Weekly Digest on AI and Emerging Technologies (14 September 2026)

Daily Digest on AI and Emerging Technologies (8 september 2026) – https://pam.int/daily-digest-on-ai-and-emerging-technologies-8-september-2026/

Daily Digest on AI and Emerging Technologies (9 september 2026) – https://pam.int/daily-digest-on-ai-and-emerging-technologies-9-september-2026/

Daily Digest on AI and Emerging Technologies (10 september 2026) – https://pam.int/daily-digest-on-ai-and-emerging-technologies-10-september-2026/

Daily Digest on AI and Emerging Technologies (11 september 2026) – https://pam.int/daily-digest-on-ai-and-emerging-technologies-11-september-2026/

 

 

Governance, Legislation, Regulation, Geostrategies

UN report calls for Global Fund on AI capacity-building

(DigWatch) On 11 September 2026, the United Nations Secretary-General submitted a report to the General Assembly finding that financing for artificial intelligence (AI) capacity building remains fragmented and leaves significant geographical gaps. The report, Unique challenges faced by developing countries in artificial intelligence capacity-building (A/80/817), was submitted pursuant to General Assembly resolution 78/311 and recommends steps towards establishing a global fund for AI capacity-building. – https://dig.watch/updates/un-report-global-fund-on-ai-capacity-building

ITU-coordinated initiative U4SCC releases guide on autonomous cities and AI

(DigWatch) Coordinated by the International Communications Union (ITU), UN-Habitat, and the United Nations Economic Commission for Europe (UNECE), the United for Smart Sustainable Cities Initiative (U4SSC) published a guide discussing ‘Autonomous cities and AI: The next frontier of urban transformation’. The document presents a structured framework for understanding, assessing and advancing autonomous cities while stressing the value of retaining ‘human governance’ under which ‘human institutions, public objectives and autonomous technologies interact to improve urban performance and resilience’. The initiative is also supported by a network of partners that include FAO UNDP, UNESCO, and UNEP amongst many others. – https://dig.watch/updates/itu-releases-guide-on-autonomous-cities

China Mining News releases Global Mining Development Report 2026

(DigWatch) The China Mining News – part of the China Geological Survey (a public institution managed by the Ministry of Natural Resources) – has released Global Mining Development Report 2026 during 2026 China Mining Conference and Exhibition. The publication – reported by China Daily – underscores the growing role of artificial intelligence and related digital technologies in mineral exploration, autonomous equipment and data‑driven decision‑making, positioning them as central to the transformation of the global mining sector and to the development of international standards for critical minerals. – https://dig.watch/updates/china-releases-global-mining-report-2026

California signs child online safety and AI bills into law

(DigWatch) California Governor Gavin Newsom has signed a package of child online safety and AI measures that had recently cleared the state Legislature, turning several proposals on social media design, AI companion chatbots and children’s privacy into law. The bills were signed on 10 September 2026. The package includes SB 1119, known as Adam’s Law, which introduces stronger safeguards for children using companion chatbots. It requires crisis protocols where a child expresses suicidal thoughts, parental controls, notifications when safety settings are disabled, independent child-safety audits and annual risk assessments. – https://dig.watch/updates/california-signs-child-online-safety-ai-laws

China and SCO members expand cooperation on AI in education

(DigWatch) China and other members of the Shanghai Cooperation Organization (SCO) are expanding cooperation in basic education through a new centre in Beijing, with artificial intelligence and digital education among the areas expected to support their work. The China-SCO Basic Education Cooperation Center was unveiled on 10 September in Beijing’s Chaoyang District. Education authorities from SCO member states and basic education institutions across China are expected to use the centre to exchange experience and develop cooperation in education. – https://dig.watch/updates/china-sco-members-education-centre-ai-cooperation

South Korea forecasts 25–30 GW of AI-related power demand

(DigWatch) South Korea expects electricity demand to rise sharply as AI data centres and semiconductor production expand. Climate, Energy, and Environment Minister Kim Sung-whwan told Reuters that AI-related demand alone could add 25–30 gigawatts to national power needs, alongside additional pressure from electric vehicles and the shift from gas to electric heating. The government is preparing an updated long-term energy roadmap to 2040, due next month. The expected increase is prompting South Korea to consider whether additional nuclear power plants will be needed. Kim described nuclear energy as an essential part of the country’s future power mix, although the number of possible new reactors remains under review. South Korea currently operates 26 reactors, which provide just under one-third of its electricity, while renewables account for about 11%, coal 29% and gas 27%. – https://dig.watch/updates/south-korea-ai-data-centre-electricity-demand

