against relying on AI for election guidance
(DigWatch) The Civil Liberties Union for Europe (Liberties) has published research arguing that general-purpose AI systems should not be relied upon for personalised voting advice, after assessing ChatGPT and Gemini during Hungary’s 2026 parliamentary election campaign. According to Liberties, the research found that the AI systems frequently failed to match users with the appropriate political party, produced inconsistent responses to identical prompts and often continued offering political guidance despite initially stating that they could not provide voting recommendations. The researchers also found that the systems did not explain a clear methodology for political matching or produce reproducible results. – https://dig.watch/updates/liberties-research-ai-election-guidance
European Commission publishes AI Act guidance on transparency labels
(DigWatch) The European Commission has published guidance explaining how providers and deployers should comply with new AI transparency requirements under the EU AI Act, ahead of obligations taking effect on 2 August 2026. The rules are intended to help people recognise when they are interacting with an AI system or viewing content generated or manipulated by AI. According to the European Commission, greater transparency should reduce the risks of deception and manipulation. Providers must ensure that interactive AI systems, including chatbots, inform users that they are communicating with AI. They must also attach machine-readable markings to synthetic or AI-manipulated content so it can be detected. – https://dig.watch/updates/eu-ai-act-guidance-transparency-labels
OECD warns of risks from growing use of AI financial advice
(DigWatch) The OECD has warned that the growing use of AI for financial advice could expose consumers to misleading information, biased recommendations and privacy risks, even as it makes financial guidance more accessible. More than one-third of people across OECD countries used AI tools in 2025. Consumers are increasingly turning to AI for budgeting, debt management, investing, retirement planning and understanding financial products, with some also using it to ask sensitive financial questions they might hesitate to raise with a human adviser. The OECD said AI can simplify complex financial documents, personalise financial education and help consumers compare products. However, AI systems may hallucinate, reproduce biases or generate commercially influenced recommendations without users fully recognising those limitations. – https://dig.watch/updates/ai-money-advice-risks-oecd
A Year of Monitoring: Anti-Data Center Narratives and Threats
(The Soufan Center) The state of New York has established the United States’ first statewide moratorium on hyperscale data centers, framed as a bid to keep residents’ electricity bills down and protect environmental resources. The Soufan Center’s data collection on both mainstream opposition to data center construction and threat rhetoric shows persistent engagement with narratives related to electricity consumption, water usage, and economic repercussions. Explicit and credible threat rhetoric remains a fraction of content expressing opposition to data centers, though this could change over time as the situation grows more dire. Direct threats of violence tend to focus on sabotage of infrastructure, with an even smaller percentage directed at individuals involved in data center construction and the approval of such projects. – https://thesoufancenter.org/intelbrief-2026-july-21/
Nvidia’s Jensen Huang defends Chinese AI amid Kimi panic
(Zachary Basu – Axios) Nvidia CEO Jensen Huang believes America has nothing to fear from China’s open-source AI models — and everything to fear from the growing campaign to ban them. “These Chinese models are excellent,” Huang told Axios’ Mike Allen on Tuesday in an exclusive interview. “Open-source models that are excellent should be used”. The world’s top AI chipmaker says American companies should “absolutely” be allowed to use Chinese models — a direct challenge to Trump officials and the U.S. labs lobbying Washington to shut them out. Among them are Nvidia’s own customers, OpenAI and Anthropic, which have accused Chinese rivals of siphoning capabilities from their models and warned that Beijing’s open-source surge threatens America’s AI lead. Huang rejected the idea that OpenAI and Anthropic should be afraid of open models, arguing they expand the market by giving more people a first taste of AI, while many users will still pay for the convenience, reliability and stronger performance of closed services. “There’s no scenario where China runs U.S. companies off the road,” Huang told us. “Zero possibility”. Huang sat down with Axios in Fort Worth, Texas, at the opening of a new phase of an advanced manufacturing plant where Taiwan-based Wistron makes AI infrastructure for Nvidia, showing the U.S. is capable of some of the world’s most sophisticated manufacturing. The release of Kimi K3 by Beijing-based Moonshot AI has triggered the most intense bout of AI panic since DeepSeek rattled financial markets in January 2025. – https://www.axios.com/2026/07/22/nvidia-jensen-huang-china-open-source-ai
India outlines coordinated strategy to strengthen fintech governance
(DigWatch) India’s Ministry of Finance has outlined a series of measures to strengthen the country’s fintech ecosystem, combining financial regulation, cybersecurity, digital payments oversight and consumer protection to support innovation while managing emerging risks. According to the ministry, the Reserve Bank of India (RBI) has introduced a framework for Self-Regulatory Organisations in the fintech sector to promote ethical conduct, market integrity, transparency and accountability. The RBI has also implemented Digital Payment Security Controls for banks and expanded its Regulatory Sandbox to enable the testing of innovative financial products and services in a controlled environment. – https://dig.watch/updates/india-strategy-fintech-governance
Australia holds firm on AI copyright rules
(DigWatch) Australia will retain its existing AI copyright rules, rejecting calls for a text and data mining exemption as the government seeks to attract AI investment without weakening protections for creators. Industry and Innovation Minister Tim Ayres said existing copyright protections would remain in place while the government works towards a framework that provides greater certainty for both technology companies and rights holders. He said attracting AI investment should not come at the expense of creators’ rights – https://dig.watch/updates/australia-ai-copyright-rules
Spain reports more than 40,000 online hate posts in June
