Daily Digest on AI and Emerging Technologies (10 september 2026)

Governance, Legislation, Regulation, Geostrategies

Malaysia’s Energy Commission says data centres use 9.28% of electricity

(DigWatch) Data centres account for 9.28 per cent of Malaysia’s total electricity consumption, according to the Energy Commission. Its chief executive officer, Siti Safinah Salleh, said electricity use by data centres can vary with the weather because cooling systems require more energy during hotter periods. She told reporters, ‘We expect power demand to increase in the fourth quarter of the year because there are a few data centres that are anticipated to come online or become operational somewhere in November.’ Power demand is currently over 21 gigawatts, and approvals for new data centre capacity are based on the power system’s available capacity rather than on a specific consumption cap. – https://dig.watch/updates/malaysia-data-centres-electricity-usage

Kenya reviews national child online safety survey

(DigWatch) The Communications Authority of Kenya (CA) and the University of Nairobi (UoN) have begun reviewing preliminary findings from a national survey on child online protection and safety in Kenya. The review is being carried out ahead of validation of the final report and is intended to assess the structure of the report, its main findings and the issues that should be highlighted for stakeholders. According to the CA, the survey is expected to provide evidence that can help inform future interventions on child online protection. – https://dig.watch/updates/kenya-child-online-safety-survey

Italy’s central bank orders sanctions screening for every crypto transfer

(DigWatch) Banca d’Italia has warned crypto-asset service providers (CASPs) that sanctions screening must be carried out on every individual crypto transfer, regardless of its value, in a new communication on compliance with EU and national restrictive measures. Firms must check information on both the originator and beneficiary before executing a transaction. The central bank has specifically instructed operators not to configure internal systems with a minimum transaction threshold that could allow smaller transfers to escape automated screening. The requirement is intended to ensure sanctions controls are applied consistently, including to low-value transactions. – https://dig.watch/updates/italy-orders-sanctions-screening-crypto-transfers

India expands WorldSkills participation with new advanced technology skills

(DigWatch) India will compete for the first time in software testing, intelligent security technology, unmanned aerial systems, digital interactive media design, and other technology-intensive categories when it participates in the WorldSkills Competition in Shanghai later this month. The Ministry of Skill Development and Entrepreneurship announced on 9 September that Team Skill India will enter 63 of the competition’s 64 skills from 22 to 27 September, with nearly 70 competitors. Eleven categories will be new for India, also including optoelectronic technology, industrial mechanics, aircraft maintenance, heavy vehicle technology, dental prosthetics, landscape gardening, and retail sales. – https://dig.watch/updates/india-adds-digital-technology-skills-worldskills

Republic of Korea puts water, energy and AI at centre of international policy talks

(DigWatch) The Republic of Korea has brought together government officials and water-sector experts from around 50 countries to examine how artificial intelligence can support water and energy management while responding to the resource demands of AI-related industries. The Ministry of Climate, Energy and Environment opened Korea International Water Week 2026 in Daegu on 9 September, with around 10,000 participants expected during the three-day event. Under the theme ‘Water, Energy, AI: Securing Our Future’, approximately 50 sessions will address the relationship between water management, energy systems, AI, and climate resilience. – https://dig.watch/updates/republic-of-korea-water-energy-ai-policy

India joins 25 countries in US-led 6G initiative

(DigWatch) The US Department of Commerce announced that India had joined the Call to Action for 6G Leadership and Security, a US-led multilateral initiative aimed at coordinating government approaches to the development of next-generation telecommunications networks. India’s government subsequently confirmed that it had endorsed the initiative. The initiative was launched by the US National Telecommunications and Information Administration (NTIA) on 27 July 2026 with 25 participating governments: Albania, Australia, Canada, Costa Rica, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Honduras, Italy, Japan, Latvia, Lithuania, Norway, Panama, Paraguay, the Philippines, Romania, South Korea, Sweden, the United Kingdom and the United States. India’s participation expands the initiative to 26 governments. – https://dig.watch/updates/india-joins-us-led-6g-initiative

UK seeks input on AI deployment in energy system ahead of new strategy

(DigWatch) The UK government has opened a consultation on how artificial intelligence should be deployed across the country’s energy system, as it prepares its first AI for Clean Energy Strategy. Minister for Local Energy and Jobs Martin McCluskey announced the process on 8 September during the Google for Startups Accelerator Europe event in London, saying the government wanted to examine both the potential benefits of AI and the risks of introducing it into critical energy infrastructure. The Department for Energy Security and Net Zero is seeking evidence until 6 November on where AI could improve energy forecasting, planning, optimisation, and coordination, as well as the barriers preventing wider adoption. The UK has identified six areas requiring attention: access to data, market incentives, regulation and governance, security and trust, integration with existing technical systems, and workforce capabilities. It is also asking where government intervention may be needed through regulation, standards, funding, or other measures. – https://dig.watch/updates/uk-ai-deploymentenergy-system-strategy

