Weekly Digest on AI and Emerging Technologies (28 September 2026)

Daily Digest on AI and Emerging Technologies (22 September 2026) – https://pam.int/daily-digest-on-ai-and-emerging-technologies-22-september-2026/

Daily Digest on AI and Emerging Technologies (23 September 2026) – https://pam.int/daily-digest-on-ai-and-emerging-technologies-23-september-2026/

Daily Digest on AI and Emerging Technologies (24 September 2026) – https://pam.int/daily-digest-on-ai-and-emerging-technologies-24-september-2026/

 

Governance, Regulation, Legislation, Geostrategies

Bill Gates says AI companies self-regulating isn’t enough and governments should be involved in monitoring – Microsoft co-founder and billionaire philanthropist Bill Gates on Wednesday called for lawmakers in Washington to regulate the development of artificial intelligence, weeks after the CEOs of some of the nation’s biggest AI labs agreed on the need to slow the pace of AI progress. “No one thinks self-regulation is enough,” Gates told NBC News’ “Meet the Press” in an interview. “You need law enforcement and the politicians to get into the discussion about what safeguards and monitoring look like,” he said. “And that has to be a required thing. And it will be a little bit of overhead for the industry, but not a dramatic slowing of what they’re doing.” – https://www.nbcnews.com/politics/politics-news/bill-gates-ai-companies-self-regulating-governments-monitoring-rcna599619

The US wants the world to pick a side on AI. But for many countries, China’s pitch may be more compelling – The rapid advances of Chinese artificial intelligence over the past year seem to have alerted Washington to the real possibility that the world’s second-largest economy could pull ahead of the United States in an increasingly tight technology race. “We’re leading China in AI…and frankly, I want to keep it that way, because whoever wins AI wins,” US President Donald Trump said earlier this month. Trump’s comments underscore the stakes of a US-China tech competition that is increasingly being framed in existential terms. The US has an obvious edge, with pioneering AI labs, the most advanced chips and deep-pocketed investors. Leveraging that dominance, Washington is also forcing countries around the world to pick a side. But China has a vision that, for many, may be more compelling. Even as it trails the US in frontier AI models, it’s rapidly narrowing the technology gap while championing a more open ecosystem centered on accessibility and lower cost. While over two dozen countries and the European Union signed up to Trump’s Pax Silica, Xi has recruited 29 countries, including Russia, Indonesia and Pakistan, to his alternative vision of open models, which allow users to freely download, customize and run without paying hefty fees to American firms like Anthropic and OpenAI. For developers in the Global South, an inexpensive Chinese model from DeepSeek or Moonshot may be more useful than a slightly more capable system requiring an expensive subscription and access to a foreign cloud provider, said Eric Olander, editor in chief of The China-Global South Project, a research agency. Amid concerns about AI’s potential threat to humanity and growing calls for a global oversight body, the technology became a key focus of the Trump-Xi summit (…). The right thing to do on AI, Xi said during talks with Trump, is to “draw on each other’s strengths, not guard against each other” – a reference to Beijing’s concern about US containment, from existing tech export controls to potential AI restrictions. “The two sides can continue their dialogue on AI, exchange views on its risks and benefits, and jointly prevent the misuse and abuse of AI,” he added. This followed preliminary talks last weekend, when a new AI safety notification system was proposed, and the two agreeed to establish a formal dialogue on AI. But the summit has yielded little progress on AI beyond broad-stroke consensus on continuing dialogue – underscoring the entrenched mutual mistrust amid contrasting visions on AI. – https://edition.cnn.com/2026/09/26/tech/us-china-ai-explainer-intl-hnk

