Governance, Regulation, Legislation, Governance
India expands AI strategy across government and public services
(DigWatch) India has outlined an ambitious expansion of AI across government, identifying hundreds of potential applications while investing simultaneously in computing infrastructure, domestic AI models, governance and workforce development. The government identified 762 potential AI applications across 62 ministries and departments, spanning operational efficiency, public services and sector-specific challenges. The use cases emerged after ministries were encouraged to explore practical AI deployments during the India AI Impact Summit in February 2026. – https://dig.watch/updates/india-government-ai-rollout-762-use-cases
China updates IP framework to support emerging technologies
(DigWatch) China has announced plans to strengthen intellectual property rights (IPR) protection under its 15th Five-Year Plan (2026–2030), positioning IP policy as a key pillar of its strategy for advancing AI and other frontier technologies. According to the China National Intellectual Property Administration (CNIPA), the strategy aligns IP policy with the country’s broader objectives of technological innovation, industrial development and high-standard opening up. – https://dig.watch/updates/china-ip-framework-emerging-technologies
South Korea launches alliance to expand AI data centre infrastructure
(DigWatch) South Korea’s Ministry of Science and ICT has launched a public-private alliance to accelerate the development of AI data centres, positioning digital infrastructure as a strategic pillar of the country’s long-term AI and industrial policy. The alliance brings together government agencies, private companies and academic institutions to coordinate the development of AI data centres, covering cloud infrastructure, energy supply, cooling technologies and the regulatory environment needed to support long-term growth. – https://dig.watch/updates/south-korea-public-private-ai-infrastructure
Germany launches national framework for EU AI Act
(DigWatch) Germany’s AI Market Surveillance and Innovation Promotion Act, known as AI-MIG, entered into force on 29 July, establishing the country’s national framework for implementing and enforcing the EU AI Act. The legislation gives the Federal Network Agency (Bundesnetzagentur) several central responsibilities. It will act as a market surveillance authority, national coordination and competence centre, single point of contact and central complaints body for the EU regulation. Bundesnetzagentur will directly supervise AI systems used in certain sensitive areas, including employment, critical infrastructure and education, as well as systems incorporated into radio equipment. It will also monitor prohibited AI practices and transparency obligations within its areas of responsibility. – https://dig.watch/updates/germany-launches-national-framework-for-eu-ai-act
Experts call for stronger governance of digital identity systems
(DigWatch) Financial Innovation for Impact (Fii) and the Cambridge Centre for Alternative Finance (CCAF) have launched a global study examining how electronic know-your-customer and digital identity systems are being implemented. The Global e-KYC Landscape Study includes separate surveys for public authorities and industry participants, both of which are open until 5 October 2026. Researchers aim to compare adoption across regions and income groups, identify implementation barriers and assess the benefits delivered by existing systems. The initiative forms part of Fii’s Digital Public Infrastructure Regulatory Programme, led in partnership with CCAF and supported by the Gates Foundation. – https://dig.watch/updates/experts-call-governance-digital-identity-systems
Legal analysis flags WTO risks in EU Cybersecurity Act 2.0 revision
(DigWatch) The European Commission’s proposed revision of the Cybersecurity Act could conflict with international trade rules by enabling restrictions based on suppliers’ links to particular countries, according to a legal analysis by former WTO Appellate Body member and chair Peter Van den Bossche. Proposed by the Commission in January 2026, the revised act would establish a trusted information and communications technology supply chain framework alongside changes to the European cybersecurity certification system. – https://dig.watch/updates/analysis-wto-risks-in-eu-cybersecurity-act-2-0
OECD says AI could strengthen market leaders