Social Media Platforms (Ofcom Licensing) Bill presented in UK Parliament

(DigWatch) On 7 September 2026, the Social Media Platforms (Ofcom Licensing) Bill was introduced into the House of Lords. The Ofcom Licensing Bill proposes that a person must not operate a ‘social media platform’ that is available to users in the United Kingdom unless authorised by a licence issued by Ofcom. Accordingly, operating a platform without a licence would be an offence under the proposed legislation. For the purposes of the Act, a ‘social media platform’ means a platform which: (a) has the sole or significant purpose of enabling users to create, share, discover or consume user‑generated content, and (b) enables users to discover, interact with or follow the content or accounts of users other than those with whom they communicate privately. The bill requires licence applications and renewals to be made in writing to Ofcom and Ofcom must have regard to the duties of licensees, the compliance requirements, and any other matters it considers relevant, when deciding whether to grant a licence. A licence may be granted subject to any condition Ofcom considers necessary for a fixed period not exceeding ten years. – https://dig.watch/updates/social-media-platforms-ofcom-licensing-bill-presented-in-uk-parliament

UNESCO launches global consultation on AI governance in education

(DigWastch) UNESCO released a discussion paper and launched a global consultation on governing AI in education. The paper, Sustaining education as a common good in the age of AI: The case for deliberative governance, examines how AI can affect education’s public purposes and argues that governance requires both the authority and capacity to make decisions and inclusive mechanisms for exercising that authority. The paper notes that students and teachers are already using AI widely, often before official policies have been adopted. It identifies uneven governance capacity within and between countries, with many education systems lacking the regulatory frameworks, institutional capacity, and shared understanding needed to guide AI use. It also considers how AI can widen access to learning, including for learners with disabilities, while examining risks to human agency, critical reasoning, assessment, and human relationships. – https://dig.watch/updates/unesco-consultation-ai-governance-in-education

AI datacentres pose growing threat to electricity systems worldwide

(UN News) Use of data-intensive technologies – in particular artificial intelligence (AI) data centres – is growing faster than electricity infrastructure can handle, the UN’s economic commission for Europe has warned, raising concerns about the future reliability and resilience of energy systems worldwide. Datacentre consumption is expected to almost double by 2030 – from 485 Terawatt-hours (TWh) in 2025 to 950 TWh by 2030, equivalent to three per cent of global demand, according to the intergovernmental International Energy Agency (IEA). Investment in datacentre infrastructure worldwide, on the other hand, is forecast to roughly double only by 2050 – from around $800 billion per year in 2026 to $1.8 trillion per year in 2050. The Geneva-based commission (UNECE) warns that in many regions, datacentres and other energy-intensive facilities are being built much faster than the power grids needed to supply them.  A large facility can often be built and connected within two to five years, but expanding transmission lines and other grid infrastructure can take more than 10 years because of lengthy planning, approval and construction processes. –  https://news.un.org/en/story/2026/09/1168296

Security and Surveillance

US Agencies Warn Chinese AI Firms Are Extracting Advanced AI Models

(Pierluigi Paganini – Security Affairs) NSA, CISA, and the FBI jointly published an advisory accusing six Chinese AI companies, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, of running industrial-scale extraction campaigns against US frontier models since at least late 2024. The framing is deliberate: this isn’t a footnote to how these companies build AI, the agencies call it the core of their entire development strategy. Distillation is a legitimate and widely used technique. It involves training a smaller AI model to reproduce the answers and capabilities of a larger one. But the advisory says the activity it uncovered went much further. It alleges that the companies sent millions of requests to models such as Claude, GPT, Gemini, and Grok and extracted billions of tokens. “China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy.” states the report. “Likely with Chinese government awareness, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024.” – https://securityaffairs.com/198770/security/us-agencies-warn-chinese-ai-firms-are-extracting-advanced-ai-models.html

