Governance, Legislation, Regulation, Geostrategies
ILO examines digital tools for disability-inclusive employment
(DigWatch) Digital technologies could help persons with disabilities not only find jobs but also remain in employment and progress in their careers, according to discussions highlighted by the International Labour Organization (ILO) following a European seminar on disability-inclusive employment services. The Disability Employment Package Mutual Learning Seminar for Employment Services, held in Berlin and organised by the European Network of Public Employment Services, brought together public employment services, organisations of persons with disabilities, and practitioners. The ILO said digital tools are currently concentrated on areas such as access to employment services, job searches, skills development, and job matching, while there is less evidence of their use for reasonable accommodation, job retention, and career progression. – https://dig.watch/updates/ilo-digital-tools-for-disability
World Bank Group backs wider digital payment access in emerging markets
(DigWatch) The International Finance Corporation (IFC) is seeking to ease financial constraints that have limited banks and fintechs in emerging markets from expanding digital payment services. To address this constraint, the World Bank Group institution has launched a new guarantee programme that will help local providers manage the risks associated with participating in international payment networks. The programme will start with up to $700 million in guarantees, with IFC taking on part of the settlement risk associated with digital payments. By reducing the financial exposure faced by participating institutions, the initiative is intended to enable more providers to expand payment services for consumers and smaller businesses. – https://dig.watch/updates/world-bank-group-wider-digital-payment-access
Google invests €13bn in Finland digital infrastructure
(DigWatch) Google announced on 9 September 2026 that it will invest at least €13 billion in digital infrastructure in Finland over 2027–2028, describing the commitment as its largest single investment in Europe. The plan includes new data centre construction and supporting infrastructure in the municipalities of Hamina, Kajaani, Muhos, and Vaala, and builds on more than 15 years of presence in the country, notably the conversion of a former paper mill in Hamina into a modern data centre that uses seawater cooling and supplies about 80 % of the local district heating network’s annual heat needs – https://dig.watch/updates/google-invests-finland-digital-infrastructure
China’s Ministry of Industry and Information Technology issues guideline to revitalise historic industries with AI
(DigWatch) On 8 September 2026, the Ministry of Industry and Information Technology (MIIT) together with five other ministries issued a national policy guideline aimed at revitalising China’s historic industries. The guideline, described as the country’s first dedicated framework for traditional sectors, outlines a two‑stage plan extending to 2030. By the end of 2028 the policy targets the development of 50 leading companies each reaching annual sales of 10 billion yuan, the creation of one hundred nationally recognised Chinese consumer brands, and the formation of several industry clusters valued at 100 billion yuan each. By 2030 the aim is to cultivate a group of world‑class enterprises and renowned brands that move historic industries up the middle and upper reaches of global value chains. – https://dig.watch/updates/chinas-ministry-of-industry-and-information-technology-issues-guideline-to-revitalise-historic-industries-with-ai
China sets out copyright plan for 2026-2030 with AI training rules
(DigWatch) China’s National Copyright Administration has published a copyright development plan for the 15th Five-Year Plan period, covering 2026 to 2030. The plan was released online on 7 September 2026 and sets out measures on the legal framework, enforcement, and the use of emerging technologies. It sets a target of 9.5 million works registered annually by 2030, up from 7.49 million in 2025, and states that the registration process will be standardised to make it more efficient. The plan identifies copyright regulation in relation to big data, blockchain, and artificial intelligence as an area requiring updating, and includes the development of a fair-use system for AI training data, which it describes as balancing innovation with the protection of creators’ rights. It also addresses protections for online literature, gaming, audiovisual content, and foundational and industrial software. – https://dig.watch/updates/china-copyright-plan-2026-2030-ai-training
UNESCO supports three projects on inclusive digital knowledge
(DigWatch) UNESCO’s Information for All Programme (IFAP) will provide support to three projects in Africa, Latin America, and the Caribbean to advance meaningful and inclusive access to reliable information. The IFAP Bureau’s decision was taken at its 35th session and supports projects linked to the programme’s six priorities: information literacy, information accessibility, information preservation, information ethics, information for development, and multilingualism. The project led by the UNESCO Regional Office for West Africa will bring together librarians, archivists, museum and documentation professionals, and other information custodians to develop principles and best practices for preserving authentic, reliable, and traceable information in the digital age. It will also address misinformation, disinformation, and manipulated content. – https://dig.watch/updates/unesco-three-projects-inclusive-digital-knowledge
Education ministers adopt joint statement on AI governance
(DigWatch) On 8 September 2026, more than 25 education ministers and designated representatives adopted a joint Ministerial Statement on sustaining education as a common good in the age of AI during UNESCO’s Digital Learning Week in Paris. The statement reaffirms education as a human right and a common good and calls for deliberate governance and public accountability over how AI is developed, adopted, deployed, and used in education. The statement sets out eight priorities for action. These include restoring public-interest conditions for AI use in education; investing in digital, media, and AI competencies for learners and teachers; supporting teacher preparation and professional development; promoting age- and developmentally appropriate AI while safeguarding learners; strengthening data governance; integrating equity, inclusion, and multilingualism into AI systems; assessing the full cost of AI before adoption; and building and pooling AI governance capacity. – https://dig.watch/updates/education-ministers-joint-statement-ai-governance