Trump-Xi Summit: How to Reach an AI Arms Control Deal With China – There are mounting calls in the United States for President Donald Trump and Chinese President Xi Jinping to negotiate a U.S.-China agreement on AI safety, given warnings from leading U.S. AI companies—Anthropic, OpenAI, Google, and others—that humans could soon lose control of advanced AI models. The United States and China will eventually need to reach such a negotiated agreement to ensure neither country fields an AI model that poses a danger to public safety. The current situation has drawn parallels with Cold War arms control negotiations, given that the United States and the Soviet Union found ways to reduce nuclear risks even while in vigorous competition. While dialogue between the United States and China to share perspectives on AI-related risks is warranted, a U.S.-China agreement governing AI development is exceedingly unlikely under current strategic conditions and would be without precedent in the history of arms control. However, there are steps that Washington can take today that would create the conditions conducive to successful negotiations down the road. The United States has a clear, albeit not dominant, lead over China in AI. U.S. AI labs are somewhere between six months and one year ahead of their Chinese counterparts, but China’s AI capabilities remain competitive, and crucially, China still believes it can surpass the United States. Both the United States and China correctly view AI leadership as strategically existential, which means their top priority is maintaining—or, in China’s case, obtaining—leadership in the technology. For both countries, mitigating AI risks is a crucial objective, but secondary to AI leadership. This strategic posture is rational given the critical national security importance of AI, but also extremely unconducive to reaching an arms control agreement. Every past bilateral strategic arms control agreement was either negotiated between countries that were already at overall strategic parity or was agreed to only after one country concluded that it was better to lock itself into a disadvantageous position because it could not win the strategic competition. There is no historical case in which two states of unequal strength concluded an arms control agreement to regulate a strategically critical technology that either caused the leader to cede its overall strategic advantage or that constrained the trailing state’s development and deployment of that technology before that state had concluded the race was lost. But this does not mean an AI arms control agreement is impossible. Rather, it means that if the United States wants to maximize the chances of reaching such an agreement with China but preserve its lead, it must first take steps that cause China to conclude that it will not be able to catch up to the United States in AI and that it therefore should strike a deal sooner rather than later. – https://www.cfr.org/articles/how-to-reach-an-ai-arms-control-deal-with-china

AU calls for continental framework on terrorist use of emerging technologies – The African Union Peace and Security Council (AU PSC) has renewed its call for a continental framework to address the use of emerging technologies by terrorist groups, including encrypted platforms and digital finance. Meeting at ministerial level in New York on 23 September 2026, the Council discussed regional responses to terrorism and violent extremism as part of a broader agenda on good neighbourliness and security cooperation in Africa. In its communiqué, the Council asked the African Union Commission to develop the framework in line with an earlier February 2026 Assembly decision and the Algeria Guiding Principles, while ensuring consistency with international standards. It also called on technology and financial companies to strengthen cooperation with AU member states to prevent terrorist recruitment, financing and propaganda on digital platforms. The Council linked this work to the AU Continental Strategic Plan of Action on Counter-Terrorism in Africa 2026–2030, which includes countering online exploitation alongside prevention and stronger support for Member States. – https://dig.watch/updates/au-calls-for-framework-on-terrorist-use-of-emerging-technologies

UN Human Rights Council urges action against AI-enabled gender violence – The UN Human Rights Council (UN HRC) Advisory Committee has put forward legal and policy measures to address technology-facilitated gender-based violence (TFGBV) affecting women and girls, including forms involving artificial intelligence (AI). Presenting its study on TFGBV during an interactive dialogue at the UN HRC’s 63rd session on 24 September, the Committee identified non-consensual intimate image sharing, cyberstalking, surveillance and AI-generated sexual deepfakes among the forms of TFGBV impacting women and girls. The body also noted that women journalists, politicians and human rights defenders can face such abuse, which can discourage women’s participation in digital spaces and public life. – https://dig.watch/updates/un-rights-council-urges-ai-gender-violence

Africa needs its own AI solutions, not borrowed ones, says expert – Africa should focus its use of technology on solving its own real challenges rather than copying the systems and priorities of other parts of the world. That’s the opinion of one of the expert members of the UN-backed Independent International Scientific Panel on Artificial Intelligence, Girmaw Abebe Tadesse, who leads Microsoft’s AI for Good Lab in Kenya. n an exclusive interview with UN News in Nairobi, Mr. Tadesse said the first step for the continent is to identify key problems that need to be addressed before deciding on the type of technology, infrastructure and data needed. The interview took place as world leaders, policy experts and top AI executives met at UN Headquarters in New York during High-Level Week where greater attention is being focused on how the frontier technology can be safely managed for the benefit of all. – https://news.un.org/en/story/2026/09/1168440

