Daily Digest on AI and Emerging Technologies (18 September 2026)

Goyernance, Regulation, Legislation, Geostrategies

You Don’t Have to Sell It to Be Bound by It: GPAI and the EU AI Act – In July, OpenAI’s models broke into Hugging Face’s systems. OpenAI’s recently released technical report on the incident revealed that an “internal-only research model had the broadest confirmed role in the incident.” This raises the question of whether the European Union’s AI Act applies to models not released publicly but merely deployed internally. This question is not new. It is especially important in the context of recursive self-improvement or, in other words, artificial intelligence (AI) systems being able to create new versions of themselves entirely autonomously, which often constitutes the internal deployment of AI. Indeed, AI companies have already made several statements about AI systems being heavily involved in AI research and development, with both Anthropic and OpenAI claiming that AI writes up to 80 percent of the company’s code, and Google  and Meta not trailing far behind. While the companies claim humans still review the code and while agentic coding based on human commands falls short of AI systems’ true independence in self-improvement, the companies also warn that it may not be long before AI takes the reins. AI achieving such capabilities would have numerous implications, including losing control over the AI system after it surpasses our own capabilities. This is why it is of utmost importance to examine whether the EU AI Act, the world’s first comprehensive AI legislation, regulates internal deployment. With the European Commission having been able to exercise its enforcement powers under the EU AI Act since Aug. 2, an affirmative answer to this question would enable the European Commission to take action (including by imposing fines) against AI companies that conduct autonomous AI research and development or otherwise internally deploy their models without complying with the EU AI Act. – https://www.lawfaremedia.org/article/you-don’t-have-to-sell-it-to-be-bound-by-it–gpai-and-the-eu-ai-act

Why We Opted Not to Work at the AI Labs – Knowledge is power. That’s especially true of knowledge of artificial intelligence (AI)—what it is, how it works, how to use it, and how it is developing over time. While millions of users access AI everyday, a much smaller set of people witness the current state of the art. Consider that the median researcher at OpenAI relies on AI agents to perform tasks of ever greater complexity for increasing periods of time, with the net result of AI agents performing the equivalent of 3.1 days of work for every one day of human labor. They have access to models that are months ahead of the public frontier. The individuals and organizations that can harness AI to such ends will be more productive, more profitable, and more powerful. The power resulting from AI expertise is becoming more and more concentrated in what we refer to as the “Silicon Tower.” Our friends and colleagues have left academic roles at prestigious institutions, including our home institutions, Stanford and the University of Texas, to join AI companies. The Information documented that 22 leading academics had made that move—facilitating a brain drain from campuses to the Bay Area; it’s likely that even more have made that jump in the time since. We ourselves have had to navigate these choices, deciding whether to accept job offers for life-changing amounts of money and access versus the freedom and independence of the academy. – https://www.lawfaremedia.org/article/why-we-opted-not-to-work-at-the-ai-labs

OpenAI says it found more instances of AI models acting deceptively – OpenAI found additional incidents of AI models acting deceptively and taking unsanctioned actions during training, the company announced Wednesday. It’s also introducing a new process for the company to publicly report such instances. Under the new system, OpenAI will share updates on concerning AI behavior more frequently instead of waiting to bundle multiple instances into one report. The company said it wants to share more information about troubling AI behavior in the absence of an industry-wide standard. The announcement comes after tech leaders called for a slowdown in AI development to prevent the technology from advancing beyond human control. “As AI systems grow more advanced and more widely deployed, we need to build a broader and better-informed consensus on the progress of alignment research,” OpenAI wrote in a blog post Wednesday. “Alignment” refers to the process of making sure AI acts the way humans want and expect. “We do not believe that the AI industry has solved alignment and monitoring to a sufficient degree to continue responsibly scaling at maximum speed for much longer,” the post said. – https://edition.cnn.com/2026/09/16/tech/ai-models-acting-deceptively-openai