(DigWatch) AI could help smaller businesses compete with established companies, but its benefits may disproportionately favour firms that already control valuable data, talent and computing resources, according to new OECD research. The working paper distinguishes between companies that use AI and those that develop it, as well as between generative and non-generative systems. It finds that the effects on competition vary considerably depending on the technology and a company’s market position. Firm-level analysis covering France and Portugal between 2011 and 2022 found no systematic association between the adoption of non-generative AI and increased market power. Companies using AI tended to be larger and more productive, but their mark-ups were not substantially higher than those of other firms. – https://dig.watch/updates/oecd-says-ai-could-strengthen-market-leaders
CERRE paper questions whether EU consumer law is ready for agentic AI
(DigWatch) A new paper from the Centre on Regulation in Europe (CERRE) argues that existing EU consumer law may not be equipped for the rise of agentic AI, as autonomous systems increasingly move beyond recommending products to making purchasing decisions on behalf of consumers. The paper argues that EU consumer law is built on the assumption that a human makes the final purchasing decision—an assumption that weakens once AI agents act as intermediaries between consumers and traders. With some estimates suggesting agentic AI could handle 10% to 20% of e-commerce transactions by 2030, the authors argue that several existing legal requirements become difficult to apply. – https://dig.watch/updates/cerre-paper-eu-consumer-law-agentic-ai
AI’s Economic Winners
(Rebecca Patterson – Council on Foreign Relations) The last decade has seen economics and financial markets play increasingly center-stage roles in driving countries’ national security and geopolitical goals. Those with greater economic and market resources, both broadly and through narrow but critical points of leverage, had a greater ability to shape global power dynamics. That trend has now collided with a separate structural change that is advancing at an incredible pace: the development of artificial intelligence (AI). The influence that AI has on different countries’ economic futures and resulting geoeconomic abilities will help define the global balance of power. So who is most likely to see the greatest economic benefits of AI? It’s an impossible question to answer with much confidence, given all the unknowns about the speed and shape of AI’s future development as well as how countries and companies navigate the innovation. That said, there are several variables that can help determine which countries are most likely to be able to capture AI in a way that most strongly supports their respective economies. While developing frontier models can help drive economic “winners,” it is not the only path to faster economic growth. Put another way, the United States and China, leading the frontier AI model race, will not necessarily become the largest economic beneficiaries. Equally important will be a country’s labor-market structure, fiscal capacity, financial markets, social readiness, and the interconnection between potential labor displacement and consumer demand. Winners in this race will also need to maintain strong relationships with supply-chain allies. In addition, there will almost certainly be countries that are not broad AI economic winners but still retain geoeconomic leverage thanks to dominating a key input required for AI to function. – https://www.cfr.org/articles/ais-economic-winners
Privacy blockchains challenge traditional monitoring tools, Chainalysis says
(DigWatch) Different approaches to blockchain privacy require distinct compliance and monitoring methods, according to analysis published by blockchain intelligence company Chainalysis. The company examined four privacy architectures used by Canton Network, Zcash, Solana and Aztec. Each system conceals and discloses different transaction information, affecting how financial institutions, auditors and regulators can review activity. Canton uses sub-transaction privacy, under which participants receive only the information needed for their role in a transaction. Regulators, auditors and other authorised parties can access when explicitly included in the relevant data-sharing arrangements. – https://dig.watch/updates/privacy-focused-blockchains-challenge-crypto
South Korea advances broad crypto regulatory framework
(DigWatch) South Korea’s Financial Services Commission (FSC) is preparing comprehensive digital asset legislation that would establish new rules for stablecoins, cryptocurrency exchanges and broader crypto market activity, as the country continues to build a long-term regulatory framework for digital assets. The proposed Digital Asset Basic Act would consolidate several cryptocurrency-related bills currently under consideration in the National Assembly. It would introduce rules covering stablecoin issuance, exchange operations, disclosures, internal controls and operational security, although key questions remain unresolved, including ownership limits for major exchanges and requirements for issuers of won-denominated stablecoins. – https://dig.watch/updates/south-korea-stablecoin-regulation-framework
