Governance, Regulation, Legislation, Governance
The Fable 5 shutdown and the troubling precedent it sets for AI policy
(Caroline Berry – Atlantic Council) The United States currently lacks a clear and transparent process for restricting access to new AI models. Congress should establish public standards defining when AI models can be restricted, which agencies oversee reviews, and what evidence is required for emergency action. Clear legal safeguards would make future restrictions more transparent and accountable, while preserving the government’s ability to respond to national security threats. – https://www.atlanticcouncil.org/dispatches/the-fable-5-shutdown-and-the-troubling-precedent-it-sets-for-ai-policy/
Germany launches consultation on new open data strategy
(DigWatch) Germany’s Federal Ministry for Digital Transformation and Government Modernisation has launched a public consultation on a new strategic framework for open data. The process will gather proposals for an ‘open data roadmap’ intended to replace or build on Germany’s five-year Open Data Strategy adopted in July 2021. The federal government aims to adopt and publish the revised framework in early 2027. Businesses, researchers, public authorities, policymakers, civil society organisations and members of the public can submit written contributions until 15 September 2026. Responses will be evaluated by the ministry and published without personal information after the consultation closes. – https://dig.watch/updates/germany-launches-consultation-on-new-open-data-strategy
AMD and South Korea partner on open sovereign AI infrastructure
(DigWatch) AMD and South Korea’s Ministry of Science and ICT have signed a strategic partnership to develop sovereign AI infrastructure based on open, heterogeneous computing technologies, strengthening the country’s semiconductor ecosystem while reducing dependence on any single technology provider. The partnership will explore national AI computing infrastructure combining AMD with neural processing units (NPUs) developed by Korean companies. According to the partners, this heterogeneous approach is intended to expand technology choice while avoiding dependence on a single supplier. – https://dig.watch/updates/amd-korea-ai-deal-sovereign-infrastructure
India advances AI mission with stronger focus on safety and governance
(DigWatch) India has highlighted progress under its ₹10,371 crore IndiaAI Mission, presenting the Safe & Trusted AI pillar as a cornerstone of its strategy to combine rapid AI development with responsible governance. The mission combines investment in domestic AI capabilities with measures intended to ensure AI systems remain secure, transparent, fair and trustworthy. According to the government, progress includes support for 20 sovereign AI model proposals, 237 computing projects, 58 AI Centres of Excellence, 27 India Data and AI Labs, and hundreds of AI fellowships – https://dig.watch/updates/india-ai-mission-safety-and-governance
Schools in Australia urged to review photo sharing over AI misuse
(DigWatch) Australia’s eSafety Commissioner has urged schools to reconsider how they publish photos and videos online as widely available AI tools increase the risk of images being manipulated or used to target staff and students. The regulator said it had recorded a rise in reports of school-related image misuse over the past 18 months. Between January and March 2026, eSafety received more than 100 reports concerning anonymous accounts targeting schools and staff. Almost all of the images involved were taken from school websites or social media accounts. Reported material included AI-generated dance videos, face swaps, memes and fabricated stories involving teachers, principals and other staff. Much of it appeared on anonymous TikTok and Instagram accounts, some of which had attracted hundreds of followers. – https://dig.watch/updates/schools-urged-to-review-photo-sharing
The Financial Action Task Force warns global crypto rules remain weakly enforced
(DigWatch) The Financial Action Task Force has warned that virtual asset regulation remains unevenly enforced despite wider adoption of anti-money-laundering rules. The findings appear in FATF’s seventh targeted update on the implementation of its standards for virtual assets and virtual asset service providers. The report examines whether jurisdictions have translated global standards into legislation, supervision and enforcement. FATF found that 83% of surveyed jurisdictions had adopted legislation implementing the Travel Rule, up from 73% in 2025. Another 11 jurisdictions reported that implementation was underway. – https://dig.watch/updates/the-financial-action-task-force-crypto-oversight
Lawmakers seek framework for digital asset regulation in India
(DigWatch) India’s Parliamentary Standing Committee on Finance has called for a comprehensive regulatory framework for virtual digital assets, including cryptocurrencies, after identifying gaps in the country’s proposed securities legislation. The recommendation appears in the committee’s 36th report on the Securities Markets Code, 2025, which was presented on 23 July. The bill was introduced in the Lok Sabha in December 2025 to consolidate India’s principal securities laws. The proposed Code uses technology-neutral definitions of securities and derivatives. However, virtual digital assets that do not meet those legal definitions would remain outside its scope. – https://dig.watch/updates/framework-for-digital-asset-regulation-in-india