Why is China less worried about an AI dystopia than the US? – Unlike in the United States, no one in China seems to be openly fretting over the prospect of humanity being destroyed by artificial intelligence soon. There, citizens access local government services through AI-powered digital employees; students receive instant feedback on written assignments by uploading a photo; and hotel guests collect parcels delivered to their doorsteps by robots. The wide adoption of AI in today’s China underscores the country’s embrace of the novel technology. A Morgan Stanley survey released Monday found 80% of Chinese respondents used AI at least weekly, far exceeding the 54% in the US. Even as US tech executives and researchers urge a slowdown in AI development citing its existential threat to humanity, the Chinese public has remained comparatively unfazed. “This technology was created to serve humanity,” said Xu Jingyuan, 22, a business student from Beijing. “We shouldn’t see it as something to fear, but as something that brings greater conveniences to our lives”. He said the government is “absolutely capable” of managing its risks. Xu’s comments echoed those of several people CNN spoke to this week, reflecting a divide in attitudes toward AI in Chinese and American society, as well as differing levels of trust in respective governments’ ability to handle the potential threats posed by the technology. “In the US, there is a general public perception that without whistleblowing, big corporations could escape accountability or scrutiny due to weak government oversight,” said Lian Jye Su, chief analyst at technology research firm Omdia. “Whereas in China, I think there is this very strong confidence from the public that if any sh*t hits the fan, the government will step in”. Analysts also point to differences in exposure to AI, public discourse around the technology, and the broader cultural and historical context as possible explanations for the divide. In a survey by marketing research firm Ipsos earlier this year, 83% of Chinese respondents found AI-powered products or services exciting, whereas only 33% of those in the US felt similar way. Meanwhile, another survey by marketing consultancy Edelman showed that 86% of respondents in China said they trusted their own government to do what is right, compared with just 39% in the US. A marked difference between the two nations is their political systems. While whistleblowing is routine in the US and policy debates often become messy, especially in an increasingly polarized democracy, China’s top-down power structure allows the one-party state to set agendas without facing open criticism. – https://edition.cnn.com/2026/09/17/tech/china-ai-debate-intl-hnk

Latin America’s Long Game: Nuclear Disarmament in the Age of AI – Latin America built the world’s first nuclear-free zone in 1967, and ever since, it has been at the forefront of innovation in nuclear diplomacy, responsible international behavior, and nonproliferation norm-setting.  Over 20 countries in the region initially signed the Treaty of Tlatelolco—formally, the Treaty for the Prohibition of Nuclear Weapons in Latin America and the Caribbean. Eventually, all Latin American and Caribbean nations signed and ratified the treaty. Tlatelolco remains a viable alternative to today’s faltering nuclear architecture. Latin America is now pushing to prevent artificial intelligence (AI) from being integrated into nuclear command, control, and communications (NC3) systems. The region’s long game, total nuclear disarmament in the age of AI, might be the answer to one of the most intractable problems in grand strategy today. Yet Latin America is still perceived as “the land that geopolitics forgot,” where geopolitical strategy is notorious only for its absence, as hard security questions dissolve into the more conventional issues of corruption, illicit economies, drug trafficking, and criminal violence. This perception of Latin America’s irrelevance in geopolitics and U.S. grand strategy could not be more misguided. It is a region where peaceful grand strategy works and the paradigm of nuclear disarmament has been successfully put into practice. – https://www.lawfaremedia.org/article/latin-america-s-long-game–nuclear-disarmament-in-the-age-of-ai

Ukraine moves to crack down on scam call centers after corruption scandal– Ukraine’s parliament approved tougher criminal penalties for involvement in fraudulent call centers and the theft of personal data, following a corruption scandal in which prosecutors were accused of taking bribes to protect scam operations. The legislation, passed Wednesday in the Verkhovna Rada, would make it a separate crime to use electronic communications to commit fraud, including schemes involving stolen or misused personal or banking information to take money or other property. The bill would also criminalize setting up, running or working for a fraudulent call center, as well as recruiting people to participate in such operations. – https://therecord.media/ukraine-call-center-scam-crackdown