Biotech: US House and Senate propose 2 bills for CISA to step up the protection of biotechnology infrastructure – US lawmakers introduced two bills to formally designate biotechnology and sensitive biological data as critical infrastructure: the Protecting Biotechnology and Biomanufacturing as Critical Infrastructure Act and the Protecting Biological Data Act. A bipartisan, bicameral group of US lawmakers introduced two bills on 24 September 2026 that would expand federal cybersecurity protections to biotechnology, biomanufacturing and sensitive biological data. The proposals would direct the Cybersecurity and Infrastructure Security Agency (CISA) to strengthen the protection of biotechnology infrastructure and systems containing genetic and other sensitive biometric data, reflecting growing recognition that the bioeconomy has become strategically important to economic security, public health and national security. – https://dig.watch/updates/us-lawmakers-cisa-biotech-criticalinfrastructure

UK outlines safeguards for hyperscale data centres – The UK Government has outlined how hyperscale data centres are expected to address water use, environmental impacts, and land protections as scrutiny grows over the infrastructure demands of large AI facilities. Responding to parliamentary questions on 22 and 23 September, ministers outlined different requirements depending on how hyperscale data centres proceed through the planning system. Developments under the Nationally Significant Infrastructure Projects (NSIP) regime must assess impacts on water resources through their Environmental Impact Assessment and supporting documentation. At the same time, national planning policy considers sustainable water use and resource efficiency. – https://dig.watch/updates/uk-hyperscale-data-centres-safeguards

US local data centre rules tighten in Minnesota, Iowa, and Chicago – Local governments in Minnesota, Iowa, and Illinois (USA) are reconsidering local data centre rules, using temporary development pauses and proposed zoning changes to examine infrastructure and community impacts. In Woodbury, Minnesota, the City Council approved a moratorium on 23 September covering new data centres, expansions beyond existing approvals, and other high-volume public-infrastructure users. The measure can remain in place for up to one year while the city studies issues including electricity demand, water use, noise, and possible zoning changes. Woodbury currently has three data centres but had no active applications or discussions with developers when it adopted the moratorium. – https://dig.watch/updates/us-local-data-centre-rules-moratoria-zoning

Texas halts data centre permits pending resource audit – Texas Governor Greg Abbott has directed the Texas Commission on Environmental Quality (TCEQ) to halt permits sought by data centres until the state’s ongoing audit of the sector is completed. The decision expands an audit ordered in August covering data centres progressing through the Electric Reliability Council of Texas (ERCOT) interconnection process. Projects are being examined for electricity demand, water consumption and sources, cooling technologies, on-site power generation, public financial support, ownership, and potential impacts on surrounding communities. Projects that fail to complete the audit can already be denied connection to the electricity grid. – https://dig.watch/updates/texas-data-centre-resource-audit

Australia consults on making data centres pay grid expansion costs – On 24 September 2026, the Australian Energy Market Commission (AEMC) published a consultation paper that sets out two rule change requests aimed at ensuring data centres and other large loads ‘properly contribute to the network costs they cause or accelerate when connecting to the National Electricity Market (NEM)’. The proponent of the requests states that the objective is ‘to ensure that consumers do not inappropriately bear the costs associated with new data centre connections and other large loads’, arguing that current arrangements under the National Electricity Rules may not always allocate the costs and risks of large‑load connections appropriately. – https://dig.watch/updates/australia-data-centre-network-cost-rules

Tasmania council halts work at proposed AI data centre – On 25 September, the Latrobe Council in Tasmania, Australia, said it was concerned that work at the site of a proposed AI data centre might go beyond what is permitted under the site’s approved Forest Practices Plan. The council said it would issue a notice of its intention to take enforcement action and had asked the developer, Firmus, to stop work while it assessed the matter. According to the council, Firmus complied with that request and will have an opportunity to respond to the notice. – https://dig.watch/updates/tasmania-halts-work-at-firmus-ai-data-centre