Ten European institutions launch blockchain for tokenised assets
(DigWatch) Ten European financial institutions have launched Regulated Layer One (RL1), a member-owned blockchain cooperative for regulated markets and institutional digital assets. RL1 has been established in Luxembourg as a European Cooperative Society. Its founding members are ABN AMRO, Cecabank, Chartered Investment, Crédit Mutuel Alliance Fédérale, DekaBank, DZ BANK, LBBW, Natixis CIB, SC Ventures and Seturion. Each member holds equal decision-making rights over the network’s governance and development. RL1 says the structure is intended to prevent any single institution or group of network operators from exercising excessive control. – https://dig.watch/updates/european-banks-launch-rl1-blockchain-network
IMF urges stronger stablecoin market oversight in Brazil
(DigWatch) The International Monetary Fund (IMF) has urged Brazil to strengthen oversight of its growing stablecoin market, warning that cross-border crypto flows are becoming increasingly sensitive to global financial shocks and could create new channels for financial volatility. The IMF’s latest Financial System Stability Assessment found that Brazil’s digital asset market has expanded rapidly since 2017, with dollar-backed stablecoins emerging as a major source of cross-border activity. – https://dig.watch/updates/imf-oversight-brazil-stablecoin-market
Bank of Russia drafts rules for regulated crypto market
(DigWatch) The Bank of Russia has published its first draft regulations for organised cryptocurrency trading, following parliamentary approval of a wider framework governing digital assets. Under the proposals, exchanges would determine how digital currencies and digital rights are traded through their own rules. They would also calculate market and weighted average prices, disclose trading information and submit data to the central bank. The regulator has proposed requirements for a new category of market participant known as digital depositories. These entities would record holdings and transfers of cryptocurrencies and digital rights, operating on principles similar to traditional securities depositories. – https://dig.watch/updates/russia-crypto-digital-currency-trading-rules
Security, Surveillance
Researchers Expose Flying Eagle Criminal Ecosystem Behind Fake Chinese Police App
(Pierluigi Paganini – Security Affairs) Hunt.ioresearchers and independent journalist NetAskari started with a fraudulent Android app impersonating a Chinese Provincial Public Security Bureau service and ended up mapping a sprawling criminal ecosystem built around a leaked Android RAT framework called Flying Eagle, 飞鹰. The investigation found 170 active servers, two Telegram channels distributing modified versions of the stolen codebase, and a likely successor platform already in version 2 development. Chinese state media had already warned citizens about the fake police app in June 2026. Nobody had yet traced what was behind it. “Analysis of the malware led to a Telegram channel distributing the source code for an undocumented Android application builder and device control framework called Flying Eagle (飞鹰). Hunt.io researchers pivoted on TLS certificates and panel fingerprints to identify 170 servers running the framework, and uncovered a fractured criminal ecosystem built around its leaked codebase.” reads the report published by Hunt.io. “Flying Eagle combines APK generation and full-featured C2 device management in a single panel, with phishing overlays for financial, adult, and government service apps. The source code was stolen in early 2026, along with nearly 200 customer databases, leading to multiple modified variants circulating across criminal actors”. The leak turned a single commercial RAT into an open toolkit that anyone willing to pay 2,000 USDT for a “fixed” version, or nothing at all for the free Docker release dropped on Telegram in April, could deploy. The framework is more capable than most MaaS offerings at this price point. – https://securityaffairs.com/196369/malware/researchers-expose-flying-eagle-criminal-ecosystem-behind-fake-chinese-police-app.html
Why brand impersonation is becoming an initial access vector