Security and Surveillance

Chosen Brick, Iran’s Surveillance Malware – The UK, the US, and the Netherlands published a joint advisory warning about a Windows malware family, dubbed Chosen Brick, that Iran’s intelligence services use to track down dissidents, journalists, and activists, and the stakes for the people on the receiving end go well beyond a locked file server. “CHOSEN BRICK is a malware family that has been used to target individuals around the world including in the UK, US and the Netherlands from at least 2025. CHOSEN BRICK enables Iranian state cyber actors to collect information on a target’s contact – s, emails and social media messages, which could enable tracking of their movements.” reads the advisory. “Iran almost certainly uses cyber activity to support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists”. The advisory was issued jointly by the UK’s National Cyber Security Centre, the FBI, and the Netherlands’ AIVD. The three agencies gave a name to malware activity that security researchers had already been tracking under different names. This is not the first time Iranian state-linked actors have used Telegram-based malware against the Iranian diaspora. In March, the FBI reported that Iranian actors had been using Telegram as command infrastructure to target dissidents, with activity dating back to late 2023. The latest advisory adds a formal name, a joint attribution, and a more detailed look at how the malware operates. Iran has repeatedly used cyber operations to target people it considers a threat to the regime, including dissidents, activists and journalists. Iranian intelligence services have also been linked to plots involving the kidnapping or killing of perceived opponents abroad. For victims of CHOSEN BRICK, the risk may extend beyond cyber intrusion. – https://securityaffairs.com/199217/malware/chosen-brick-irans-surveillance-malware.html

Cyberattacks on Oil Tankers Put Maritime Critical Infrastructure at Risk – U.S. Coast Guard personnel and FBI agents boarded two Texas‑bound energy tankers last month after cyberattacks hit the vessels while they were underway, according to U.S. officials. One of the ships was the VL Prosperity, a 1,093‑foot Liberian‑flagged crude oil supertanker headed to Galveston, Texas. Iranian state media identified the ship soon after the incident and claimed hackers gained access to propulsion, navigation and cargo systems, knocking out communications for about 30 hours. “U.S. Coast Guard personnel and FBI agents boarded two Texas-bound energy tankers last month after cyberattacks struck the vessels while they were traveling toward the United States, according to U.S. officials.” CBS News reports. The Coast Guard has not publicly pinned the attacks on Iran. Rear Adm. Amy Grable, commander of U.S. Coast Guard Cyber Command, told CBS News that investigators did find evidence of a malicious cyber actor after assessing the vessel’s IT and other onboard systems. “They started out by doing an assessment of the information technology and the other systems on board the vessel, and they did find malicious cyber activity,” Grable told CBS News. “When these vessels are highly connected, they’re susceptible to cyber threats,” Grable said, warning that an attack could lead to “a vessel blocking a waterway or a pollution incident or any other number of safety and security hazards to our ports and waterways.” – https://securityaffairs.com/199280/hacking/cyberattacks-on-oil-tankers-put-maritime-critical-infrastructure-at-risk.html

SilkParasite Infrastructure Links SpiceRAT to Central Asian Targets – Hunt.io and researcher Guy Yasur have traced a tight cluster of SpiceRAT command‑and‑control servers that predate and extend Bitdefender’s August 2026 SilkParasite report. The work doesn’t dissect malware samples; it maps the network side of the operation with enough precision to tie three of SilkParasite’s seven RAT families (SpiceRAT, NodeEdgeRAT, and NomadRAT) through shared certificates, domains, and hosting patterns. “Shared parent domains and an identical TLS certificate connect this infrastructure to hosts Bitdefender attributed to SpiceRAT, NodeEdgeRAT, and NomadRAT, three of the seven malware families documented in the SilkParasite report.” reads the report published by Hunt.io. “The certificate imitating the Uzbekistan railway entity was issued by TLC, a certificate authority wholly funded by CAICT, a Chinese state research institute under the Ministry of Industry and Information Technology”. In March 2026, Hunt.io identified five SpiceRAT command-and-control servers hosted by different providers and in different countries. Researchers linked them through several common elements, including the same hostnames, TLS certificates, and a cloned webpage used as the default page. Instead of focusing only on the malware itself, this approach looks at the infrastructure behind it. Shared certificates or identical webpage hashes can provide strong and practical indicators that defenders can use to identify other servers linked to the campaign. One certificate in particular stands out. It impersonates Uzbekistan’s state railway authority (azure.uzrailwaystax[.]com) and was issued by TLC DV TLS CA, a CA wholly funded by CAICT, a Chinese state research institute under the Ministry of Industry and Information Technology. The issuer alone isn’t an indicator—nearly 3,000 servers host TLC certificates—but a domain‑validated cert spoofing a Central Asian state entity from a China‑based CA does suggest a deliberate procurement channel. – https://securityaffairs.com/199267/apt/silkparasite-infrastructure-links-spicerat-to-central-asian-targets.html