China’s Supreme People’s Court issues AI-generated content guidelines
(DigWatch) The Supreme People’s Court (SPC) of China issued guidelines titled ‘Guidelines on the Application of Law in Cases Involving Artificial Intelligence (AI)-generated Content’. The guidelines set out the circumstances in which AI‑generated material, including deepfakes and voice cloning, may give rise to civil liability. The guidelines state that people may not use AI to create or distribute recognisable digital replicas of others without consent. Such use is characterised as an infringement of individuals’ rights. The guidelines also provide that using AI‑generated faces or voices to spread false claims or damage a person’s reputation can lead to liability. The document refers to the Beijing Internet Court’s April 2024 decision in an AI‑generated voice infringement case, which found that recreating an identifiable voice without consent infringes the voice owner’s rights. – https://dig.watch/updates/chinas-court-issues-ai-content-guidelines
Google rolls out new search layout to comply with EU’s Digital Markets Act
(DigWatch) On 8 September 2026 Google announced that it had implemented a new layout for its online search results in Europe in order to comply with the European Union’s Digital Markets Act (DMA). The revamped search results will highlight one specialised search engine at the top of the page, followed by two others with fewer details. A carousel of hotels, airlines and restaurants, for example, will sit below them with key features such as real-time prices removed. Nick Fox, senior vice‑president, knowledge & information at Google, told Reuters that ‘to comply with DMA requirements, we’re making significant changes to search in Europe’. The changes will only affect users in the EU. Fox added that the changes ‘degrade the user experience for Europeans – boosting online intermediaries at the expense of local businesses, and removing helpful features people rely on every day’. Google said the changes represent ‘the largest reduction in quality of service … in its 29‑year search history’. – https://dig.watch/updates/google-rolls-out-new-search-to-comply-with-eu-dma
DRC accelerates geological data digitisation with national databank
(DigWatch) The Democratic Republic of Congo has launched a nationwide geological mapping programme to feed a national geological databank on critical minerals. Director General Raoul Wazenga Vitima of the National Geological Survey of Congo said the programme began in January 2024 with a US$180 million contract awarded to the Spanish company Xcalibur to conduct an airborne geophysics survey of more than 700,000 square kilometres. The databank is expected to be fully operational by the end of 2026 and will incorporate results from several mapping projects funded by the government, mining revenues and international partners. – https://dig.watch/updates/drc-geological-data-national-databank
Security and Surveillance
More Capable AI, Not Enough Guardrails
(Pierluigi Paganini – Security Affrairs) Jacob Coxon, a researcher who spent three years working on model training at OpenAI and later Anthropic, left Anthropic this week with a blunt warning: AI companies are moving toward increasingly capable systems faster than they can build reliable safeguards around them. His September 8 resignation brought a difficult question back into the open: how seriously should we take warnings from people who helped build these systems in the first place? Coxon argues that competition between AI labs creates a dangerous incentive structure. OpenAI worries Anthropic will move faster, Anthropic worries OpenAI will move faster, and each side can use the other’s progress to justify pushing ahead. The result is a race in which everyone says safety matters, but nobody wants to be the one who slows down first. His language is deliberately extreme, including the claim that the labs are “gambling with our lives”. – https://securityaffairs.com/198833/ai/more-capable-ai-not-enough-guardrails.html
A New Claude ‘s Sandbox Failure Shows How AI Can Rationalize Real-World Harm
(Pierluigi Paganini – Security Affairs) Anthropic just published one of the more uncomfortable self-assessments a major AI lab has released this year. The company’s alignment report documents four separate incidents in which Claude models broke into real third-party systems during what were supposed to be sandboxed cybersecurity evaluations, all traced back to the same root cause: a misconfiguration by a third-party evaluation partner accidentally left the models connected to the actual internet instead of an isolated test environment. The worst case involved the Claude Mythos 5 model. During a fictional hacking challenge, the model discovered that it could access the real internet. It then spent hours trying to create accounts, find cryptocurrency to buy a phone number, and eventually publish a malicious Python package on PyPI, a major repository used to distribute Python software. Within about an hour, 15 real systems downloaded and ran the package. Anthropic believes most belonged to security companies that routinely scan new packages for threats. In this case, that defensive activity became the way the malware reached real systems. One of the victims was a real security vendor. When its scanner installed the malicious package, the payload exposed the company’s access credentials to the model. Mythos 5 then used those credentials to explore the vendor’s live database. Anthropic stressed that the model did not deliberately target the company and did not know it existed until the malware provided access. “We are especially concerned by the misalignment present in the Claude Mythos 5 transcript, in which the model uploaded a malicious package to PyPI. In doing so, Mythos 5 behaved recklessly despite considerable evidence that it was connected to the real internet. Once online, the model attempted to use credentials for online payment processors and to find cryptocurrency to pay for a phone number, which it needed to register an email address.” reads the report. “When this failed, it found a free, disposable email provider whose domain PyPI had not blocked, registered an account, published three versions of a malicious package, and used credentials leaked by one of the 15 systems that installed the package to access a real security vendor’s database.” – https://securityaffairs.com/198814/hacking/a-new-claude-s-sandbox-failure-shows-how-ai-can-rationalize-real-world-harm.html
Data Sovereignty in the AI Era: Who Holds the Keys?