(Pierluigi Paganini – Security Affairs) Attackers recently poisoned more than 700 websites, including sites run by Harvard, Oxford, and DuckDuckGo. They used a fake Cloudflare page to trick visitors into running a ClickFix attack that installed malware. Researchers tracing the incident found the same injected code running across hundreds of unrelated sites, all feeding shared attacker infrastructure. That Harvard and Oxford can get turned into malware delivery platforms is concerning. That two rival criminal groups were fighting each other for control of the same hijacked sites is cause for immediate action. Whether you’re a university, online retailer, financial institution, or anything in between, brand impersonation is no longer merely a reputational irritation. It’s attacker infrastructure, and you need to act accordingly. – https://securityaffairs.com/196359/hacking/why-brand-impersonation-is-becoming-an-initial-access-vector.html
Cybercriminals Are Leveraging Autonomous AI Offensive Security Agents
(Pierluigi Paganini – Security Affairs) Resecurity analyzed how autonomous offensive security agents such as T3MP3ST, Strix, CyberStrike, XBOW, PentAGI, PentestGPT, and Nebula lower the barriers to vulnerability identification and exploitation. The analysis also explores why AI is being repurposed for real attacks and what defenders should do in response. From a broader perspective, cybercriminals and foreign adversaries are expected to leverage AI to maximize the impact of cyberattacks, while also optimizing and scaling malicious activity —creating a race between AI-driven attackers and defenders. Beyond frontier models like Mythos, the report details how modern offensive security agents such as T3MP3ST, Strix, CyberStrike, XBOW, PentAGI, PentestGPT, Ethiack Nebula, and specialized LLMs like CyberStrike-OffSec-35B, have lowered the barriers to vulnerability identification and exploitation. Increasingly, these tools are becoming available to financially motivated cybercriminals, who would otherwise lack the technical abilities to carry out sophisticated attacks. Artificial intelligence is rapidly transforming offensive security from isolated automation into autonomous, multi-agent systems capable of mapping attack surfaces, identifying vulnerabilities, validating exploits, and producing technical reports with minimal human intervention. According to Resecurity, AI agents are redefining how cybersecurity assessments are performed while also introducing new dual-use risks – leading to data breaches and network intrusions orchestrated via AI. – https://securityaffairs.com/196331/ai/cybercriminals-are-leveraging-autonomous-ai-offensive-security-agents.html
Analog Devices Discloses Data Breach After Unauthorized System Access
(Pierluigi Paganini – Security Affairs) Semiconductor giant Analog Devices (ADI) disclosed a data breach following a cyberattack that resulted in unauthorized access to some of its systems on June 23. Analog Devices, Inc. (ADI) is a major semiconductor company that designs and manufactures integrated circuits (ICs) used to convert, process, and manage real-world signals in electronic systems. Unlike companies that mainly produce processors or memory chips, ADI specializes in analog and mixed-signal semiconductors, which act as the bridge between the physical world and digital systems. Analog Devices immediately activated its incident response plan, involving cybersecurity experts and law enforcement. The company confirmed that certain files were exfiltrated, but the investigation into the scope and nature of the stolen data is still ongoing. The US company, which generates around $12 billion in annual revenue, reported the incident to the SEC. – https://securityaffairs.com/196320/data-breach/analog-devices-discloses-data-breach-after-unauthorized-system-access.html
FCC Restricts New Foreign Robots and Inverters Over Security Risks
(Pierluigi Paganini – Security Affairs) The FCC just widened its Covered List again, this time adding foreign-produced advanced robotic devices and power inverters. In plain terms, that means new models in those categories generally can’t get the equipment authorization they need for import, marketing, or sale in the US, although already authorized devices can still be sold and used. “The Federal Communications Commission’s Office of Engineering and Technology (OET) announces that certain prohibitions contained in 47 CFR §§ 2.932(b) and 2.1043(b) will not apply for now to certain foreign-produced advanced robotic devices and power inverters. All advanced robotic devices and power inverters authorized for use in the United States may continue to receive software and firmware updates that mitigate harm to U.S. consumers at least until January 1, 2029.” reads the FCC public notice. “These include all software and firmware updates to ensure the continued functionality of the devices, such as those that patch vulnerabilities and facilitate compatibility with different operating systems.” – https://securityaffairs.com/196308/security/fcc-restricts-new-foreign-robots-and-inverters-over-security-risks.html
