Daily Digest on AI and Emerging Technologies (24 September 2026)

Governance, Regulation, Legislation, Geostrategies

U.S. President Donald Trump rebrands AI as ‘Super Intelligence’ and opposes regulation at UN General Assembly – During his address to the United Nations General Assembly on 22 September, U.S. President Donald Trump called for artificial intelligence to be renamed as ‘superintelligence’ and argued against regulation as he stated that ‘we’re going to encourage it, not rein it in’. His speech comes after a week of intense public debate around AI safety and governance, particularly within the United States. In terms of rebranding AI, Trump explained that ‘the use of the word artificial makes intelligence sound fake […] and it is not fake. It’s actually amazing but we have to be careful.’ He then discussed the growing concerns around AI safety and existential risks that have emerged following the hack of Hugging Face by rogue OpenAI agents and the public resignation of an Anthropic researcher, comparing fears about AI to fears about climate change. Trump said that ‘every major new technology brings challenges, and super intelligence is no exception. Yet the very same people who said we’ll all be dead in 12 years because of global warming […] are now saying that AI is going to kill us all’. – https://dig.watch/updates/trump-rebrands-ai-and-opposes-regulation-at-unga

WHO urges stronger safeguards for AI-related health research – The World Health Organisation (WHO) marked the virtual launch of a new report on 21 September, calling for stronger ethics oversight of artificial intelligence (AI)-related health research and warning that existing review mechanisms may not fully address the risks the technology introduces. The event presented the report Artificial intelligence-related health research: Ethics review and oversight, developed jointly by WHO experts in research ethics, science, and digital health and AI. ‘Artificial intelligence is creating unprecedented opportunities to accelerate health research and improve people’s lives‘, said Dr Meg Doherty, Director of WHO’s Department of Science for Health, in a statement marking the launch. She added that ‘At the same time, innovation must be guided by strong ethical safeguards that protect human dignity, rights and equity‘. – https://dig.watch/updates/who-ai-health-research-ethics

ILO study finds AI is reshaping work in Chinese enterprises – AI adoption is increasing productivity in some Chinese enterprises while creating concerns about job displacement, skills shortages, and workers’ future incomes, according to a new International Labour Organization (ILO) study . The research draws on interviews with 21 enterprises across several sectors and a survey of 1,591 professionals. Companies that measured AI’s impact reported substantial productivity improvements. At one insurance company, 300 customer-service employees increased the number of issues handled daily from 6,000 to 15,000. Another insurance group reduced recruitment times from 30 to 13 days, while a manufacturing facility reported a 30% increase in production efficiency. However, the figures were self-reported and not independently verified, and most firms lacked systematic methods for assessing AI’s wider effects. – https://dig.watch/updates/ilo-study-ai-work-chinese-enterprises

EU reports identify gaps in AI use and digital education – The European Commission has published two reports examining the use of generative AI in teaching and learning and the progress of digital education across European education systems. The findings identify differences in access to digital infrastructure, teacher preparedness, and the development of national policies for AI in education. The first report, Friend or foe? Evidence from the use of generative artificial intelligence in learning and teaching examines the growing use of generative AI in education. It finds that the technology’s benefits for learning depend on how it is used, while its long-term effects on students’ skills remain unclear. The report calls for initial and continuing professional development for teachers, supported by institutional guidelines on responsible AI use. – https://dig.watch/updates/eu-reports-gaps-ai-use-digital-education

‘Ask us first’: Children demand a voice on AI’s future – The first generation to grow up with AI may also be the last one anyone thinks to ask about it – and that has to change, the UN’s top human rights official said on Tuesday. “Today’s children are the first generation to grow up with artificial intelligence – yet often the last to be asked for their views,” UN High Commissioner for Human Rights Volker Türk told a high-level meeting in New York on protecting children in the age of AI, held on the sidelines of the General Debate. Children, he insisted, must be treated as full rights-holders in how AI is built and used – not an afterthought once the technology has already shaped their lives. The meeting was co-chaired by French President Emmanuel Macron, Spanish Prime Minister Pedro Sánchez, Kenyan President William Ruto and Australian Prime Minister Anthony Albanese. – https://news.un.org/en/story/2026/09/1168403

