G7 working group advances cybersecurity approach for AI systems

The German Federal Office for Information Security published guidance developed by the G7 Cybersecurity Working Group outlining elements for a Software Bill of Materials for AI. The document aims to support both public and private sector stakeholders in improving transparency in AI systems.

The guidance builds on a shared G7 vision introduced in 2025 and focuses on strengthening cybersecurity throughout the AI supply chain. It sets out baseline components that should be included in an AI SBOM to better track and understand system dependencies.

The document outlines seven baseline building blocks that should form part of an AI Software Bill of Materials (SBOM for AI), designed to improve visibility into how AI systems are built and how their components interact across the supply chain.

At the foundation is a Metadata cluster, which records information about the SBOM itself, including who created it, which tools and formats were used, when it was generated, and how software dependencies relate to one another.

The framework then moves to System Level Properties, covering the AI system as a whole. This includes the system’s components, producers, data flows, intended application areas, and the processing of information between internal and external services.

A dedicated Models cluster focuses on the AI models embedded within the system, documenting details such as model identifiers, versions, architectures, training methods, limitations, licenses, and dependencies. The goal is to make the origins and characteristics of models easier to trace and assess.

The document also introduces a Dataset Properties cluster to improve transparency into the data used throughout the AI lifecycle. It captures dataset provenance, content, statistical properties, sensitivity levels, licensing, and the tools used to create or modify datasets.

Beyond software and data, the framework includes an Infrastructure cluster that maps the software and hardware dependencies required to run AI systems, including links to hardware bills of materials where relevant.

Cybersecurity considerations are grouped under Security Properties, which document implemented safeguards such as encryption, access controls, adversarial robustness measures, compliance frameworks, and vulnerability references.

Finally, the framework proposes a Key Performance Indicators cluster that includes metrics related to both security and operational performance, including robustness, uptime, latency, and incident response indicators.

According to the paper, the objective is to provide practical direction that organisations can adopt to enhance visibility and manage risks linked to AI technologies. The framework is intended to support more secure development and deployment practices.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot

Council compromise text advances EU AI Act changes

The Council of the European Union has confirmed agreement on a compromise text for the Digital Omnibus on AI, a proposal intended to simplify parts of the EU AI Act’s implementation while preserving protections for health, safety, and fundamental rights.

The Permanent Representatives Committee confirmed the agreement on 13 May 2026, following informal negotiations between the EU institutions on 6 May. The Council Presidency was authorised to send a letter to the European Parliament stating that, if Parliament adopts the text at first reading, the Council will approve Parliament’s position.

The compromise text amends Regulation (EU) 2024/1689 on AI and Regulation (EU) 2018/1139 on civil aviation. It says targeted changes are needed because delayed standards, national governance structures, and conformity assessment frameworks have created compliance burdens heavier than expected.

The proposal would adjust several AI Act implementation rules, including provisions on AI literacy, treatment of small mid-cap enterprises, conformity assessment, AI regulatory sandboxes, real-world testing, and the role of the AI Office. It would also simplify some registration and monitoring requirements while providing more time for high-risk AI obligations to apply.

One major addition concerns prohibited AI practices. The text would prohibit placing on the market, putting into service, or using AI systems that generate or manipulate realistic non-consensual intimate images, videos, audio, or similar material of identifiable people. It would also prohibit AI systems that generate or manipulate child sexual abuse material, subject to limited lawful exceptions.

The compromise text also modifies the AI literacy obligation. Instead of requiring providers and deployers to ensure a sufficient level of AI literacy among staff, the revised wording would require them to take measures to support AI literacy, while clarifying that they are not required to guarantee a specific level for each individual.

For high-risk AI systems, the compromise text proposes delayed application dates for certain obligations: 2 December 2027 for systems classified as high-risk under Article 6(2) and Annex III, and 2 August 2028 for systems classified as high-risk under Article 6(1) and Annex I. The text says this is intended to address implementation challenges linked to delayed standards, guidance, and national competent authorities.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

IPC New South Wales’ Generative AI guidance targets privacy risks in Australia

The Information and Privacy Commission New South Wales, has issued guidance for public sector agencies in Australia on managing privacy risks associated with the use of generative AI tools.

The guide states that the Privacy and Personal Information Protection Act 1998 applies to the handling of personal information through generative AI tools. It is intended to help agencies understand and comply with privacy obligations when adopting tools such as ChatGPT, Gemini, Claude, Perplexity, and Copilot.

Generative AI can support workplace tasks such as drafting, editing, document analysis, research, translation, transcription, and process automation. However, the IPC warns that these tools can create privacy risks when prompts, uploaded files, or outputs include personal or health information.