eSIM Plus and Nicegram Share Belarus-Linked Codebase, Analysis Finds
(Pierluigi Paganini – Security Affairs) Two popular apps available in EU app stores, Nicegram, with over 50 million downloads, and eSIM Plus, with over 1 million, are presented to users as Lithuanian products. The Mysterium VPN Research Team pulled apart both Android packages to see what the binaries themselves reveal, following OCCRP reporting that both apps are allegedly developed and controlled from Belarus. What they found in the code substantially corroborates that reporting. “Most decisively, the eSIM Plus package is cryptographically signed by “Mobyrix, Minsk” (a Belarusian signature on an app marketed under the Lithuanian “Appvillis” brand), and it ships live integrations with two Russian services, Yandex AppMetrica (analytics) and Voximplant (call routing, via a .ru endpoint).” reads the report published by Mysterium VPN Research Team. “Nicegram shares the same “Appvillis” codebase and backend, though the specific Russian SDKs aren’t present in the Nicegram build we examined.” – https://securityaffairs.com/196280/security/esim-plus-and-nicegram-share-belarus-linked-codebase-analysis-finds.html
Post-quantum signature candidate withdrawn after Claude finds weakness
(DigWatch) The team behind HAWK has withdrawn the post-quantum digital signature scheme from a US standardisation process after researchers using Anthropic’s Claude Mythos Preview discovered a substantially improved attack against it. HAWK had reached the third round of the National Institute of Standards and Technology’s evaluation of additional digital signature algorithms designed to withstand future quantum computers. The HAWK team confirmed Anthropic’s findings and said straightforward attempts to strengthen the scheme would make it uncompetitive. NIST subsequently updated its candidate list to record the withdrawal. – https://dig.watch/updates/claude-finds-weakness-post-quantum-signature
Eight countries align with new EU cyber sanctions
(DigWatch) Eight non-EU European countries have aligned their national policies with the European Union’s latest sanctions against Russian individuals and entities linked to malicious cyber operations. Albania, Bosnia and Herzegovina, Iceland, Moldova, Montenegro, North Macedonia, Norway and Ukraine. aligned themselves with a Council decision adopted on 13 July 2026. The decision added eight individuals and four entities to the EU’s cyber sanctions list. The targets include companies, cybercriminals and pro-Russian groups accused of facilitating ransomware, phishing, malware operations and attacks against critical infrastructure. – https://dig.watch/updates/eight-countries-align-with-new-eu-cyber-sanctions
Defence, Intelligence, Warfare
Chinese Research Details Distillation for Military Use
(Sunny Cheung – The Jamestown Foundation) Distillation has become essential to the rise of Chinese artificial intelligence (AI) models. Chinese academic and industry papers published in the period 2024–2026 detail how distillation takes place—including adversarial distillation—and provides insight into the kinds of entities involved in the work of using leading models to build capabilities that rival the world’s best models. The prize is frontier reasoning: the step-by-step “chain of thought” that is the most expensive capability to build and the one on which U.S. laboratories lead most clearly. The Chinese research literature documents a deliberate, premeditated effort to distill that capability. Some published Chinese research also focuses on engineering distillation techniques to evade detection. Much of this work is conducted by researchers affiliated with the People’s Liberation Army, the defense industry, and the Chinese Academy of Sciences. Distilled models are either already being used, or are proposed to be used, for public security applications such as surveillance and monitoring systems, and for military and cyber operations. – https://jamestown.org/chinese-research-details-distillation-for-military-use/
Frontiers
Hong Kong launches quantum readiness framework for banks
(DigWatch) The Hong Kong Monetary Authority (HKMA) has introduced a framework to help banks prepare for future quantum computing risks, linking post-quantum cybersecurity with the city’s expanding tokenised finance and digital asset ecosystem. The initiative includes a white paper and the banking sector’s first Quantum Preparedness Index, which currently places overall readiness at 2.3 out of 10 and sets full preparedness as a long-term objective by 2030. – https://dig.watch/updates/hong-kong-quantum-readiness-framework-banks