EESC calls for changes to Cloud and AI Development Act – The European Economic and Social Committee (EESC) has adopted an opinion calling for revisions to the proposed Cloud and AI Development Act (CADA) as the European Union seeks to expand European cloud and AI infrastructure. The opinion was adopted on 23 September 2026 by a vote of 212 to 0, with 3 abstentions. The EESC supports the proposal’s objective of strengthening Europe’s cloud and AI ecosystem and reducing dependence on non-European providers, but argues that changes are needed to how infrastructure expansion is financed and implemented. – https://dig.watch/updates/eesc-cloud-and-ai-development-act-revisions

To adopt UNCITRAL MLETR principles, Canada proposes the ‘Enabling Digital Trade Act’ – On 21 September, the Government of Canada introduced omnibus legislation, Bill C‑39 or the ‘Building Canada Strong Act’, for its first reading in the House of Commons. The bill proposes amendments to over twenty Canadian federal statutes. Affecting digital trade, the text seeks to enact the ‘Enabling Digital Trade Act’ to eliminate requirements on the submission of trade information in physical form to the Government of Canada. The Enabling Digital Trade Act also makes electronic transferable records (ETRs), electronic documents and data sources, ‘functionally equivalent‘ to their paper counterparts. – https://dig.watch/updates/canada-digital-trade-act

Iceland releases roadmap and action plan for AI in healthcare – Iceland’s Ministry of Health released a new Digital Health Roadmap for Artificial Intelligence in Clinical Practice and an accompanying Digital Health Action Plan on Artificial Intelligence on 24 September 2026, establishing a framework for the co-ordinated and responsible introduction of AI across the country’s healthcare system. The Roadmap provides practical guidance for clinical personnel, system owners, and project managers considering AI solutions, while the Action Plan sets out governance, monitoring, and capacity building measures for implementation. – https://dig.watch/updates/iceland-releases-roadmap-and-action-plan-for-ai-in-healthcare

UNESCO backs digital vocational learning platform for Africa – UNESCO and the Sino-North Africa Education Innovation Association (SNAEIA) are advancing cooperation on digital vocational education through the China–Africa MOOC Platform, which aims to reach at least 10,000 learners during its first two years. The initiative forms part of wider efforts to improve access to technical and vocational education and training (TVET) across Africa. The jointly developed platform will combine online courses, digital learning resources, and AI-enabled approaches for students, instructors, and adults seeking employment or opportunities to develop new skills. It also plans to offer locally adapted courses, digital credentials, and training linked to industry requirements. – https://dig.watch/updates/unesco-digital-vocational-learning-africa

Security, Surveillance

OpenAI bots meddled with multiple US government agency sites – OpenAI has acknowledged that it alerted “dozens” of global institutions that their websites may have been meddled with by its AI bots acting improperly. AI agents attempted to get information from “governments, universities, public agencies, and other institutions”, including the SEC, Census Bureau and Education Department, the company said. The disclosures come just days after Australian Prime Minister Anthony Albanese announced that OpenAI agents had breached non-public files on the website of its government-run health care scheme, Medicare. Since August, public fears have grown around the potentially serious, even life-threatening, impacts of AI tools falling outside of human control. OpenAI said that some of the data was accessed by AI agents, essentially bots that are designed and trained to operate somewhat autonomously, which were working to find “authoritative sources of public information”. But the company noted that some of the bots went beyond that and worked to bypass security measures on websites. When attempting to get information from the Census Bureau, for instance, AI agents used tools reserved for software developers to access it, the company said. OpenAI said all of the government data accessed by bots was public. – https://www.bbc.com/news/articles/cw62jje658dlo