Canada updates banking framework for crypto and tokenised deposits

(DigWatch) Canada’s banking regulator is taking a more accommodating approach to tokenised deposits and selected crypto-asset activities, while maintaining prudential safeguards for financial institutions. The Office of the Superintendent of Financial Institutions (OSFI) has clarified that tokenised deposits are ‘not legally distinct’ from traditional deposits, meaning their underlying technology does not determine their legal treatment. – https://dig.watch/updates/canada-framework-crypto-and-tokenised-deposits

Security and Surveillance

European Commission launches Security Research and Innovation Campus to strengthen EU security

(DigWatch) The European Commission has launched a new Security Research and Innovation Campus at the Joint Research Centre (JRC) in Ispra, Italy, to strengthen the EU’s response to evolving security challenges and hybrid threats. The initiative forms part of the ProtectEU Internal Security Strategy and is intended to bring scientific research closer to the operational needs of European security authorities. The Campus brings together JRC laboratories and expertise across six interconnected areas: space, connectivity, and quantum; border management; crisis management; defence; internal security; and nuclear security. The approach is designed to support the development and deployment of security technologies while allowing research priorities to adapt to changing threats. – https://dig.watch/updates/european-security-research-and-innovation-campus

Cyber Resilience Act reporting obligations begin for manufacturers

(DigWatch) Reporting obligations under the EU Cyber Resilience Act apply from 11 September 2026. Manufacturers of products with digital elements must now report actively exploited vulnerabilities and severe incidents affecting the security of their products to the European Union Agency for Cybersecurity (ENISA) and to a national Computer Security Incident Response Team (CSIRT). Article 14 of Regulation (EU) 2024/2847 sets a staged timeline. An early warning is due within 24 hours of the manufacturer becoming aware. A fuller notification follows within 72 hours. A final report is due within 14 days after a corrective or mitigating measure becomes available, in the case of an actively exploited vulnerability, or within one month of the 72-hour notification, in the case of a severe incident.  – https://dig.watch/updates/cyber-resilience-act-reporting-obligations

Shufti publishes 2026 identity fraud report highlighting AI-use by organised crime networks

(DigWatch) Shufti’s Identity Fraud Report 2026, based on identity-verification data collected across eleven industries during the first half of 2026, points to a shift in AI-enabled identity fraud from isolated attempts by individual fraudsters towards coordinated criminal networks operating through shared identities, devices, documents and digital infrastructure. The report finds that generative AI has reduced the cost and technical barriers to producing convincing fraudulent identities, allowing criminal groups to reuse the same manipulated identity assets across multiple verification attempts and jurisdictions. – https://dig.watch/updates/shufti-2026report-identity-fraud-ai-use-oc-groups

Anthropic: AI Misuse Is Entering a New Phase: From Cybercrime to Surveillance, Propaganda and Weapons

(Pierluigi Paganini – Security Affairs) Artificial intelligence (AI) is becoming more than a tool for people who want to do something malicious. It is increasingly becoming part of the operational machinery itself. That is the main message emerging from Anthropic ‘s latest Threat Intelligence report, which examines malicious activity identified and disrupted between December 2025 and August 2026. The cases cover cyber operations, influence campaigns, surveillance, fraud, biological research, conventional weapons and attempts to extract the capabilities of frontier AI models. The actors involved are equally diverse. Anthropic describes suspected state-sponsored groups, financially motivated criminals, commercial surveillance operators and politically motivated individuals. What connects many of these cases is not a new attack technique, but the way AI changes the economics, speed and scale of operations. – https://securityaffairs.com/198905/ai/anthropic-ai-misuse-is-entering-a-new-phase-from-cybercrime-to-surveillance-propaganda-and-weapons.html

Anthropic says it blocked misuse of its AI that could have supported biological weapons

(Barbara Ortutay – AP) Anthropic said Thursday it has blocked efforts by bad actors to use its artificial intelligence models for malicious activity such as cyberattacks, surveillance, and research that could have led to biological weapons. As AI models grow more powerful, elaborate cyberattacks no longer require sophisticated skills and even lone individuals can create threats that would not have been possible even a year ago, Anthropic said. The company said it has added stronger safeguards in its latest models to restrict biological research that could also be used to make weapons. “The cases we share here aren’t typical misuse, but rather examples of the most notable and novel threat activity we’ve identified to date,” Anthropic said in its third report since March 2025 describing AI misuse. The report includes snippets of the malicious code and AI prompts Anthropic said it found and it urged governments and AI competitors to identify and prevent similar abuse. “We’re publishing this work because we believe we have a responsibility to disclose malicious misuse of our services. As models become increasingly capable, their risks will increase, unless AI developers and society’s defenders act to make them safer,” the company said. The lengthy report by the AI startup, which is planning an initial public offering this fall, was published two days after one of its researchers announced he’s resigning over concerns that Anthropic and its competitors are not acting responsibly in AI development. He echoed concerns raised inside and outside of the industry about the technology’s potential to elude human control. – https://apnews.com/article/anthropic-ai-threat-bioweapon-russia-00266dca90e4f8853f669648998d3bda

