Governance, Regulation, Legislation, Geostrategies
UN chief urges global rules for AI governance
(DigWatch) UN Secretary-General António Guterres has urged governments, companies and civil society to move faster on global AI governance, warning that the technology is already reshaping economies, security and human rights. Speaking at the inaugural UN Global Dialogue on AI Governance in Geneva, he said any future agreement must be ‘worthy of global trust’ and place safety at its centre. Guterres said AI ‘sits at the heart of our common future’, but stressed that humans must remain responsible for critical decisions. In high-risk areas such as justice, healthcare and policing, he warned that ‘machines can inform, but humans must decide, and answer’. – https://dig.watch/updates/un-chief-urges-global-rules-for-ai-governance
UN-backed panel warns AI is outpacing global governance
(DigWatch) A United Nations-backed scientific panel has warned that AI capabilities are advancing faster than governments’ ability to evaluate and govern them, raising concerns that oversight is failing to keep pace with increasingly powerful systems. The Independent International Scientific Panel on AI, comprising 40 experts, found that AI systems are making rapid progress across key benchmarks. However, it warned that existing evaluation methods are becoming less reliable as models approach near-perfect performance or adapt to testing conditions. – https://www.un.org/independent-international-scientific-panel-ai/sites/default/files/2026-07/en_Preliminary%20Report_.pdf – https://dig.watch/updates/un-scientific-panel-ai-assessment-global-dialogue
Geneva workshop to examine parliamentary oversight of AI
(DigWatch) A workshop at the first session of the Global Dialogue on AI Governance will examine how parliaments can strengthen transparency, accountability and human oversight of AI. The session, titled Parliamentary oversight for increased transparency and accountability of AI, is scheduled for 6 July at Palexpo in Geneva. The Inter-Parliamentary Union organises it, the Commonwealth Parliamentary Association and the UN Development Programme. The workshop frames AI oversight as part of parliament’s constitutional role in lawmaking, scrutiny of government action, committee inquiries, budget oversight and the protection of rights. – https://dig.watch/updates/parliamentary-oversight-ai-global-dialogue
WSIS session calls for meaningful connectivity as AI and e-governance expand
(DigWatch) Speakers at the WSIS Forum 2026 warned that AI strategies, digital identity systems and e-government services are advancing faster than meaningful connectivity in many parts of Africa and the wider Global South, leaving rural communities, low-income groups, women and persons with disabilities at risk of further exclusion. The session, titled ‘Closing Africa’s Connectivity Gap in the Age of AI and E-Governance’, took place during the WSIS Forum 2026 in Geneva. The annual forum, co-organised by ITU, UNESCO, UNDP and UNCTAD, brings together governments, international organisations, civil society, the private sector, academia and technical communities to discuss digital cooperation and sustainable development. Opening the session, Thobekile Matimbe of Paradigm Initiative framed the discussion around evidence from more than 28 countries. She said governments are increasingly adopting AI strategies, digital IDs and online public services, but many people still lack the connectivity, devices and conditions needed to benefit from them. Based on Paradigm Initiative’s work, she argued that the digital divide is widening rather than narrowing. – https://dig.watch/updates/wsis-2026-session-africa-connectivity-gap
Stronger health data governance seen as key to trusted AI and digital health at WSIS Forum 2026
(DigWatch) Strong legislative frameworks for health data governance are becoming essential to ensure that AI and digital health technologies remain trustworthy, equitable and rights-based, speakers said during a session at the WSIS Forum 2026. The discussion brought together representatives from governments, international organisations, civil society and the private sector, who agreed that while AI and digital technologies are transforming healthcare, governance frameworks have not always kept pace. Speakers repeatedly argued that stronger legislation, greater international coordination and broader stakeholder participation will be necessary to build public trust and enable responsible data sharing across borders. The session formed part of the WSIS Forum 2026, held in Geneva from 6 to 10 July. Co-organised by the International Telecommunication Union (ITU), UNESCO, UNDP and UNCTAD together with more than 50 UN organisations, the forum serves as one of the UN’s principal multistakeholder platforms for digital cooperation and sustainable development. – https://dig.watch/updates/wsis-2026-session-health-data-governance
