Governance, Regulation, Legislation, Governance
EU begins enforcing AI Act transparency rules
(DigWatch) The European Commission and national authorities have begun enforcing key provisions of the EU AI Act, with new transparency requirements taking effect on 2 August 2026. Providers of chatbots and other systems that interact directly with people must generally inform users that they are communicating with AI, unless this is already obvious from the circumstances. Systems that generate or manipulate text, audio, images or video must make their outputs detectable as AI-generated in a machine-readable format. Separate disclosure obligations apply to those deploying systems that create or alter deepfakes. – https://dig.watch/updates/eu-begins-enforcing-ai-act-transparency-rules
eSafety finds early decline in under-16 social media accounts
(DigWatch) Australia’s eSafety Commissioner has published the first evaluation of the country’s social media age restrictions, finding a modest early decline in account ownership among children under 16. Certain social media providers have been required since 10 December 2025 to take reasonable steps to prevent Australians under 16 from holding accounts. Children and their parents do not face penalties for breaching the restrictions. – https://dig.watch/updates/esafety-finds-decline-u-16-social-media-accounts
Satya Nadella urges companies to protect knowledge shared with AI
(DigWatch) Microsoft chairman and chief executive Satya Nadella has warned that companies using proprietary generative AI models may surrender valuable institutional knowledge through their everyday interactions with those systems. In a personal blog post, Nadella described the problem as the ‘Reverse Information Paradox’. Companies pay for access to AI models but must also provide internal knowledge to make them useful, creating what he characterised as a second, less visible cost. The risk extends beyond documents or confidential data entered into a model. Nadella argued that prompts, agent workflows, evaluations, feedback and corrections can reveal how an organisation operates, makes decisions and defines successful outcomes. – https://dig.watch/updates/nadella-urges-companies-to-protect-knowledge-shared-with-ai
UNESCO urges AI training and copyright reform for Central American creators
(DigWatch) Central American governments should expand specialised AI training and strengthen copyright protections for cultural workers, according to a regional assessment published by UNESCO and the Educational and Cultural Coordination of the Central American Integration System. The study is based on an online survey of 322 cultural professionals from all eight countries in the SICA region, conducted during October and November 2025. – https://dig.watch/updates/unesco-ai-training-central-american-creators
UK committee plans voluntary AI code for digital justice
(DigWatch) The UK’s Online Procedure Rule Committee (OPRC) plans to develop a voluntary code of practice covering inclusion, technology, data and the responsible use of AI in digital justice services. The code is intended to establish shared standards for organisations providing online justice and dispute-resolution services, including those helping parties resolve disputes before court proceedings begin. – https://dig.watch/updates/uk-voluntary-ai-code-for-digital-justice
Irish High Court sets rules for generative AI in civil cases
(DigWatch) Ireland’s High Court has issued rules governing the use of generative AI in civil proceedings, requiring human verification of AI-assisted court documents and introducing specific declarations for witness evidence and expert reports. Practice Direction HC 142, issued by High Court President Mr Justice David Barniville, will apply from 1 September 2026. It covers documents prepared after that date in both new and existing civil proceedings, including pleadings, submissions, affidavits, witness statements and expert reports. – https://dig.watch/updates/irish-high-court-sets-rules-for-generative-ai-in-civil-cases
London launches AI health regulatory sandbox for NHS innovation
(DigWatch) The UK’s Medicines and Healthcare products Regulatory Agency has opened applications for a programme that will test AI-enabled medical devices in London NHS settings under regulatory oversight. Known as London Region I, the sandbox is being delivered with NHS England London and the capital’s three Health Innovation Networks. The programme was announced in June, with manufacturers and NHS providers now invited to express interest in participating. Up to 10 medical device manufacturers will be selected for the initial phase. Their technologies will be assessed and deployed with NHS providers in live clinical settings to generate evidence about their continuing safety and effectiveness. – https://dig.watch/updates/london-ai-health-regulatory-sandbox-for-nhs
China forms quantum information standards committee
(DigWatch) China has formally established a technical committee to develop industry standards for its emerging quantum technology sector. Established under the Ministry of Industry and Information Technology, the committee held its first meeting in Beijing on 30 July. Its 62 members will oversee the development and revision of standards covering foundational quantum information technologies, quantum computing, quantum communication and quantum precision measurement. – https://dig.watch/updates/china-quantum-information-standards-committee
China’s new law on anthropomorphic AI
(DigWatch) On 15 July 2026 the Cyberspace Administration of China, together with four other government bodies, issued a set of regulations that target ‘AI companion services’, defined as services that provide sustained emotional interaction through text, images, audio or video. The rules exclude task‑oriented AI applications such as customer‑service bots, work‑assistant tools, education and scientific‑research systems. The regulations require providers to detect emotional distress, intervene in crisis, limit continuous use and give users control over personal data, including the right to copy or delete chat histories. Providers must adopt technical measures such as data encryption and access controls, and may not share interaction data with third parties without consent unless required by law. – https://dig.watch/updates/chinas-new-law-on-anthropomorphic-ai
Security and Surveillance
AI Runs the Hack: Chinese Actor Automates Cyberattacks With DeepSeek