The guide highlights risks including unexpected use or disclosure of personal information, cross-border data transfers, unauthorised disclosure, data breaches, extended retention of personal information, generation of new personal information, inaccurate or discriminatory outputs, and loss of transparency or data subject control.

Some generative AI providers may collect customer data, including prompts, uploaded files, and outputs, to train or improve their models, according to the IPC. Agencies should assess whether personal or health information uploaded to a generative AI service may be processed offshore or used for purposes beyond the original collection purpose.

Recommended measures include privacy impact assessments, updates to privacy management plans and data breach response policies, clear public notices, consent where required, acceptable use policies for staff, training, pre-deployment testing, third-party vendor assessments, and data residency in Australia where possible.

Human review is also presented as an important safeguard, especially where generative AI outputs inform decisions affecting individuals’ access to services, opportunities, or benefits. The IPC urges agencies to avoid a ‘set and forget’ approach and continuously monitor generative AI use, governance, culture, and emerging privacy risks.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

Republic of Korea and UAE deepen AI and semiconductor partnership through new investment forum

The Republic of Korea and the United Arab Emirates have expanded cooperation on AI infrastructure and semiconductors through a new bilateral investment forum focused on AI ecosystems, data centres and advanced chip technologies.

The forum, held in Seoul by the Republic of Korea’s Ministry of Trade, Industry and Resources alongside the Ministry of Science and ICT and the National AI Strategy Committee, brought together government officials, investors and technology firms from both countries. Discussions focused on practical cooperation across AI infrastructure, local-language AI models, semiconductors and industrial AI deployment.

A 25-member UAE delegation attended the event, including representatives from major investment and technology organisations such as Core42, MGX, Mubadala, the Abu Dhabi Investment Authority and the Technology Innovation Institute. Officials highlighted growing strategic competition around AI infrastructure and stressed the need for long-term international partnerships across the semiconductor and AI supply chain.

The discussions placed particular emphasis on low-power and high-efficiency AI infrastructure built around AI semiconductors, including neural processing units, alongside large-scale data centre development and AI service deployment. South Korean companies also presented investment proposals covering AI chips, infrastructure systems and industrial AI technologies during dedicated business sessions and networking meetings.

The initiative builds on expanding Republic of KoreaUAE cooperation following South Korean President Yoon Suk Yeol’s state visit to the UAE in 2025 and the UAE’s previously announced $30 billion investment commitment.

Officials from both sides argued that combining UAE investment capacity with South Korean expertise in semiconductors, manufacturing and AI infrastructure could support joint technology development and future expansion into global markets.

Why does it matter?

AI competition is increasingly centred on infrastructure, semiconductors and strategic investment alliances instead of only AI models and software. The Republic of Korea-UAE agreement highlights growing efforts by countries to secure influence across the global AI supply chain through cross-border partnerships involving data centres, specialised AI chips and industrial deployment.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!  

World Economic Forum highlights AI role in infrastructure security

The World Economic Forum has highlighted AI-driven network defence as a possible tool for protecting critical infrastructure, as cyberattacks on hospitals, power grids, schools and transport systems become faster and harder to detect.

Lumu Technologies founder and CEO Ricardo Villadiego says nation state actors and ransomware groups are increasingly targeting critical infrastructure such as hospitals, power grids, schools, utilities and transport networks. It argues that local authorities and community-level service providers often face these threats with limited resources and small teams.

The author points to the convergence of operational technology and internet-connected IT systems as a major source of vulnerability. As sensors, smart meters and programmable logic controllers become more connected, the attack surface expands across both digital and physical infrastructure.

The article also argues that AI is increasing the speed and stealth of cyberattacks, making it harder for human-led security teams to detect and respond to threats quickly. In response, it presents AI-driven network monitoring as one way to identify anomalies across connected systems and block malicious activity before it reaches physical control systems.

A key concern is the reliance on endpoint-only security. The article notes that many critical infrastructure environments contain unmanaged or outdated devices, such as industrial systems, medical equipment and physical control assets, where conventional security agents may not be practical.

Why does it matter?

Critical infrastructure cybersecurity is increasingly about the connection between digital systems and physical services. As hospitals, utilities, schools and transport networks become more connected, cyberattacks can cause real-world disruption. AI-driven defence tools may help overstretched teams monitor complex environments more effectively, but their use also raises questions about reliability, oversight and dependence on automated security decisions in essential services.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our chatbot!  