Google fixes the seventh actively exploited Chrome zero-day of 2026

(Pierluigi Paganini – Security Affairs) Google released a Chrome update fixing 230 security vulnerabilities, including one already exploited in the wild tracked as CVE-2026-87491 (CVSS score of 8.8). The medium-severity flaw affects V8, Google’s open source high-performance JavaScript and WebAssembly engine, Chrome’s JavaScript and WebAssembly engine. An attacker can exploit the out-of-bounds write through a specially crafted HTML page and execute arbitrary code inside Chrome’s sandbox. Google fixed the issue in Chrome 153.0.8010.36 and later versions. “CVE-2026-87491: Out of bounds write in V8” reads the advisory. “Google is aware that an exploit for CVE-2026-87491 exists in the wild.” – https://securityaffairs.com/198757/security/google-fixes-the-seventh-actively-exploited-chrome-zero-day-of-2026.html

PoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5 BIG-IP APM Server Memory

(Pierluigi Paganini – Security Affairs) SophosLabs published a detailed technical analysis on September 8, 2026, of a Linux implant, dubbed PoisonedRefresh by ESET, they found in compromised F5 BIG-IP Access Policy Manager environments. Sophos tracks it as Linux/Agnt-IC. F5 has confirmed exploitation of the underlying vulnerability and links the activity to a cluster it tracks internally as c05d5254. “The malware targets deployments featuring Apache, libphp, APR module loading, BIG-IP APM webtop components, and BIG-IP upgrade workflows, suggesting it was developed for specific environments. F5 associates the related c05d5254 activity with BIG-IP APM systems affected by CVE-2025-53521, an exploited unauthenticated RCE in BIG-IP APM when an access policy is configured on a virtual server.” reads the report published by SophosLabs. “If you believe you are, or have been, using affected BIG-IP APM versions, follow F5’s remediation and compromise-assessment guidance before applying generic Apache or PHP hardening recommendations”. The short version: the web shell is real and works as expected, but the implementation removes almost every artifact defenders normally use to find it. – https://securityaffairs.com/198746/malware/poisonedrefresh-a-fileless-linux-rootkit-that-injects-php-web-shells-into-f5-big-ip-apm-server-memory.html

Chaotic Eclipse Released ShieldCrash, A PoC For Microsoft Defender Zero-Day

(Pierluigi Paganini – Security Affairs) Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Microsoft Defender. The researcher named the exploit ShieldCrash, it triggers an arbitrary file read as SYSTEM. The researcher claims that Microsoft has not fully fixed the ShieldBreak vulnerability (CVE-2026-69414). According to the researcher, Microsoft closed several ways to exploit the flaw but missed a specific condition that still allows the same attack. The researcher published a proof of concept (PoC) that can read arbitrary files with SYSTEM privileges, the highest level of access on Windows. He says all supported Windows versions remain vulnerable, even after the September 2026 security updates. – https://securityaffairs.com/198726/security/chaotic-eclipse-released-shieldcrash-a-poc-for-microsoft-defender-zero-day.html

Microsoft’s Biggest Patch Tuesday: 974 CVEs, 2 Zero-Days and 20 Wormable Bugs

(Pierluigi Paganini – Security Affairs) Microsoft’s September 2026 Patch Tuesday set a new record. Depending on how researchers count external and Chromium bugs, Microsoft fixed between 966 and 997 CVEs in this update. The company also fixed another 204 vulnerabilities earlier in September across Azure, Entra ID, Edge, and other services. This means the total number of September fixes is already much higher than the headline figure. “It’s a new record release from Microsoft, but, again, that seems to be the new normal. As always, counting this beast is tricky, but I see 972 new CVEs rolling out from Redmond this month.” reads the report published by ZDI. “On the one hand, congrats to the security gnomes at Microsoft for being able to patch bugs at this rate. On the other hand, AI-assisted vulnerability discovery shows no signs of slowing down. However, we have not seen a correlating spike in active exploits – yet”. The number of addressed issues skyrockets due to the use of AI for code auditing in the monthly counts, it has been climbing steadily through 2026. What hasn’t arrived yet, and ZDI notes the absence explicitly, is a corresponding spike in active exploits, though 58 of this month’s fixes are rated by Microsoft as more likely to be exploited. – https://securityaffairs.com/198705/security/microsofts-biggest-patch-tuesday-974-cves-2-zero-days-and-20-wormable-bugs.html

US State Department updates China travel advisory, warning electronic communications surveillance

(DigWatch) The US Department of State has updated its travel advisory for China, warning US citizens that Chinese security services may be able to access private electronic communications and that messages critical of Chinese authorities could result in detention or deportation. The advisory, reissued on 4 September, maintains mainland China at Level 2, ‘Exercise Increased Caution’. The State Department said there was no change to the advisory level or risk indicator, but updated its summary of the risks facing US citizens. It cites what it describes as the arbitrary enforcement of local laws, the use of exit bans without a fair and transparent legal process, and the risk of detention. – https://dig.watch/updates/us-updates-travel-advisory-for-china