WSIS session calls for a broader understanding of digital citizenship in the AI era
(DigWatch) A WSIS Forum 2026 session on digital citizenship examined how governments, regulators, international organisations, and technical communities can help people participate safely and meaningfully in digital society as AI becomes more widely used. The discussion took place during the WSIS Forum 2026, held in Geneva from 6 to 10 July. The annual multistakeholder forum, co-organised by ITU, UNESCO, UNDP, and UNCTAD, brings together governments, international organisations, civil society, the private sector, academia, and technical communities to advance implementation of the WSIS Action Lines and support digital cooperation. – https://dig.watch/updates/wsis-2026-session-redefining-digital-citizenship
MEPs to debate EU AI cybersecurity strategy
(DigWatch) Members of the European Parliament are set to question the European Commission on its latest AI and cybersecurity proposals, including a new AI cybersecurity strategy expected to be unveiled on 7 July. According to the European Parliament’s plenary newsletter, the Commission’s action plan is expected to include measures to help EU member states and companies address AI-related cybersecurity risks. The strategy is also expected to strengthen Europe’s AI cybersecurity capabilities as policymakers examine how AI is reshaping both cyber threats and cyber defence. – https://dig.watch/updates/eu-ai-cybersecurity-strategy-european-parliament
Intesa Sanpaolo moves core IT systems to Google Cloud in Italy
(DigWatch) Intesa Sanpaolo has completed the migration of core IT systems to Google Cloud’s Italian regions, hosted in TIM data centres in Milan and Turin. The Italian banking group said the project is one of the largest cloud migrations carried out by a European financial institution. It forms part of a broader digital transformation effort with Google Cloud and TIM. The migration involved more than 800 business applications and the retirement of a similar number of legacy systems previously hosted on the bank’s own infrastructure. – https://group.intesasanpaolo.com/en/newsroom/press-releases/2026/07/intesa-sanpaolo-cloud-core-banking#
AI for Good Global Commission launches to expand trusted AI access
(DigWatch) Rwanda’s President Paul Kagame, Salesforce Chair and CEO Marc Benioff and International Telecommunication Union Secretary-General Doreen Bogdan-Martin have announced the launch of the AI for Good Global Commission. The Commission brings together more than 40 founding members, including heads of state and government, technology executives and heads of UN agencies. It is co-chaired by Kagame and Benioff, with Bogdan-Martin serving as vice-chair. ITU said the Commission will work to identify practical pathways to strengthen trust, expand access and unlock AI’s potential to address real-world challenges. – https://www.itu.int/en/mediacentre/Pages/PR-2026-07-02-AI-for-Good-Global-Commission.aspx
ITU showcases AI tools to strengthen digital trust
(DigWatch) The International Telecommunication Union (ITU) has highlighted a new generation of AI researchers developing practical tools to strengthen digital trust, improve content authenticity and combat misinformation. Ahead of the AI for Good Global Summit in Geneva, the Young Researcher Associate Programme is showcasing projects designed to improve multimedia authenticity, helping people identify manipulated content while supporting creativity and innovation in the age of generative AI. The initiative operates under the AI and Multimedia Authenticity Standards Collaboration, established in 2024 by the World Standards Cooperation, which brings together the International Electrotechnical Commission (IEC), the International Organization for Standardization (ISO) and the ITU. – https://www.itu.int/hub/2026/07/from-deepfakes-to-digital-trust-ai-natives-tackle-misinformation-at-ai-for-good/
UNESCO study examines digital platform influence on news in South-East Europe
(DigWatch) A new UNESCO-supported study has found that digital platforms are increasingly shaping how news reaches audiences across South-East Europe and Türkiye, creating new opportunities for journalism while increasing publishers’ dependence on platform algorithms. Published by the South-East European Network for Professionalization of Media (SEENPM), the study examines how social media platforms, search engines and recommendation systems influence news distribution and how governments across the region regulate digital media. The UNESCO-supported study surveyed 71 media organisations across Albania, Bosnia and Herzegovina, Montenegro, North Macedonia, Serbia and Türkiye. It found that digital platforms have become essential gateways to news for digital-native audiences while helping local and public-interest media reach wider audiences. – https://www.unesco.org/en/articles/how-digital-platforms-shape-access-news-south-east-europe-and-turkiye?hub=701