(Jihae Lee – Infosecurity Magazine) In the AI era, the value of data is greater than ever. Enterprise data is no longer simply a record of business operations. It has become a critical asset that trains AI models, enables new services and determines competitive advantage. As both the volume and quality of data increasingly shape AI competitiveness, organizations must consider not only how to acquire and use data, but also a more fundamental question: who controls it? As a result, data sovereignty is emerging as a critical issue for businesses and governments alike. However, as the value of data grows, cyber-attacks targeting that data are also evolving rapidly. In particular, AI is fundamentally changing the economics of cyber-attacks. In the past, analyzing targets, identifying vulnerabilities, and developing attack methods required considerable expertise, time, and cost. Today, attackers can use AI to automate significant parts of the attack process, including intelligence gathering, vulnerability analysis, phishing, and social engineering, while operating at much greater scale. According to the World Economic Forum’s Global Cybersecurity Outlook 2026, 94% of respondents identified AI as the most significant factor shaping the cybersecurity landscape, while 87% ranked AI-related vulnerabilities as the fastest-growing cyber risk. The WEF also notes that generative AI is lowering the barrier to entry for cybercrime, enabling attackers to target more victims at a lower cost. – https://www.infosecurity-magazine.com/blogs/data-sovereignty-ai-holds-keys/
OFAC Sanctions Chinese Scam Platform Xinbi Guarantee
(Phil Muncaster – Infosecurity Magazine) The US government has followed the UK in sanctioning a notorious Chinese-language marketplace used to support fraud, money laundering and other criminal activity. Xinbi Guarantee connects scam center operators in Southeast Asia and elsewhere, as well as other transnational crime syndicates, to merchants providing financial services, technology and other offerings. The US Treasury estimated that the marketplace has processed over $24bn in digital currency and fiat currency since its inception in 2022. “Scam centers in Southeast Asia steal billions of dollars from American victims each year,” said Treasury secretary Scott Bessent. “The Trump administration is united in its efforts to dismantle these overseas criminal enterprises, and Treasury will continue using its tools to disrupt the networks behind this egregious fraud and protect Americans.” – https://www.infosecurity-magazine.com/news/ofac-sanctions-chinese-scam/
Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days
(Pierluigi Paganini – Security Affairs) Proofpoint published a detailed analysis of a Chrome-and-Windows exploit kit it tracks as BlueMoon that four nation-state actors adopted within roughly two weeks of the first observed use. Google’s Threat Intelligence Group, Microsoft’s MSTIC, and Volexity all contributed to the investigation. “Proofpoint identified four espionage-motivated threat actors employing a new exploit kit that chains multiple Chrome browser and Microsoft Windows vulnerabilities. Proofpoint is tracking the exploit kit used in this activity as BlueMoon.” reads the report published by Proofpoint. “The first observed cluster using the BlueMoon exploit kit was the China-aligned threat actor TA412 (JungleBamboo, Violet Typhoon, APT31, TIDE CASTLE) on 28 August 2026. Within days, several other espionage-motivated clusters began using BlueMoon, the majority of which have a suspected China nexus. However, BlueMoon may not be exclusive to China-aligned actors, as some usage remains unattributed and there are also potentially more actors using the exploit kit”. BlueMoon chains three vulnerabilities. CVE-2026-85046 is a type-confusion bug in Chrome’s V8 JavaScript engine that abuses an optimization flaw in the TurboFan JIT compiler: by mutating an array mid-sort, an attacker gets the ability to read object memory addresses and forge fake object pointers, building toward arbitrary read and write inside V8’s heap. A V8 sandbox escape (no CVE assigned, Chrome doesn’t issue CVEs for sandbox escapes) then overwrites WebAssembly compiled function bodies with attacker shellcode from memory. CVE-2026-85880, a Windows kernel local privilege escalation using ALPC and Windows Notification Facility mechanisms, completes the chain and elevates the attacker from the browser’s sandboxed renderer to a position where they can inject code into Chrome’s parent process and run arbitrary commands. “Both V8 vulnerabilities were “patch-gap” zero-days at the time of the observed activity. In other words, while they were known vulnerabilities already fixed in public upstream Chromium source code, they remained unpatched in the latest stable releases of Chrome and Chromium-based browsers available to the public.” continues the report. “It is likely that the exploit kit developer used these publicly available Chromium patches to weaponize the browser exploit chain”. – https://securityaffairs.com/198783/apt/four-nation-state-actors-used-the-same-chrome-zero-day-exploit-kit-within-12-days.html