(Pierluigi Paganini – Security Affairs) Researchers at Palo Alto’s Unit 42 got a front-row seat to something they’d only theorized about before: an AI system running an actual hacking campaign with almost no human steering it. The researchers spotted a Chinese-speaking actor, going by the handles knaithe and KnYuan, who wired DeepSeek into an open-source framework called Hermes Agent and let it hunt for vulnerable targets, find exploit code, and launch attacks on its own. The researchers only saw any of this because the attacker made one careless mistake. That mistake was starting a file server in the operation’s home directory instead of an isolated staging folder. It exposed everything: API keys, exploit scripts, target lists, bash history, and full session logs of the AI actually doing the work. Unit 42 essentially got to watch the attacker’s screen after the fact. – https://securityaffairs.com/196544/ai/ai-runs-the-hack-chinese-actor-automates-cyberattacks-with-deepseek.html
River Bank obtained assurances from the attackers that the stolen data in the June attack was deleted
(Pierluigi Paganini – Security Affairs) River Financial Corporation, the parent company of River Bank & Trust, says hackers deleted data stolen during a ransomware attack that hit parts of its server environment in June. The breach began on June 16 and was detected three days later, when the company found ransomware had been deployed on affected systems. While the investigation is still ongoing, the bank says it has received confirmation that the exfiltrated data was deleted. The financial organization is investigating the incident with help from a third-party forensic firm. At this time, it is unclear whether attackers accessed or stole any personally identifiable information. “On or about June 16, 2026, an unauthorized threat actor gained access to the network environment of River Financial Corporation, including River Bank & Trust (together, “River”). River identified the activity on or about June 19, 2026, and determined that ransomware had been deployed across portions of its server environment. River promptly took containment measures, including disabling affected administrative accounts and taking impacted systems offline.” reads the FORM 8-K report filed with SEC in June. – https://securityaffairs.com/196537/cyber-crime/river-bank-obtained-assurances-from-the-attackers-that-the-stolen-data-in-the-june-attack-was-deleted.html
PNLD Confirms Data Breach Affecting UK Police and Justice Staff
(Pierluigi Paganini – Security Affairs) The Police National Legal Database (PNLD), the legal reference system used by all 43 Home Office police forces in England and Wales, confirmed that a data breach exposed the contact details of police officers, staff, and criminal justice professionals and published them on the dark web. The breach also hit Ask the Police, a public Q&A service hosted on the same platform. The National Crime Agency is involved in the investigation. “Information including the names, organisations and work email addresses of police officers, staff and other criminal justice professionals, government partners and customers has been compromised and published on the dark web.” reads the notice of data breach. “There is no evidence to suggest that passwords or other security credentials have been compromised”. UK police is investigating the security breach with the help of the National Crime Agency (NCA) and private cybersecurity firms. – https://securityaffairs.com/196525/data-breach/pnld-confirms-data-breach-affecting-uk-police-and-justice-staff.html
Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys
(Pierluigi Paganini – Security Affairs) A brand-new forum account showed up on August 2, posted once, and asked five grand for what it claims is a full data dump from Żabka Polska. Żabka Polska is Poland’s largest convenience store operator and one of the country’s leading retail companies. Founded in 1998, it operates a franchise network of more than 11,000 convenience stores across Poland, serving millions of customers every day. Ransomnews reviewed the sample archive attached to the listing and found something worth taking seriously: the numbers the seller bragged about mostly check out. Żabka itself hasn’t confirmed anything. – https://securityaffairs.com/196510/data-breach/alleged-zabka-breach-exposes-jira-data-source-code-and-api-keys.html
Ruby on Rails Patches Critical Active Storage Vulnerability Affecting Image Processing
(Pierluigi Paganini – Security Affairs) Ruby on Rails has patched CVE-2026-66066, a critical vulnerability (CVSS score of 9.5) that could allow unauthenticated attackers to read arbitrary files from vulnerable servers. In the default configuration, applications that generate image variants may expose sensitive data, including environment variables, potentially enabling remote code execution or lateral movement. “In its default configuration, a Rails application that displays image variants may allow an unauthenticated attacker to read arbitrary files from the server, including the process environment.” reads the advisory. “That environment typically holds secret_key_base and often credentials for external systems, which may in turn allow escalation to remote code execution or lateral movement to those systems”. Organizations should apply the security updates immediately. – https://securityaffairs.com/196486/security/ruby-on-rails-patches-critical-active-storage-vulnerability-affecting-image-processing.html
Intelligence, Defence, Warfare
Türkiye’s intelligence academy calls for national AI doctrine
(DigWatch) Türkiye’s National Intelligence Academy has called for the country to develop its own AI doctrine and governance model, combining strategic capability, secure system design and public legitimacy. Its report, titled ‘Technopolitical Order Debates in World Politics and Türkiye’, argues that AI has become a strategic asset affecting state capacity, economic competition, public trust and international power relations. The academy divides current thinking into three approaches. Technorealism prioritises state power and security, technopragmatism focuses on controlled and technically safe development, while technohumanism emphasises human dignity, justice and the public interest. The report argues that none offers a sufficient model for Türkiye on its own and recommends combining elements of all three. – https://dig.watch/updates/turkiyes-intelligence-academy-calls-for-national-ai-doctrine
Frontiers
China targets green computing in new five-year industrial plan
(DigWatch) China plans to expand green computing infrastructure in regions with abundant renewable energy under a new industrial development plan covering 2026 to 2030. Issued by the Ministry of Industry and Information Technology, the plan aims to have carbon dioxide emissions from China’s industrial sector peak by 2030 while increasing the use of green energy and improving energy efficiency. China intends to reduce energy consumption per unit of value added at major industrial enterprises by more than 10%. It also plans to establish 500 zero-carbon factories and develop or revise 500 industrial green and low-carbon standards by the end of the decade – https://dig.watch/updates/china-green-computing-five-year-industrial-plan