Pentagon data breach of military personnel raises national security concerns – A data breach at the Pentagon’s vast HR system has exposed Social Security numbers and other personal information of current and former military personnel, raising counterintelligence concerns among national security experts. “Unauthorized users” gained access to a vulnerable computer server belonging to the Defense Manpower Data Center (DMDC) beginning last October, but it wasn’t until nine months later, in July, that the Pentagon discovered and remediated the issue, according to a letter the center sent to victims of the breach reviewed by CNN. The DMDC maintained at least 60 million records as of fiscal 2024, according to its website. It’s unclear how many have been impacted, but Military Times reported that four million Department of Defense personnel could be affected by the breach. The Pentagon currently “does not have any indications of misuse” of the breached data, according to the letter. But the breached data is a potential goldmine for foreign intelligence services looking to track US military personnel, or cybercriminals looking to extort them (were they to acquire the data), according to experts. – https://edition.cnn.com/2026/09/25/politics/pentagon-data-personnel-breach

Exploit.in Database Reveals the Roots of Today’s Ransomware Ecosystem– Ransomnews researcher Dancho Danchev dug up a database dump of Exploit.in covering its first three years, from February 2005 to May 2008, and the numbers inside it tell a story about Russian cybercrime that enforcement press releases don’t. The dump contains 9,647 registered members, 13,925 threads, and 80,891 posts. The researcher who analyzed it had been reading Russian-language forums since those years and expected to recognize the layout. What surprised them wasn’t the marketplace threads selling shells and credit cards next to botnet rental offers. It was how many of the people from 2005 are still on the boards twenty years later. The forum’s section list in 2005 sat malware analysis, spam, carding, and vulnerability testing right next to car tuning, mobile phones, games, and general chat. That wasn’t ironic. It was the actual culture. About a third of everything written on Exploit.in in those years was people talking about their phones and each other. The biggest single section was the marketplace at 10,377 posts, but the car section and the humor board weren’t far behind the technical areas. “Most writing about Russian cybercrime forums calls them marketplaces, and they were. What the writing tends to leave out is that they were also where a lot of teenagers went to talk about cars and phones.” reads the report published by Ransomnews. “Both things happened in the same place with the same accounts, and nobody on the board seems to have found that strange.” – https://securityaffairs.com/199800/cyber-crime/exploit-in-database-reveals-the-roots-of-todays-ransomware-ecosystem.html

Cryptocurrency exchange Bitget Says North Korea-Linked Hackers Stole $351.6 Million – Cryptocurrency exchange Bitget says suspected North Korea-linked threat actors stole $351.6 million from a limited number of hot and warm wallets. The company detected unauthorized transfers on September 24 and temporarily suspended withdrawals. Bitget said customer balances, cold wallets and most platform assets remain secure. Mandiant and SlowMist are investigating the incident, while deposits and trading continue normally. “We are currently working with independent third-party experts Mandiant and SlowMist for a full investigation. Our first priority is our users. User balances remain intact, and Bitget’s User Protection Fund covers the impact on this platform-wide incident.” the company added. “Bitget Wallet operates as a self-custodial wallet on a completely separate and independent infrastructure from Bitget Exchange and was not affected by this incident. Bitget Wallet users’ assets remain onchain under users’ control and remain unaffected.” – https://securityaffairs.com/199754/cyber-crime/cryptocurrency-exchange-bitget-says-north-korea-linked-hackers-stole-351-6-million.html

ClickFix Campaign Abuses Trusted Websites to Deploy Psychedelic Stealer – Psychedelic Stealer is being distributed through compromised Ukrainian business websites. Attackers injected hidden iframes into legitimate pages and used them to display a fake Cloudflare verification screen to visitors. The affected sites included a hair-treatment clinic, a scale-model manufacturer, a specialist bookseller, a psychological facility, a tool retailer, and an automotive retailer. These were legitimate businesses with established social media profiles and third-party listings. Visitors were therefore directed to a trusted website they may have visited before, making the fake Cloudflare CAPTCHA harder to recognize. That’s the core of what makes this campaign uncomfortable to dismiss. Visitors didn’t stumble onto an obvious fake domain. They landed on a site they may have visited before, for a business they already had some reason to trust, and got served a fake CAPTCHA instead of the page they were looking for. The fake verification page imitates Cloudflare, complete with a randomly generated “Ray ID” in the footer and a fixed “visitor identifier” in the agreement text. Both look like the kind of tracking and authentication markers Cloudflare actually uses, and neither one means anything here. – https://securityaffairs.com/199731/malware/clickfix-campaign-abuses-trusted-websites-to-deploy-psychedelic-stealer.html

