Governance, Regulation, Legislation, Geostrategies
A joint commitment: AI speaks everyone’s language – In a joint effort, a group of 60 signatories, including Agentic AI Foundation, Anthropic, AI Singapore, Bhashini, Gates Foundation, UNICEF and World Bank Group, have united behind a shared five-year goal, for an estimated 3.4 billion people who speak languages currently underrepresented in today’s AI models to be able to use AI tools in their own language and voice. This brings together organisations working across datasets, models, benchmarks, applications, and implementation to connect and accelerate those efforts around a shared goal. As per the joint commitment, participating organisations, each contributing their individual resources and expertise, will work together to accelerate progress across four areas (i.e. building the open language layer, tracking progress honestly, turning language data into working tools and reaching people safely). It builds on years of work across the global AI ecosystem to improve language and voice capabilities and make AI more useful to people who speak underrepresented languages. – https://dig.watch/updates/a-joint-commitment-ai-speaks-everyones-language
EU proposes common sustainability rating scheme for data centres – The European Commission proposed a common EU-wide sustainability rating scheme for data centres on 21 September 2026. The scheme is intended to make energy and water use more transparent and allow facilities to be compared on a common basis, including their efficiency and wider contribution to the energy system. The proposal applies to data centres with at least 500 kW of installed IT power and would require disclosure of indicators including energy and water efficiency, local water stress conditions, and measures such as waste heat reuse. – https://dig.watch/updates/eu-data-centre-sustainability-rating-scheme
California signs seven laws regulating data centre water and energy use – California Governor Gavin Newsom has signed seven bills introducing new requirements for data centres, including rules covering electricity costs, water consumption, land use, and environmental review. The measures require proposed data centres to provide local governments and water suppliers with information on expected water use, available supply, efficiency measures, and drought planning. Data centre operators will also be responsible for upgrades needed to provide their facilities with sufficient water. The legislation also addresses the growing electricity requirements of data centres. Operators will be required to cover applicable grid-upgrade costs rather than shifting them to other electricity customers, comply with California’s energy procurement requirements, and bring additional clean-energy supply onto the grid. – https://dig.watch/updates/california-data-centre-water-and-energy-use
Australia’s Victoria introduces comprehensive rules for new data centres – The Victorian government released its Sustainable Data Centre Action Plan on 22 September 2026, setting new requirements for future data centre developments. New facilities will be prohibited in residential areas, near schools and childcare centres, and in rural locations considered unable to support them. A 150-metre buffer will also be required between new data centres and homes. The rules will not apply to more than 50 existing data centres or projects already in the planning pipeline. – https://dig.watch/updates/australia-victoria-sustainable-data-centres
Balancing Development and Security in Global AI Governance – Artificial intelligence (AI) is a core pillar of “comprehensive national power” in the People’s Republic of China (PRC), where senior officials frame the necessity of leadership in AI development as crucial for gaining an advantage in great power competition. Beijing is increasingly concerned about AI-related risks. Its calls for a global AI governance framework, however, are less about managing risks than about building non-Western influence in the AI domain. A recent collection of unusual People’s Daily articles on global AI governance advocate positioning the PRC as the rule-maker in the international system. None calls for cooperation with the United States, suggesting that this is not currently a priority for Beijing. – https://jamestown.org/balancing-development-and-security-in-global-ai-governance/
Republic of Korea plans dashboard to detect AI-related employment shocks – The Republic of Korea plans to strengthen a monitoring system designed to detect employment disruption linked to AI, as the government considers how labour policy should respond to changes associated with the technology. The Ministry of Employment and Labor discussed the planned ‘Canary Dashboard’ with experts from the Korea Labor Institute, Korea Development Institute, Korea Employment Information Service, and Science and Technology Policy Institute during an Employment Trends Review Meeting. The system is being prepared to provide real-time information on employment changes in major occupations with high exposure to AI. – https://dig.watch/updates/republic-korea-dashboard-ai-employment
Security, Surveillance
AI Incident Response Readiness Lags Behind AI Adoption, ISACA Finds – Most organizations have not rehearsed how they would handle an AI-related security incident, even as their security teams put AI to wider use, according to new research. ISACA’s 2026 State of Cyber report found that 71% of organizations have not run any AI incident response exercises. Just 3% have mature, formal runbooks for AI-specific incidents and 30% have not begun to address their response at all. Those exercises would cover scenarios such as sensitive data exposed through AI systems, AI-enabled phishing, fraud and social engineering and misuse of generative AI by employees or insiders. – https://www.infosecurity-magazine.com/news/orgs-lack-ai-incident-response/
Network Segmentation Failures Are Expanding the Corporate Attack Surface – Nearly half of network segments with OT or medical devices (IoMT) also contain IT and IoT, broadening the attack surface and raising the risk of lateral movement, according to Forescout. The security vendor analyzed 47,700 real-world network segments across organizations across multiple industries to compile its latest report, What 47,700 Segments Reveal About Network Segmentation. The report claimed that the average segment holds 54 devices across four device types: IT, OT, IoT, and IoMT. Although over three-fifths (62%) contained just one device category, 29% contained two and nearly one in 10 (9%) had three or more. A quarter (26%) contained IT and IoT, while only 13% of segments with OT devices in them were OT only, and only 6% of IoMT segments were IoMT only. – https://www.infosecurity-magazine.com/news/segmentation-failures-expanding/