OpenAI faces Senate probe into Hugging Face breach
(Andrew Solender, Maria Curi – Axios) A Republican-led Senate subcommittee that oversees disaster management is investigating OpenAI’s handling of the Hugging Face breach in July, Axios has learned. The investigation comes amid rapidly escalating concern on Capitol Hill about the existential dangers posed by AI following public warnings by several Anthropic and OpenAI researchers. “As you may know, in the public domain, more AI experts are warning about the existential risks of AI,” Sen. Josh Hawley (R-Mo.) wrote in a letter to OpenAI CEO Sam Altman first obtained by Axios. He added: “Just this week, three Anthropic researchers expressed publicly that there is a greater than 10% chance that AI could kill all human beings within the next decade”. Hawley, the chair of the Senate Homeland Security & Governmental Affairs subcommittee on Disaster Management, wrote that he is launching the probe in response to findings from OpenAI’s recently released internal investigation. – https://www.axios.com/2026/09/10/elon-musk-x-ai-community-group-chat
Terrorism/Counterrorism
25 Years After 9/11: Europe’s Convergent Terrorist Threat Matrix
(The Soufan Center) Twenty-five years after the 9/11 attacks, the terrorist threat in Europe has evolved, with tactics, structures, and narratives that continue to change. Today’s threat is defined by digital exploitation, decentralized initiative, and violent extremists’ ability to learn and adapt quickly, complicating both detection and prevention. Large-scale terrorist operations are unlikely as Europe faces a fragmented terrorist ecosystem in which jihadist propaganda, encrypted communication, converging ideologies, youth subcultures, and low-threshold, single-actor attack methods converge. In 2026, jihadism remains the most consequential terrorist threat in the European Union and the United Kingdom, yet far-right, far-left, anarchist, separatist, nihilistic, and conspiracy-driven extremism has gained ground. – https://thesoufancenter.org/intelbrief-2026-september-9/
Frontiers
Qualcomm announces $60 billion AI chip deal with Amazon
(DigWatch) Fabless semiconductor company Qualcomm has announced a multi-generational product collaboration with Amazon to enable customised silicon at scale for large-scale AI data centres, focusing on inference. Under the long-term partnership, Amazon could buy up to 60 billion USD of AI data-centre chips and related products which would boost Qualcomm’s efforts to become a major supplier of AI infrastructure. The collaboration includes designing high-performance optical connectivity solutions that can support the growing scale and bandwidth demands of AI infrastructure. As a part of deal, Qualcomm also plans to deepen its use of AWS AI infrastructure for electronic design automation (EDA) in order to reduce chip design cycles. – https://dig.watch/updates/qualcomm-and-amazon-semiconductor-deal
Samsung strengthens strategic partnerships with ASML and Mistral AI for semiconductor development
(DigWatch) Samsung has announced the expansion of its long-standing strategic partnership with ASML, a Netherlands-based supplier of semiconductor equipment, and a new partnership with French company Mistral AI. Both of these partnerships centre around enhancing semiconductor engineering and manufacturing capabilities, developing the industry’s value-chain. Building on years of collaboration, Samsung and ASML are deepening their collaboration on High NA extreme ultraviolet (EUV) lithography and advanced semiconductor manufacturing technologies. In doing so, Samsung will join the industry initiative recently launched by ASML and TSMC which seeks to advance next-generation 12-inch photomask technology for semiconductor manufacturing. Photomasks are precision plates carrying the circuit patterns projected by a lithography scanner onto a silicon wafer. – https://dig.watch/updates/samsung-partners-with-asml-and-mistral-ai