Revolut Exposed KYC Data After Fraudulent Government Email Passed Security Checks

(Pierluigi Paganini – Security Affairs) Revolut confirmed on September 12, 2026, that it disclosed sensitive customer data to an unauthorized third party after receiving fraudulent information requests sent from an email address operating inside an actual government agency’s domain infrastructure. TechCrunch reported. The customer notification, which began circulating on September 11, stated that the communication carried valid domain authentication credentials, meaning the email passed the checks that are supposed to confirm a message genuinely comes from a government authority. “Revolut received a request for customer information that appeared to come from a legitimate government agency. The request came from an unauthorised email account sent directly using the official government agency’s email domain.” reads the Revolut’s notification. “As the communication carried valid domain authentication credentials, it was fulfilled under the reasonable belief that it was an authentic government agency request”. “The exposed data included customers’ identity and contact details, including their birth date, postal and email addresses, and phone numbers, as well as copies of their identity documents including passports and driver’s licenses, according to a notification emailed to affected customers and reviewed by TechCrunch.” reported TechCrunch. “The data may have also included verification selfies, account statements, and transaction histories, the firm said in its notification”. Multiple outlets including CoinDesk and Crypto Times confirm the transaction histories covered Bitcoin. What Revolut handed over is essentially everything a regulated fintech is required to collect for identity verification, in one package, sent to the wrong people. – https://securityaffairs.com/198922/data-breach/revolut-exposed-kyc-data-after-fraudulent-government-email-passed-security-checks.html

The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open Internet

(Pierluigi Paganini – Security Affairs) Running AI locally is supposed to give organizations more control. Models, prompts and documents stay on infrastructure they manage instead of being sent to a third-party cloud. But that advantage disappears quickly when the infrastructure itself is exposed to the public internet. A new study from Mysterium VPN offers a useful snapshot of the problem. The researchers found 36,769 self-hosted AI endpoints across model servers, agent-building platforms and vector stores that were reachable and identifiable through a public internet scanning index. “Only 2.02% return an HTTP authentication challenge; for the overwhelming majority, there’s no network-layer gate whatsoever.” reads Mysterium VPN’s report. “Open WebUI: 18,529 reachable, 1 behind a gate: The most widely deployed local-LLM front-end has, as a population, no perimeter”. That number needs to be read carefully. A service returning HTTP 200 isn’t automatically unauthenticated because a login page can also return 200. Mysterium therefore used HTTP 401 and 403 responses as evidence of an authentication gate and made a stronger claim only where the application fingerprint itself proved anonymous access. – https://securityaffairs.com/198898/ai/the-ai-supply-chain-has-a-security-problem-and-much-of-it-is-sitting-on-the-open-internet.html

Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware

(Pierluigi Paganini – Security Affairs) Cisco Talos says three separate threat groups are exploiting two recently patched Secure Firewall Management Center (FMC) flaws. The main target is CVE-2026-20079, a critical authentication bypass that lets unauthenticated attackers remotely bypass security controls, run scripts and potentially gain root access. Attackers also exploit CVE-2026-20316 to access sensitive data through a low-privilege account. The second flaw can be chained with other FMC vulnerabilities to increase privileges. Cisco linked the attacks to ransomware operations, including Qilin, as well as state-sponsored activity. “Talos’ analysis illustrates three clusters of post-compromise activity on FMC instances associated with state-sponsored and crimeware threat actors, as described below.” reads the advisory. “The first cluster which we track as UAT-12197, involves the exploitation of CVE-2026-20079, leading to the deployment of web shells, a Java Archive (JAR)-based command executor, and credential exfiltration.” – https://securityaffairs.com/198884/cyber-crime/attackers-exploit-critical-cisco-fmc-flaw-to-deploy-qilin-ransomware.html