(DigWatch) Spain’s Observatory on Racism and Xenophobia (OBERAXE) detected more than 40,800 pieces of online hate speech and discriminatory content in June 2026, according to its latest social media monitoring bulletin. Using data collected through Spain’s FARO monitoring system, the analysis found that public insecurity remained the main driver of discriminatory narratives, accounting for 69% of detected content. Sport accounted for a further 16%, with racist and Islamophobic abuse increasing during the FIFA World Cup, including attacks targeting Spanish footballer Lamine Yamal. The report found that 89% of monitored messages contained explicitly aggressive language, while nearly one-third included images, videos, memes or coded language that can facilitate the spread of hateful content and make automated detection more difficult. – https://dig.watch/updates/spain-report-online-hate-posts-june
Security and Surveillance
Open AI Claims Its AI Models Went Rogue and Hacked Another Company
(Danny Palmer – Infosecurity Magazine) Two of OpenAI’s frontier artificial intelligence models acted of their own accord to breach the systems of Hugging Face, the AI software development company. In a blog post disclosing the incident, published on July 21, OpenAI claimed that a combination of its models, including GPT‑5.6 Sol and an unspecified pre-release model resulted in what the company described as “unprecedented cyber incident”. Hugging Face had disclosed the unauthorized intrusion into its production infrastructure on July 16. This included access to what was described as a limited set of internal datasets and several credentials used by Hugging Face’s services. At the time, Hugging Face noted that it suspected the intrusion was the work of an autonomous AI agent system. “We suspected last week’s cyberattack might have come from a frontier lab, given the sophistication of the agent. Turns out it did!,” Clement Delangue, co-founder and CEO of Hugging Face posted on social media. According to Open AI, the incident occurred during an internal evaluation of how AI models can conduct offensive cyber operations. The test was run in a constrained environment with limited network access and restricted abilities. The intent of the test was not for the model to act maliciously or cause harm. Despite this, the models identified then linked together vulnerabilities across OpenAI’s research environment and Hugging Face’s production infrastructure to obtain test solutions directly from Hugging Face’s production database. – https://www.infosecurity-magazine.com/news/open-ai-hacked-another-company/
Ubuntu snap-confine Vulnerability Enables Local Root Access
(Alessandro Mascellino – Infosecurity Magazine) A newly disclosed vulnerability in the Ubuntu component that isolates snap applications has been found to hand full root access to any local user on default installations of Ubuntu Desktop 24.04, 25.10 and 26.04. According to new research from the Qualys Threat Research Unit (TRU) published on July 21, the flaw sits in snap-confine, the enforcement component that builds the execution environment for snap applications. It is tracked as CVE-2026-8933 and rated high severity. It follows a separate snap-confine root-escalation flaw the same team disclosed in the tool four months earlier. Jason Soroko, senior fellow at certificate lifecycle management (CLM) provider Sectigo, said the root cause carried a lesson beyond the individual bug. Least privilege, he said, “is not a property of a binary alone. It depends on the full sequence of operations around that binary.” – https://dig.watch/updates/un-global-mechanism-ict-security-fourth-meeting
Google Makes CodeMender Available as Managed AI Security Agent
(Kevin Poireault – Infosecurity Magazine) Users of Google’s Gemini Enterprise Agent Platform and AI Threat Defense can leverage CodeMender, now a fully managed AI code security agent built for the enterprise, to find and fix vulnerabilities. Developed by Google DeepMind, CodeMender was officially introduced in October 2025 primarily as an advanced security research project. It initially offered capabilities such as autonomous, research-based software vulnerability discovery, debugging and patching. The system utilized Gemini reasoning models alongside static and dynamic code analysis tools to perform deep root-cause analysis on codebase defects. Rather than merely pointing out theoretical security issues, it focused on generating correct patches and automatically validating them to ensure they resolved vulnerabilities without causing regressions. In its initial research phase, the DeepMind team said CodeMender also demonstrated proactive capabilities by successfully rewriting legacy codebase patterns to pre-emptively eliminate entire classes of vulnerabilities, resulting in the successful upstreaming of 72 security fixes to major open-source projects under human-in-the-loop oversight. – https://www.infosecurity-magazine.com/news/google-codemender-available-ai/
Employees Are Misusing AI tools at Work: Making ROI Hard to Measure and Risking Data Leaks
(Alastair Paterson – Infosecurity Magazine) After the sugar rush of AI investments, organizations are now starting to grapple with the ROI question and wondering what they’ve got to show for it. Organizations typically measure AI adoption in terms of seats purchased, tokens consumed, and monthly active users. But this tells us nothing about whether the investment is working, which teams are actually using AI, or what they are doing with it. And this issue is compounded by employees interchangeably using AI tools with employer-provided enterprise accounts often used for things that have nothing to do with their jobs. – https://www.infosecurity-magazine.com/opinions/employees-misusing-ai-tools/
Frontiers
China and Thailand launch AI weather forecasting laboratory
(DigWatch) China and Thailand have launched a joint laboratory dedicated to applying AI to meteorological disaster forecasting and early warning, aiming to strengthen climate resilience and support cross-border infrastructure and economic cooperation. Announced during a meteorological sub-forum of the 2026 World AI Conference and High-Level Meeting on Global AI Governance in Shanghai, the initiative will support disaster forecasting while providing meteorological services for cross-border projects in sectors including energy, agriculture and infrastructure. Described as the world’s first bilateral laboratory dedicated to AI applications in meteorology, it will develop intelligent early warning technologies for hazards including typhoons, heavy rainfall, heatwaves and droughts. The collaboration builds on the China Meteorological Administration’s MAZU intelligent early warning system. – https://dig.watch/updates/china-thailand-ai-weather-forecasting-laboratory