AI-Powered CARBONATO Botnet Steals Credentials to Fund Its Own LLM Gateway – CARBONATO is a Docker-based botnet that has been active since at least October 2024. ThreatDown discovered the operation after finding an unauthenticated container registry exposed to the internet. The registry contained the attackers’ entire toolchain and revealed details about how the botnet operates. In just one day of passive, read-only collection, researchers gathered 4.3 GB of image data, including 59 repositories, 234 tags, and 605 verified file blobs. The registry also exposed the configuration history of the images, revealing command-and-control addresses, bot tokens, and even the shared password for the attackers’ own AI gateway. The operation appears to be linked to Costa Rica, although researchers say the infrastructure could also be used by someone operating from elsewhere. The initial infection method is relatively simple. The bot scans for Docker daemons accepting unauthenticated connections on port 2375, a configuration that thousands of hosts still run publicly reachable. When it finds one, it uses the Docker API itself to launch a privileged container with the host filesystem mounted, then runs commands directly on the underlying machine through that container. The host’s own daemon does most of the work. – https://securityaffairs.com/199716/malware/ai-powered-carbonato-botnet-steals-credentials-to-fund-its-own-llm-gateway.html

Defence, Military, Warfare

Coalition Operations. The Untapped Role of AI in Military Decision- Making – U.S. military strength has long depended on the ability to fight alongside allies and partners. From the Gulf War to Operation Epic Fury, coalition operations have amplified American power, but they have also exposed persistent friction: incompatible networks, conflicting classification rules, national caveats tracked in “enormous spreadsheets,” and language barriers that, at their worst, have contributed to near-fatal incidents in the field. The hope (…) is that AI-enabled decision support systems (AI-DSS)—software platforms that ingest, analyze, visualize, and share vast and disparate data—can help coalitions operate more effectively together. (…) Political will and bureaucratic change remain critical hurdles. A paper by CSET examines four specific applications of AI-DSS for allied and partner operations: building a common operating picture (COP), supporting coalition targeting decisions, accelerating the foreign disclosure information-sharing process, and bridging language differences. In each case, AI-DSS offer real advantages in managing complex disclosure guidance, centralizing information, enabling real-time translation, and building a shared operational picture more quickly and reliably. We use the Maven Smart System (MSS), now deployed broadly across U.S. commands and in some cases already providing these services, as an exemplar throughout.*Tempering the hope that AI-DSS can improve coalition operations are the same technical and political constraints that have confounded prior interoperability efforts. These include political restrictions on information sharing, varying technical and cybersecurity standards, and trust deficits in coalition partners and in the technology itself. Added to these historical hurdles are newer concerns. Allies and partners are facing political backlash over deals with U.S. technology vendors, ranging from AI-DSS developers like Palantir, the prime contractor for MSS, to generative AI companies. Concerns over the reliability of U.S. commercial partners are exacerbated by recent U.S. government actions against the AI company Anthropic. When paired with increased uncertainty over America’s support for allies and partners, nations are publicly seeking “sovereign AI” capabilities that may complicate future allied operations. Despite these challenges, NATO’s adoption of AI-DSS has moved with unusual speed. As one example, security accreditation that can take 18 months on U.S. networks took only six months to reach initial security accreditation and one year to reach full approval in the case of NATO Maven. NATO is in a uniquely strong position to embrace AI-DSS today (…). – https://cset.georgetown.edu/publication/coalition-operations/

Frontiers and Markets

Google to test AI computing chips in space with Project Suncatcher – Google’s Project Suncatcher is an early research effort to find out whether AI computing equipment could operate in space. It is Google’s ambitious project to build date centres in space by taking advantage of free and abundant energy from the sun. Google plans to launch a test satellite carrying its AI chips into low Earth orbit. The longer-term idea is to use the near-constant sunlight available there to power groups of satellites that could handle larger AI tasks. Google has not yet built an operational data centre in space. – https://dig.watch/updates/google-to-test-ai-chips-in-space-with-suncatcher