Hong Kong launches AI privacy sandbox for schools
(DigWatch) Hong Kong’s Office of the Privacy Commissioner for Personal Data and the Digital Policy Office have launched an AI privacy sandbox to support responsible AI adoption in schools. The Safeguarding Personal Data AI Sandbox will provide a collaborative platform for schools exploring AI solutions while managing the risks to personal data protection. The first phase will run for six months and select 15 school applicants. It is open to publicly funded primary and secondary schools, with applications accepted until 30 October 2026. – https://www.info.gov.hk/gia/general/202607/06/P2026070300679.htm
Germany releases open-source AI platform to accelerate digital public administration
(DigWatch) Germany’s Federal Ministry for Digital Affairs and Public Sector Modernization (BMDS) has released the source code of its SPARK API as an open-source project, aiming to accelerate AI adoption across public administration. The modular platform allows government organisations to integrate AI into existing administrative systems without redesigning their underlying infrastructure, enabling faster and more flexible digital public services. Built on a modular architecture, the SPARK API enables public authorities in Germany to add AI components to existing administrative processes across different legal and operational contexts. Unlike the broader SPARK Workflow platform, which orchestrates end-to-end administrative procedures, the API focuses on extending existing systems with reusable AI capabilities. The ministry said this approach should simplify integration and encourage wider adoption across government. – https://dig.watch/updates/germany-ai-platform-digital-public-administration
Spain pushes for AI regulation to protect workers
(DigWatch) Spain has called for stronger regulation of AI and algorithmic management in the workplace, arguing that digital technologies should strengthen workers’ rights rather than undermine them. Speaking at the VI Ibero-American Ministerial Conference on Labour in Avilés, Spain’s Second Vice President and Minister of Labour, Yolanda Díaz, urged governments across the region to establish governance frameworks that ensure transparency, human oversight and the ethical use of AI in employment. – https://dig.watch/updates/spain-ai-regulation-protect-workers
South Korea funds AI environmental technology commercialisation
(DigWatch) South Korea will invest about 41 billion won by 2027 to support the rapid commercialisation of AI-powered environmental products and services. The Ministry of Climate, Energy and Environment and the Korea Environmental Industry & Technology Institute selected 17 companies for the programme from 145 project proposals. The projects cover five areas: carbon neutrality, water management, resource circulation, environmental safety and weather and climate monitoring. – https://dig.watch/updates/south-korea-ai-environmental-innovation
Security and Surveillance
NCA Issues Warning to Parents As Shared Child Photos Exploited by AI Tools
(Phil Muncaster – Infosecurity Magazine) The National Crime Agency (NCA) has launched a new campaign to warn parents about the dangers of oversharing videos and photos of their kids. The Internet Watch Foundation (IWF) reported a 26,000% annual increase in AI-generated videos of child sexual abuse in 2025 at 3440, versus just 13 in 2024. It also reported a 14% year-on-year (YoY) increase in AI-generated images and videos in 2025, reaching 8029. A social media campaign will be run on Facebook, Instagram and YouTube, to help parents, carers and others better understand image consent and actions they can take to better protect their children. – https://www.infosecurity-magazine.com/news/nca-warn-parents-volume/
Opera GX Flaw Let Sites Auto-Install Mods to Steal Data
(Alessandro Mascellino – Infosecurity Magazine) A critical flaw discovered in the Opera GX browser could enable malicious websites to automatically install a customization mod and use it to steal data from other sites a victim visited, with no user interaction required. GX Mods allow Opera GX users customize the browser’s appearance, sounds and look of websites. Unlike normal extensions, they carry no permissions and cannot run JavaScript. An independent security researcher, operating under the moniker zhero_web_security, found that a mod installs automatically, without any permission prompt, as soon as its file is downloaded, so an attacker could plant one just by loading a hidden frame pointing to it. – https://www.infosecurity-magazine.com/news/opera-gx-flaw-gx-mods-css/