AI Drives Surge in Bot and API Threats – AI helped drive a 300% increase in bot traffic last year, alongside a range of other enterprise threats, a new report from Akamai has revealed. The security vendor’s latest State of the Internet report, published on September 22, is based on threat intelligence gathered from across its global security and network infrastructure. Alongside the surge in bot traffic, which primarily impacted the commerce vertical, Akamai warned that AI is “elevating APIs as the dominant attack surface for modern enterprises”. It recorded a 113% increase in daily API attacks between 2024 and 2025. Some 87% of surveyed organizations experienced an API-related security incident in 2025; up from 76% in 2022. – https://www.infosecurity-magazine.com/news/ai-drives-surge-in-bot-and-api/
CISOs Must Update Incident Response Playbooks for Multimodal Deepfakes, Gartner Warns – Almost half of CISOs have reported at least one deepfake incident in the past 12 months, highlighting the need to update incident response playbooks to address multimodal deepfake threats. As the opening of the Gartner Security & Risk Management Summit in London on September 22, the global consulting firm published findings from its AI-driven Social Engineering Attacks report, which surveyed 297 senior cybersecurity leaders. The study, conducted between survey conducted in March and May 2026, found that AI is increasing the volume, personalization and credibility of social engineering while reducing the reliability of familiar detection cues. – https://www.infosecurity-magazine.com/news/update-incident-response/
Contagious Interview: 30,000 devices infected by a fake job interview – On September 18, Japan’s National Police Agency, the FBI, the US Department of Defense’s Cyber Crime Center, and intelligence agencies from Australia and Germany published a joint advisory about a group called WaterPlum, better known as Contagious Interview. The name says it all. The job interview is the infection vector. The numbers in the advisory are hard to shrug off. At least 30,000 devices infected across more than 100 countries, funds or credentials stolen from over 7,000 cryptocurrency wallets, and a total of 1.7 billion yen, roughly $10.71 million, funneled back to North Korea. The victims are almost always the same type: freelance developers and specialists in blockchain and Web3 work. Japan’s NPA and the FBI assess that both WaterPlum operators and some North Korean IT workers report to the same place, the 313 General Bureau of the Munitions Industry Department, under the Workers’ Party’s Central Committee. That’s not a loose affiliation. It’s an org chart. – https://securityaffairs.com/199506/uncategorized/contagious-interview-30000-devices-infected-by-a-fake-job-interview.html
Maritime cyber risk in satellite-linked edge devices increases to 22% of the maritime cyber incidents in 2025 – Maritime cyber risk is increasingly extending beyond traditional onboard IT systems towards the satellite-linked edge devices. A September 2026 analysis reported that attacks exploiting such devices accounted for 22% of maritime cyber incidents tracked by cybersecurity company Cydome in 2025, compared with 3% in 2024; the absolute number of attacks was reported to be in the hundreds. These devices provide the communications bridge between ships, shore-based systems and satellite networks, but can also provide an entry point into onboard environments. Vulnerabilities identified in iDirect equipment used for satellite connectivity illustrate this exposure: the US Cybersecurity and Infrastructure Security Agency issued an advisory on vulnerabilities affecting the technology in July and updated it in September. The growing use of satellite connectivity, including low-Earth-orbit services such as Starlink, is further expanding the number of external connections available to increasingly connected vessels. – https://dig.watch/updates/maritime-cyber-risk-linked-edge-devices-i
Cyble and UAE Cyber Security Council join under MoU over the country national cybersecurity strategy 2025-2031 – UAE and Cyble announced the signing of a Memorandum of Understanding (MoU) with the United Arab Emirates’ Cyber Security Council (CSC), the federal entity responsible for strengthening the country’s cybersecurity posture. The agreement establishes a framework for cooperation centred on advanced threat intelligence, early-warning capabilities and actionable information on emerging cyber risks affecting government and critical-infrastructure entities. Cyble’s AI-native threat-intelligence platform, Cyble Vision, powered by Blaze AI, is expected to support the collaboration by detecting, analysing and contextualising threats including ransomware, phishing, fraud, malicious campaigns and vulnerabilities. – https://dig.watch/updates/cycle-uae-mou-threat-intelligence-2025-2031
Frontiers and Markets
Biotechnology : Anthropic expands access to frontier AI with massive advancements in biomolecular modelling – Sept 2026 – The convergence of frontier artificial intelligence and biotechnology is entering a new phase, as Anthropic has simultaneously expanded controlled access to its most capable AI models for life-science research and reported substantial improvements in the computational tools used to model and design biological molecules. Taken together, the developments illustrate how AI is moving beyond being a supporting tool for biotechnology toward becoming an increasingly capable component of the biological research process. Anthropic opened applications for its Life Sciences Verification Program (LSVP), a beta programme giving verified life-science organisations access to its Mythos, Opus and Sonnet models with safeguards specifically adapted for biology-related work. The programme is intended for a broad range of activities, including drug discovery, research biology, clinical development, manufacturing, quality assurance and regulatory work. Anthropic said dozens of organisations had already participated in an earlier access programme and that it expected to expand the programme to hundreds of organisations. – https://dig.watch/updates/anthropic-ai-biomolecular-modelling
Swiss PPP to establish a post-quantum semiconductor and cybersecurity capability Centre in Jura – WISeKey International Holding Ltd, its subsidiary SEALSQ Corp and the Republic and Canton of Jura announced on 21 September 2026 the signing of a Memorandum of Understanding (MoU) to explore the establishment of a post-quantum Semiconductor and Cybersecurity Center in the Swiss canton of Jura under a public-private partnership (PPP). The proposed Jura Center would focus on the design, personalisation, testing and secure provisioning of next-generation post-quantum semiconductor technologies, positioning the initiative at the intersection of quantum-resistant cryptography, semiconductor security and digital sovereignty. – https://dig.watch/updates/swiss-post-quantum-semiconductor-centre