Tackling Spyware Abuse: What States Must Do Under International Law to Protect Journalists and Strengthen Security – The Citizen Lab, a digital-security research group at the University of Toronto, published a report this past July revealing that Stelios Kouloglou, a prominent Greek investigative journalist and former member of the European Parliament, was hacked with NSO Group’s Pegasus spyware multiple times in 2022 and 2023. At the time, Kouloglou was serving on the PEGA Committee, a European Parliament body created to investigate government misuse of commercial surveillance tools — the very abuse to which he was being subjected. Investigations revealed that the attacks coincided with key decision-making periods during the drafting of the committee’s final reports. Kouloglou’s case is striking, but it is far from unique. Around the world, governments have turned commercial spyware against dissenting politicians, journalists, human rights defenders, and activists. Investigations by Citizen Lab, Amnesty International’s Pegasus Project, and the Predator Files — along with work by many other civil society organizations — document a pattern of abuse that implicates the right to privacy, freedom of expression and association, press freedom, due process, and the integrity of democratic institutions. Software like Pegasus is installed on a target’s phone by exploiting security flaws in the device’s operating system. The most advanced versions use what researchers call “zero-click” exploits, which means that the target does not need to open a link or take any action at all. The infection is silent, often undetectable, and gives the operator full access to the device’s camera, microphone, messages, and location data. – https://www.justsecurity.org/156978/tackling-spyware-abuse-protect-journalists/

OpenAI admits its models lie to cover their own mistakes – Most companies don’t publish a document explaining how their product misbehaves. OpenAI just did. On September 16, it released a formal framework for tracking, investigating, and disclosing cases of model misalignment, paired with six actual incident reports covering the last six months. OpenAI admits that its previous way of sharing these findings was not very organized. Some discoveries were grouped together, others were saved for system cards, while some were held back until there was enough information for a larger report. The new framework aims to make the process faster by publishing what researchers find, even before OpenAI fully understands the issue or knows how to fix it. There is also a pretty direct admission in the announcement. OpenAI says the industry still has not solved alignment and monitoring well enough to keep AI development moving at the current pace for much longer. That is a surprisingly frank statement from a company whose business depends on providing AI services. “We are sharing a new framework for tracking, investigating, and disclosing instances of model misalignment at OpenAI, along with six reports on unexpected or concerning model behavior we’ve observed in the last six months.” reads the company’s announcement. “This new framework is intended to expedite publishing misalignment reports following observation, even when we haven’t fully explained or mitigated the behavior we’re reporting.” – https://securityaffairs.com/199302/ai/openai-admits-its-models-lie-to-cover-their-own-mistakes.html

Forget doomsday: The AI hacking crisis is already here – An unprecedented wave of AI-powered, human-driven cyberattacks is coming, security experts say — and it’s a far more urgent risk than theoretical conversations about AI wiping out humanity. The great September AI panic — which spread from boardrooms to Congress to American households in the last week — may have missed the point. Powerful models with advanced cybersecurity capabilities are already allowing attackers to bypass the human bottleneck that has long prevented most hacking campaigns from reaching industrial scale. Executives and former officials have told Axios they fear automated cyberattacks that turn off critical services like the power grid, or attackers using AI agents (like the ones that breached Hugging Face) to hack self-driving cars or create a botnet that takes over the whole internet. OpenAI on Wednesday disclosed six new incidents in which its models concealed mistakes, sought unauthorized credentials, uploaded files to the public internet or communicated across supposedly isolated training environments. – https://www.axios.com/2026/09/17/ai-cyber-doomsday-hacking-threats

EU chief wants joint response to cyberattacks, sabotage – European Commission President Ursula von der Leyen proposed on Wednesday an emergency mechanism allowing any EU country to summon the bloc’s governments in response to security threats including sabotage, cyberattacks and drone incursions. Delivering her annual State of the Union address in Strasbourg, Von der Leyen said threats were “mounting on our soil,” pointing to recent incidents in Denmark, Lithuania and Poland and an attempted drone attack in Leipzig. “Cyberattacks and sabotage, arson and drone incursions” are “ramping up every day,” she said, arguing that the EU’s institutions and decision-making processes had failed to keep pace. “Our systems were made for a different world,” she said. “They are driven by well-intentioned attempts at consensus and compromise. But we need to consider whether they are still fit for purpose.” – https://therecord.media/eu-chief-wants-joint-response-to-cyberattacks