G7 cybersecurity group urges post‑quantum migration

(DigWatch) The G7 Cyber Security Working Group and the US Cybersecurity and Infrastructure Security Agency have urged governments and organisations to begin preparing for the risks posed by quantum computing. Their new call to action warns that advances in quantum technology could eventually undermine widely used public-key encryption and put sensitive information and digital infrastructure at risk. The guidance stresses that organisations should not wait until powerful quantum computers become available. Attackers can already collect encrypted information with the intention of decrypting it in the future, while sufficiently powerful quantum computers could also threaten authentication systems, potentially allowing trusted identities to be impersonated and creating wider supply-chain risks. – https://dig.watch/updates/g7-cybersecurity-urges-post-quantum-migration

US claims Chinese AI firms are carrying out ‘industrial-scale’ theft of trade secrets

(Sean Lyngaas – CNN) Chinese artificial intelligence firms are committing “industrial-scale” theft of their American counterparts’ trade secrets to save money and bring the coveted technology to market faster, US federal agencies alleged Tuesday. Major Chinese tech companies are using “distillation,” which involves training lesser AI models on more advanced ones, to “extract restricted proprietary functionalities and capabilities of U.S. frontier AI models,” the FBI, National Security Agency, and Cybersecurity and Infrastructure Security Agency claimed in an advisory. Distillation can be a legitimate research technique, but American officials and AI executives have long complained that the volume and targeted manner of Chinese distillation campaigns against US firms amount to stealing. The new advisory puts more evidence behind those accusations and adds to the growing tensions between US and China over AI technology. President Donald Trump has said that AI will be among the discussion topics when he hosts Chinese leader Xi Jinping in Washington, DC, later this month. “The sheer scale of these campaigns and their sophistication indicate that distillation is not a supplement to these companies’ AI model development, but the critical core of it,” the new advisory says. – https://edition.cnn.com/2026/09/08/politics/us-accuses-china-of-stealing-ai-technology

Courts nnd Litigation

India child rights body summons Meta over alleged abuse ads

(DigWatch) According to Indian media reports, the National Commission for Protection of Child Rights (NCPCR) has summoned Meta India’s leadership to appear before the commission on 9 September 2026 as part of an inquiry into allegations that advertisements linked to child sexual exploitation and abuse material appeared on Instagram. The summons follows an earlier NCPCR notice issued to Meta on 3 July, after the commission took suo motu cognisance of a BBC Eye investigation into alleged paid advertisements promoting or facilitating access to child sexual abuse material. Meta responded around a week later, after which the commission reportedly decided on 4 August to open a formal inquiry. –  https://dig.watch/updates/india-child-rights-body-summons-meta-over-alleged-abuse-ads

Delaware court finds X likely abandoned the tweet mark and bird logo

(DigWatch) Chief Judge Colm F. Connolly of the US District Court for the District of Delaware granted X Corp. a partial preliminary injunction on 3 September 2026 in its Twitter trademark dispute with the start-up Operation Bluebird. The order bars Operation Bluebird from using the ‘Twitter’ name while the case continues, but does not extend to the ‘tweet’ word mark or the bird logo. X Corp. sued in December 2025, after Operation Bluebird filed two intent-to-use applications with the US Patent and Trademark Office to register ‘TWITTER’ and ‘TWEET’ and announced a social networking platform under the domain twitter.new. The start-up, co-founded by a former Twitter trademark lawyer, argued that X Corp. abandoned the marks when it rebranded the platform in July 2023. X Corp.’s claims include trademark infringement, counterfeiting, false designation of origin, unfair competition, and dilution under federal and Delaware law. By late December, more than 140,000 people had reserved handles on the platform. – https://dig.watch/updates/twitter-trademark-injunction-tweet-bird-logo

Frontiers

OpenAI addresses user data questions surrounding proposed Navier–Stokes solution

(DigWatch) OpenAI announced that an internal AI system had produced a solution to the Navier–Stokes existence and smoothness problem, one of mathematics’ seven Millennium Prize Problems. Alongside the mathematical result, the company addressed questions about whether data submitted by two researchers using its AI tools could have contributed to the models involved. The Clay Mathematics Institute (CMI) designated the question as one of seven Millennium Prize Problems in 2000, with USD 1 million allocated for the solution of each problem. Only one of the seven, the Poincaré Conjecture, has previously been resolved, following work by mathematician Grigori Perelman in 2002 and 2003. – https://dig.watch/updates/openai-navier-stokes-claim-and-user-data