ICANN published IDN and UA adoption report 2026 – The Internet Corporation for Assigned Names and Number (ICANN) has published the Internationalized Domain Names (IDNs) implementation and Universal Acceptance (UA) adoption report 2026, which assesses progress on IDNs and UA. The report also covers developments in IDN policy and implementation, Label Generation Rules, IDN Implementation Guidelines, and work supporting the New gTLD Program 2026 round. UA refers to the technical readiness of Internet-enabled software applications and systems to accept, validate, store, process, and display all valid domain names and email addresses correctly and consistently, regardless of their script, language, or character length. This includes IDNs and internationalized email addresses enabled through Email Address Internationalization (EAI). – https://dig.watch/updates/icann-published-idn-and-ua-adoption-report-2026

Security and Surveillance

Uk Prime Minister announces centre for information defence at the UN – Prime Minister Andy Burnham addressed the United Nations General Assembly in New York has announced that the United Kingdom will establish a National Centre for Information Defence. The centre is intended to detect and disrupt AI‑enabled disinformation campaigns by hostile actors and will work alongside intelligence agencies, government departments, law enforcement bodies and social media platforms. Burnham alleged that ‘the Kremlin spends around £1.3 bn each year on manipulating information’. He said Russian agencies have used ‘bots and fake websites, falsified newspaper articles, forged the branding of 28 British organisations, including universities and the BBC’. According to the BBC no immediate comment was recorded from the Russian delegation present in the hall. Burnham warned that artificial intelligence will ‘multiply’ existing threats and described the most advanced ‘Frontier AI’ as ‘one of the most significant challenges and opportunities of our age’. He said the United Kingdom will act as an ‘honest broker’ in efforts to agree global principles and standards for AI safety, transparency, access to models and safe development. – https://dig.watch/updates/uk-pm-information-defence-at-the-un

ENISA Cyber threat landscape 2026 reports on the leading and converging threats on the European cyber environment – The newly published ENISA Threat Landscape 2026, released on 22 September 2026, analyses cyber incidents and events observed throughout 2025 and places the current European threat environment in the context of geopolitical developments and increasingly interconnected digital ecosystems. Its central message is less about the emergence of entirely new threats than about the convergence and scaling of existing ones: cybercrime, state-linked activity, hacktivism and vulnerability exploitation increasingly rely on overlapping tools, techniques and dependencies. Based on the analysis of incidents and events observed between January and December 2025, the report presents a threat-centric assessment of the European cybersecurity environment, examining not only individual attack techniques but also how different threat actors, sectors and digital dependencies interact, the European Union Agency for Cybersecurity (ENISA) has identified ransomware, vulnerability exploitation and the growing use of artificial intelligence by threat actors among the most significant features of the EU’s current cyber threat landscape. – https://dig.watch/updates/enisa-eu-cyber-threat-landscape-2026

Ransomware Attacks Reach Record High for 2026 – Over 1000 organizations globally were hit with ransomware attacks during August, as the number of cyber extortion campaigns reached a new high for 2026, analysis of incidents has warned. According to NCC Group’s Cyber Threat Intelligence Report for August 2026, published on September 23, 1073 companies fell victim to ransomware attacks during the month. The report stated the figure represented a record high for 2026 and a 12% increase on the 973 organizations hit by ransomware attacks during July. During August, North America was the most common target for ransomware attacks, accounting for 44% of incidents, organizations in Europe accounted for 26% of known incidents, while 13% of ransomware attacks targeted victims in Asia. Organizations in South America, Africa and Oceania accounted for 6%, 2% and 2% of ransomware victims, respectively. – https://www.infosecurity-magazine.com/news/ransomware-attacks-reach-record/

EU Auditors Warn Information-Sharing Gaps Are Hindering Cyber Incident Response – The EU’s top audit institution has criticized the union for various “shortcomings” that are hindering its detection and response to large-scale cyber incidents. The EU Court of Auditors said in a new report that the bloc’s €1.4bn ($1.6bn) budget for cybersecurity is doing some good, but that it suffers from an Achilles heel, “The insufficient exchange of information”. A lack of formally defined roles is hampering cooperation between country-level CSIRTs and European Cyber Crisis Liaison Organisation Network (EU-CyCLONe), it warned. The slow transposition of NIS2 into national law is also having a negative impact, while national security laws restrict what information can be shared. – https://www.infosecurity-magazine.com/news/eu-auditors-slam-blocs-cyberinfo/