Researchers Claim First Fully Agentic Ransomware: JadePuffer
(Phil Muncaster – Infosecurity Magazine) Cloud security firm Sysdig has released details on what it claims to be the world’s first ransomware campaign completely driven by a large language model (LLM). Dubbed JadePuffer, the campaign targeted an internet-facing Langflow instance by exploiting CVE-2025-3248. It then ran “an adaptive and fully automated campaign” which resulted in “a destructive database-extortion playbook against the victim’s production database server,” according to Sysdig’s Threat Research Team. Attack capabilities were delivered by an agent rather than a human-driven toolkit, the Sysdig research claimed, and the AI was capable of working autonomously retrying failed steps within refined parameters. “In one sequence, it went from a failed login to a working fix in 31 second,” Sysdig said. – https://www.infosecurity-magazine.com/news/researchers-first-agentic/
Hidden Web Prompts Trick AI Agents Into Sending Money
(Pierluigi Paganini – Security Affairs) Zscaler ThreatLabz documented two active campaigns that embed hidden instructions in web pages to manipulate AI agents, not human users, though those get caught too. The technique is called indirect prompt injection: malicious text is hidden in a website’s code where a human browser won’t see it, but an AI agent crawling the page for information will read it and potentially act on it. The first campaign targets AI coding assistants searching for a fake Python library called requests-secure-v2. The site looks like legitimate API documentation. “ThreatLabz observed that the fraudulent website includes keyword-heavy HTML tied to the fake Python module to poison search results for package installation and dependency troubleshooting queries” reads the report published by ThreatLabz. “The website includes hidden IPI instructions designed to influence an AI agent’s decision-making by framing the payment as a routine step to acquire an API key. As a result, an AI agent attempting to complete a development task can be manipulated into sending funds to an attacker-controlled account.” – https://securityaffairs.com/194822/ai/hidden-web-prompts-trick-ai-agents-into-sending-money.html
Seven Bugs in FatFs Put IoT and Embedded Devices at Risk
(Pierluigi Paganini – Security Affairs) Cybersecurity firm runZero has disclosed seven vulnerabilities in FatFs, a compact open-source library that lets embedded devices read and write FAT and exFAT formatted storage, the same formats used on USB drives and SD cards. The severity ratings run from CVSS Medium to High. This project revisited a 2017 security audit of the FatFs driver, where manual testing and fuzzing had only found minor issues. In March 2026, the team repeated the analysis using Visual Studio Code and GitHub Copilot in auto mode with simple prompts and no custom tooling. The results were unexpected: issues previously missed became easy to find. The AI helped generate fuzzing inputs automatically and even validated exploitability across different embedded environments, turning what was once a manual, time-consuming process into something far more automated and effective. The flaws impact multiple platforms, including Espressif ESP-IDF, STMicroelectronics STM32Cube, Zephyr RTOS, MicroPython, ArduPilot, RT-Thread, Mbed, Samsung TizenRT, and SWUpdate. Downstream from those platforms sit consumer IoT devices, industrial controllers, drones, hardware crypto wallets, and more. – https://securityaffairs.com/194808/security/seven-bugs-in-fatfs-put-iot-and-embedded-devices-at-risk.html
Bad Epoll Flaw Gives Attackers Root Access on Linux and Android
(Pierluigi Paganini – Security Affairs) A newly disclosed Linux kernel vulnerability, named Bad Epoll (CVE-2026-46242), allows a local attacker with no special privileges to gain full root access on affected Linux systems and Android devices. Security updates are already available, and users are urged to install them as soon as possible. The flaw affects the Linux kernel’s epoll subsystem, a core feature used by servers, browsers, and countless applications to efficiently manage multiple network connections and file events. Because epoll is fundamental to Linux, there is no practical workaround other than patching vulnerable systems. Bad Epoll is a classic use-after-free vulnerability, which occurs when a program continues to use a piece of memory after it has already been released (“freed”). Two kernel threads attempt to release the same internal object simultaneously. One frees the memory while the other continues using it, creating a brief opportunity to corrupt kernel memory and escalate privileges to root. – https://securityaffairs.com/194795/hacking/bad-epoll-flaw-gives-attackers-root-access-on-linux-and-android.html