UK Council Attack Linked to Mass Exploitation of SonicWall Flaw

(Pierluigi Paganini  – Security Affairs) On July 17, 2026, the Borough Council of King’s Lynn and West Norfolk announced it had detected a cyberattack affecting council services. Hunt.io has since published a detailed technical analysis linking that incident, with moderate confidence, to a wider mass-exploitation campaign against SonicWall SMA1000 appliances using CVE-2026-15409, a maximum-severity SSRF flaw that received a CVSS score of 10.0. CVE-2026-15409 affects the WorkPlace portal’s WebSocket proxy. An attacker does not need to log in. By sending a specially crafted request to /wsproxy, they can make the appliance connect to port 1050 on its own local system, where a CouchDB-related Erlang service is running. The attacker can then use a hardcoded cookie found in the appliance firmware to complete the Erlang connection and access the couchdb@127.0.0.1 node. From there, they can send commands that execute operating system commands with the privileges of the couchdb account. The attack may sound complicated, but once automated, an attacker can complete all the steps in just a few seconds. – https://securityaffairs.com/198864/hacking/uk-council-attack-linked-to-mass-exploitation-of-sonicwall-flaw.html

Defence, Intelligence, and Warfare

Users in Houthi-held Yemen tried to develop advanced weapons with AI, Anthropic says

(Sarah El Deeb – AP) Anthropic says Claude users in northern Yemen, territory controlled by Iran-backed Houthi rebels, tried to use the AI model to develop advanced missiles. AI is already transforming warfare from Ukraine to Gaza, and its use on a rugged and remote battlefield is likely to increase concerns about its rapid spread. Anthropic said the users of the accounts, which it blocked after identifying them, did not succeed in “fielding an operational device” but did carry out a failed test of a guided rocket. It said it knows that because the users returned to its Claude chatbot to find out why it failed. In a report released Thursday, the company did not identify the users. But mountainous northern Yemen is controlled by Houthis, suggesting that the rebels are pursuing more sophisticated weapons at a time when they are already wielding an array of drones, missiles and other munitions in their campaign to seize more territory in Yemen and damage Saudi Arabia’s oil exports. – https://apnews.com/article/yemen-houthis-anthropic-ai-missiles-9b20934e031ff3d99dd8bb49d85d97a9

Courts and Litigation

SpaceX sues to block release of tax‑break records for AI semiconductor facility

(DigWatch) SpaceX filed a lawsuit in Texas, USA this week to block the release of records related to tax breaks it received for Terafab, the proposed semiconductor factory SpaceX is building near Houston. In the filing, SpaceX argued that the Terafab records contain ‘confidential information’ and that releasing them would reveal ‘negotiating strategy, concessions, and limits to every jurisdiction, competitor, and counterparty with which SpaceX negotiates in the future.’ – https://dig.watch/updates/spacex-blocks-release-of-semiconductor-documents

Brazil’s Attorney General office sent an extrajudicial notification to YouTube to remove AI avatar videos

(DigWatch) Brazil’s Union Advocacy General (AGU) issued YouTube with an extrajudicial notification requesting the removal or labelling of videos that use artificial‑intelligence‑generated avatars to simulate doctors and other healthcare professionals. The AGU asked YouTube to comply within 72 hours. The notice also requested that the company assess other flagged channels under its policies on health misinformation and synthetic content and adopt preventive measures against similar material. The notification was based on an analysis by Brazil’s Ministry of Health that identified 97 profiles that posted said content between 1 January and 10 July 2026. – https://dig.watch/updates/brazil-sent-notice-to-youtube-to-remove-videos

Florida sues Netflix over collection of children’s data

(DigWatch) In the USA, Florida Attorney General James Uthmeier filed a lawsuit on 9 September 2026 alleging that Netflix misled subscribers by promising an ad‑free, privacy‑focused service while secretly collecting extensive behavioural data, including from children’s profiles, to support its advertising business. The 66‑page complaint alleges that Netflix collected detailed information about how users interacted with the service, including what they watched, paused, rewound, searched for, skipped and abandoned. Florida alleges that this also applied to Kids Profiles, which Netflix markets for children aged 12 and under. The state argues that this data was later used to support Netflix’s advertising business after the company introduced an ad-supported tier in 2022. Florida also alleged that autoplay defaults on these profiles constitute ‘dark patterns’ designed to extend viewing sessions and generate additional data. – https://dig.watch/updates/florida-netflix-childrens-data

US federal trial against Huawei Technologies over the two decades of racketeering conspiracy, has began in New York – 9 September 2026

(DigWatch) The US federal trial against Chinese telecommunications giant Huawei Technologies began in Brooklyn, New York, on 9 September 2026, opening one of the most significant criminal cases in the long-running technology and geopolitical confrontation between Washington and Beijing. Federal prosecutors accuse Huawei and its subsidiaries of engaging in a two-decade pattern of racketeering and criminal conduct, including the theft of American trade secrets, wire and bank fraud, sanctions violations and the use of the US financial system to support business involving Iran. Huawei denies the allegations and argues that prosecutors are presenting legitimate business activities and isolated employee misconduct as evidence of a coordinated criminal enterprise. – https://dig.watch/updates/us-trial-huawei-racketeering-conspiracy