Coast Guard, FBI boarded tanker after attack by ‘foreign cyber actors’ – The U.S. Coast Guard said it boarded a tanker transiting the Gulf of Mexico in August after the vessel’s network was attacked by hackers. A Coast Guard spokesperson confirmed the incident after the Wall Street Journal reported that at least two tankers headed for the U.S. were hit with cyberattacks. Bloomberg News identified one of the  tankers as VL Prosperity, and Iranian government-backed news outlet Mehr said the ship lost communications for 30 hours. The FBI did not respond to requests for comment and several other agencies directed Recorded Future News to the U.S. Coast Guard, which said officials boarded the ship to “ensure integrity of the vessel’s operational and information technology systems following indications that the vessel’s network were compromised by foreign cyber actors”. “On August 21, a highly specialized team — comprised of USCG Law Enforcement personnel, USCG Cyber Protection Team members, a vessel inspector, and FBI Cyber Action Team operators — embarked the vessel to conduct a comprehensive cyber security boarding and investigation,” the spokesperson said. “Currently, there are no reports of operational disruptions, vessel instability, physical danger to crews, or environmental impacts”. – https://therecord.media/oil-tanker-cyberattack-coast-guard-fbi

Three Ukrainians to face charges for alleged hack of 610,000 Roblox accounts – Three Ukrainians are set to stand trial for allegedly stealing access to more than 610,000 Roblox accounts and selling them to buyers in Russia, according to Ukrainian law enforcement. Prosecutors in Ukraine’s western Lviv region said Tuesday that from May 2025 until April 2026 the group stole digital credentials that allowed them to access accounts without knowing users’ passwords. They then used software to determine which accounts contained valuable virtual currency, rare items or other digital assets that could fetch higher prices on the resale market. Roblox is an online gaming and social platform particularly popular with children and teenagers, where users can play games largely created by other players, build avatars and buy virtual items using the platform’s currency. – https://therecord.media/ukraine-roblox-hacker-arrested

Flock camera use by internal affairs unit puts DC police at odds with officers’ union – Flock automated license plate recognition cameras are under fire from the Washington, D.C., police department’s union after it discovered Internal Affairs investigators used the controversial technology to track the whereabouts of sworn officers without their knowledge. There are no known prior cases of police departments deploying Flock ALPRs to monitor their own personnel, privacy advocates say. Washington’s Metropolitan Police Department (MPD) defended the practice, saying in a statement that its “position is that the use of LPR in the misconduct investigation was appropriate.” – https://therecord.media/dc-police-union-opposes-flock-camera-use-probing-officers

DOJ takes down NightmareStresser DDoS platform – The NightmareStresser platform used to disrupt hundreds of educational institutions, government agencies and other organizations was seized on Tuesday by the Justice Department. The DOJ announced the court-authorized takedown alongside Canadian officials, but declined to say if any arrests were conducted as part of the operation. NightmareStresser was a well known site used to launch distributed denial of service (DDoS) attacks, and court documents said it was used in hundreds of DDoS attacks since 2022, targeting “educational institutions, government agencies, gaming platforms and millions of people.” – https://therecord.media/doj-takes-down-nightmarestresser-ddos-site

PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug – Attackers have been uploading PHP webshells to WordPress sites through a critical flaw in a third-party WooCommerce plugin, four months after a fix was released. In a technical write-up published on September 14, Wordfence said its firewall had blocked more than 100,000 exploitation attempts against CVE-2026-27540 in WooCommerce Wholesale Lead Capture, a premium plugin from Rymera Web Co with an estimated 6000 active installations. The flaw was disclosed and patched on February 20 in version 2.0.3.2. Wordfence rated it CVSS 9.8. The CVE record, issued by Patchstack, carried a 9.0 score, a difference that turns partly on how complex the attack is judged to be. Wordfence’s data shows a single unauthenticated request. – https://www.infosecurity-magazine.com/news/woocommerce-wholesale-lead-capture/

Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes – UK-based security testing and advisory provider SE Labs is launching a new testing program to help buyers evaluate cybersecurity vendors – and has attracted some prestigious names. The six-month testing program, called PIVOT, was unveiled by SE Labs on September 15. It will evaluate how effectively cybersecurity vendors can defend against the world’s most dangerous hacking groups and attack techniques. Several vendors have already confirmed their participation, including Broadcom – parent company of both Symantec and Carbon Black – CrowdStrike, Fortinet, Palo Alto Networks and Sophos. – https://www.infosecurity-magazine.com/news/cyber-vendors-mitre-uk-testing/