EvilTokens made phishing-as-a-service look easy. Then it got taken down – EvilTokens showed up in February 2026 and moved fast. Within months it had compromised more than 12,000 inboxes across over 10,000 organizations. Microsoft says the EvilTokens platform, operated by Storm-2992, is a phishing-as-a-service kit sold to cybercriminals through Telegram. The service costs $1,500 upfront and $500 per month, with additional tools available for extra fees. Its control panel lets customers build and manage phishing campaigns, customize landing pages, configure domains, track victims, and manage stolen authentication tokens. The platform includes 44 themes and uses AI to create targeted phishing emails based on a victim’s role. Lures can impersonate Microsoft services, document signing platforms, cloud providers, payment systems, and other business services. What made EvilTokens different wasn’t the phishing itself, it was the AI wrapped around it. Once a mailbox was open, an AI assistant sifted through the contents, mapped who controlled payments, and flagged the accounts worth targeting. A task that used to take a skilled operator hours now took the platform seconds, which meant far less skilled criminals could run campaigns that used to require real expertise. “Post-compromise, EvilTokens enabled threat actors to utilize AI assistants to sift through victim mailbox activity and engineer a phishing message based on the accessible email content. EvilTokens also allowed threat actors to conduct Microsoft Graph reconnaissance to map organizational structure and permissions, enabling continued access and potential lateral movement while tokens remain valid.” reads the report published by Microsoft. “While token-targeting phishing is not new, it has become far more common and industrialized over the last several years as organizations adopted multifactor authentication (MFA).” – https://securityaffairs.com/199593/cyber-crime/eviltokens-made-phishing-as-a-service-look-easy-then-it-got-taken-down.html

Fake LastPass on GitHub Led to an Infostealer That Killed 145 Security Tools – Someone impersonated LastPass on GitHub, got users to download a fake authenticator, and ended up killing 145 different antivirus and EDR products using a driver that Microsoft itself had signed. That last part is the one worth sitting with. LastPass’s Threat Intelligence, Mitigation, and Escalation team spotted the fake GitHub organization on August 13, 2026. It appeared high in search results for “LastPass Authenticator download” and used real LastPass logos and branding to look legitimate. The download page also displayed fake trust badges, including “VirusTotal Approved.” The badges were meaningless and were simply there to make users feel safe enough to download the file. Once LastPass brought in Delphos Labs for payload analysis, the picture got a lot bigger than one fake page. They found a shared kit actively impersonating more than 40 different companies, all running through the same infrastructure. This wasn’t a one-off phishing attempt, it was a malware-as-a-service operation with LastPass as just one of many skins on the same underlying product. “LastPass Threat Intelligence, Mitigation, and Escalation (TIME) Team, in partnership with Delphos, identified and disrupted a multi-stage malware delivery campaign impersonating at least 40 companies on GitHub.” reads the report published by LastPass. “The payload it delivered survived controls that were built to stop exactly this, with a Microsoft Windows Hardware Compatibility Publisher chain signature and a clean VirusTotal score. LastPass is internally tracking the infostealer as Rapuncel.” – https://securityaffairs.com/199577/malware/fake-lastpass-on-github-led-to-an-infostealer-that-killed-145-security-tools.html

Meta smart glasses raise privacy concerns in India – A investigation by MIT Technology Review has documented cases of covert recording involving smart glasses in India and concerns about their use around protests, raising questions about consent, surveillance and the safeguards available to people captured by wearable cameras. Among the cases documented is that of Shubnam, a 38-year-old transfeminine graphic designer who was recorded without their knowledge or consent by a content creator using Ray-Ban Meta glasses during a March protest at Delhi’s Jantar Mantar. An edited version of the footage was posted on Instagram in late May and subsequently circulated more widely, generating transphobic abuse, memes and AI generated images. Shubnam described being recognised by strangers following the video’s circulation and difficulties having copies removed. – https://dig.watch/updates/meta-smart-glasses-raise-privacy-concerns-india