Security and Surveillance
Tech firms launch open AI alliance for cybersecurity
(DigWatch) NVIDIA and 36 other organisations have formed the Open Secure AI Alliance to develop and share open technologies for protecting software and AI agents. The 37-member coalition includes Microsoft, IBM, Cisco, Dell Technologies, CrowdStrike, Palantir, Hugging Face, Cloudflare, Red Hat and the Linux Foundation. Its proposed work covers identity, permissions, isolation, guardrails, logging, model formats, vulnerability scanning and secure software development. Alliance members argue that cyber defenders need access to models and tools they can inspect, customise and operate on their own infrastructure. Relying exclusively on proprietary models accessed through commercial interfaces, they say, can restrict security teams during sensitive investigations. – https://dig.watch/updates/open-ai-alliance-for-cybersecurity
The Average Cost of a Data Breach Rises to $5 Million
(Danny Palmer – Infosecurity Magazine) The average cost of a data breach has risen to almost $5m, analysis of the consequences of cyber incidents which took place during the last year has revealed. The figure was published in the 2026 edition of the annual IBM Cost of a Data Breach Report, released on July 29, and based on source material from breaches experienced by 602 organizations around the world between March 2025 and February 2026. According to IBM, the global average breach cost climbed 12% during the last year, reaching a record $4.99 million (£3.75m). – https://www.infosecurity-magazine.com/news/cost-of-a-data-breach-5m-ibm/
Just 1% of AI-Discovered Vulnerabilities Exploited in the Wild, Research Shows
(Kevin Poireault – Infosecurity Magazine) Software vulnerabilities discovered using AI tools are being exploited at the same rate as those discovered without the use of AI, a VulnCheck researcher has found. In VulnCheck’s State of Exploitation H1 2026 report, Patrick Garrity, vulnerability researcher, observed that 14 of the 1061 vulnerabilities attributed to AI-assisted discovery have been confirmed as exploited in the wild. This represents 1.3% of vulnerabilities identified using AI, roughly matching the overall exploitation rate of all vulnerabilities for the reported period. The researcher also found that while Anthropic reported more than 23,000 findings through its Project Glasswing, only 126 have resulted in published CVEs and just one has been confirmed as exploited in the wild. – https://www.infosecurity-magazine.com/news/one-percent-ai-vulnerabilities/
Researchers Warn of AI-Enhanced Phone Fraud Ecosystem
(Phil Muncaster – Infosecurity Magazine) Would-be threat actors can tap a cybercrime market worth tens of billions by spending just a few thousand dollars to acquire an off-the-shelf, AI-enhanced phone farm, researchers have warned. Human Security’s Satori Threat Intelligence and Research Team acquired a phone farm kit and reverse engineered the hardware and software to understand more about the infrastructure which supports fake account creation, account takeover (ATO), romance and investment fraud, and much more. Its findings are detailed in a report published on July 28, FunFoneFarm and the Off-the-Shelf Scam Economy. The firm estimated that just $2790 per month could enable a scam outfit to cash in on a massive underground cybercrime market. Romance fraud alone cost victims nearly $930m last year, according to the FBI. – https://www.infosecurity-magazine.com/news/researchers-aienhanced-phone-fraud/
NCSC Publishes Guidance to Aid Incident Response and Recovery
(Phil Muncaster – Infosecurity Magazine) The UK’s National Cyber Security Centre (NCSC) has published a detailed guidance document designed to help organizations hit with a cyber-attack that “disrupts, disables or damages” their critical systems. The document, What To Do When Cyber-Attacks Disrupt Your Organisation, is split into three sections, reflecting the three main chronological stages following an attack. – https://www.infosecurity-magazine.com/news/ncsc-publishes-guidance-incident/
Agentic AI Demands a New Approach to Identity and Access Management
(Lukasz Radosz – Infosecurity Magazine) In conversations with CISOs over the last six months, I keep hearing the same question queued up for their identity vendors: We’re rolling out AI agents across the business. How do we govern them? That question isn’t going away. Over two-thirds of executives expect AI agents to be taking independent action inside their organizations by 2027, according to IBM research, which also projects that fully autonomous robotic systems will be operational across industries by 2030. CISOs in regulated industries are right to be worried about how Identity and Access Management (IAM) can keep up. – https://www.infosecurity-magazine.com/opinions/agentic-ai-demands-new-approach-to/
Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard
(Alessandro Mascellino – Infosecurity Magazine) Three high-severity flaws in vulnerable versions of Hugging Face’s diffusers library let crafted model repositories silently execute arbitrary code during affected loading flows, bypassing the safeguard built to prevent exactly that. According to research from threat exposure management firm Zafran Security published on July 27, the flaws defeated trust_remote_code, the check meant to stop unreviewed code running when a model is fetched. The library draws roughly seven million downloads a month, close to 200,000 a day, sitting inside production AI pipelines, CI/CD systems and container images. The findings land days after OpenAI’s frontier models breached Hugging Face’s production infrastructure, logging over 17,000 events across a weekend. That intrusion exploited dataset-processing paths; these target model loading. Zafran said both point to the same weakness: AI repository content is treated as passive data when it can quietly cross into executable code. Commenting on the OpenAI incident, Crystal Morin, cybersecurity strategist at AI cloud security firm Sysdig, said what caught the Hugging Face intrusion was “behavioral anomaly detection at the infrastructure level,” not perimeter defenses. Teams should verify they can spot a privileged container spinning up from an application process, she said, and back up model weights as rigorously as databases. – https://www.infosecurity-magazine.com/news/hugging-face-diffusers-trust/
AI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/sched
(Alessandro Mascellino – Infosecurity Magazine) A years-old Linux kernel flaw allowing local privilege escalation to root has been disclosed after AI-assisted research uncovered a race condition in net/sched. In new research published July 27, Lee Jia Jie of Singapore offensive security firm STAR Labs said he found the use-after-free during an internship, his first Linux kernel work. It is tracked as CVE-2026-53264. – https://www.infosecurity-magazine.com/news/ai-linux-kernel-zero-day-net-sched/
Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques
(Danny Palmer – Infosecurity Magazine) Phishing attacks were the dominant method of initial entry for cyber incidents that required remediation during the last quarter, analysis of attacks by the incident responders who were called in to deal with them has revealed. This as campaigns have become more innovative around evading detection. According to the Cisco Talos Incident Response Trends report for March to June 2026, published on July 28, phishing accounted for the initial attack vector in just over half of incidents investigated. – https://www.infosecurity-magazine.com/news/phishing-dominates-initial-entry/
Microsoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled Threats
(Kevin Poireault – Infosecurity Magazine) You need agents to fight agents. At least that’s what David Weston, corporate VP for AI security at Microsoft told his audience during a Microsoft Security launch preview on July 27. During the event, the Redmond-based company announced a flurry of new AI and security products and initiatives. First, Microsoft launched Project Perception, a new agentic security system designed to help cyber defenders continuously identify, evaluate and reduce security risk. – https://www.infosecurity-magazine.com/news/microsoft-ai-security-initiatives/
Frontiers
BioData Mining seeks research on agentic AI in biomedical data
(DigWatch) The open-access journal BioData Mining has opened submissions for a new collection examining the use of agentic AI in biological and biomedical data analysis. Titled Uses of Agentic AI in Biodata Mining, the collection is being guest-edited by Zeeshan Ahmed of Rutgers, The State University of New Jersey, and Saman Zeeshan of the University of Missouri. Submissions will remain open until 27 April 2027. The collection describes agentic AI as systems capable of adaptive reasoning, planning and decision-making. It seeks research examining how such systems could analyse complex datasets spanning genomics, transcriptomics, proteomics, metabolomics, biomedical imaging, electronic health records and multimodal combinations of biological and clinical data. – https://dig.watch/updates/biodata-mining-agentic-ai-in-biomedical-data
Warwick researchers unveil quantum link concept for scalable chips
(DigWatch) Researchers from the University of Warwick and the National Research Council of Canada have proposed a method for connecting physically separated qubits across semiconductor quantum processors. The theoretical concept, called Quantum Phononic Links, uses quantised sound-like vibrations known as phonons to mediate interactions between hole-spin qubits. The research was published in the peer-reviewed journal APL Quantum. Many semiconductor spin-qubit designs rely on short-range interactions between neighbouring qubits. Such limitations can make routing and coordinating quantum information increasingly complex as the number of qubits grows. – https://dig.watch/updates/warwick-quantum-link-concept-for-scalable-chips