India accelerates AI-driven financial inclusion through digital public infrastructure

The role of AI in financial inclusion has been expanded in India by combining AI systems with large-scale digital public infrastructure (DPI). The framework connects identity verification, digital payments, consent-based data sharing and AI-powered credit analysis to improve access to formal finance for underserved communities.

A system that is built around the JAM Trinity – Jan Dhan bank accounts, Aadhaar digital identity and mobile connectivity – alongside platforms such as UPI and Direct Benefit Transfer. By March 2026, Jan Dhan accounts had reached 58.16 crore, while UPI processed more than 2,264 crore transactions worth ₹29.53 lakh crore in a single month.

The infrastructure is generating large volumes of financial and behavioural data that AI systems can use for risk assessment, fraud detection and personalised financial services.

AI-driven lending models are becoming increasingly important for MSMEs, informal workers and first-time borrowers who often lack conventional credit histories. Through the Unified Lending Interface, lenders can analyse alternative datasets including GST records, utility payments, land records and digital transaction histories instead of relying only on traditional credit scores.

Local authorities estimate that AI-enabled credit systems could help address a credit gap worth between $130 billion and $170 billion.

India is also strengthening multilingual and regulatory support for AI finance systems. The Reserve Bank of India (RBI) and Digital India BHASHINI Division are developing ‘Banking BHASHINI’, a specialised language AI model designed to support banking terminology and financial services across all 22 scheduled Indian languages. The initiative aims to reduce literacy and language barriers while expanding nationwide access to digital banking.

Additional initiatives include the RBI Regulatory Sandbox for testing fintech innovations, MuleHunter.AI for detecting suspicious mule accounts linked to cybercrime, and the proposed Digital ShramSetu mission focused on informal workers and AI-enabled economic inclusion.

Authorities argue that combining AI with interoperable digital infrastructure could help India build a more resilient and scalable financial ecosystem as part of its broader Viksit Bharat 2047 strategy.

Why does it matter?

The expansion of AI-powered financial inclusion is crucial because it demonstrates how large-scale digital public infrastructure can reshape access to banking, credit and public services for hundreds of millions of people. Additionally, it highlights how AI can move beyond consumer applications into core economic infrastructure, influencing financial resilience, productivity, fraud prevention and long-term digital development.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!  

UN calls for AI-driven transformation of future cities

UN organisations and urban experts have called on governments, city leaders, and the private sector to accelerate the use of AI and digital technologies to shape the future of urban life. The appeal was made during the 3rd UN Virtual Worlds Day held in Geneva.

With 70 percent of the global population expected to live in urban areas by 2050, discussions focused on the emergence of an ‘AI-enabled citiverse’ combining AI, digital twins and spatial intelligence to improve planning, infrastructure management and quality of life in cities.

Participants outlined five strategic priorities, including strengthening inclusive AI systems, improving data-driven decision-making, and ensuring responsible economic and social development. Emphasis was also placed on global cooperation and the need for common standards to guide digital urban transformation.

The conference also highlighted key risks, including governance gaps, trust and safety concerns, and widening digital divides. A joint briefing warned that the benefits of AI-driven urban systems must be distributed fairly, including to developing economies and underserved communities.

Why does it matter? 

The integration of AI into urban systems signals a structural shift in how cities are designed, managed and experienced. As urbanisation accelerates globally, AI-enabled infrastructure could significantly improve efficiency, resilience and sustainability, but also risks deepening inequality if governance and access remain uneven across regions.

United Nations organisations and urban experts have called on governments, city leaders and the private sector to accelerate the use of AI and digital technologies in shaping the future of urban life. The appeal was made during the 3rd UN Virtual Worlds Day held in Geneva.

With 70 percent of the global population expected to live in urban areas by 2050, discussions focused on the emergence of an ‘AI-enabled citiverse’ combining AI, digital twins and spatial intelligence to improve planning, infrastructure management and quality of life in cities.

Participants outlined five strategic priorities, including strengthening inclusive AI systems, improving data-driven decision-making, and ensuring responsible economic and social development. Emphasis was also placed on global cooperation and the need for common standards to guide digital urban transformation.

The conference also highlighted key risks such as governance gaps, trust and safety concerns, and widening digital divides. A joint briefing warned that the benefits of AI-driven urban systems must be distributed fairly, including to developing economies and underserved communities.

Why does it matter? 

The integration of AI into urban systems signals a structural shift in how cities are designed, managed and experienced. As urbanisation accelerates globally, AI-enabled infrastructure could significantly improve efficiency, resilience and sustainability, but also risks deepening inequality if governance and access remain uneven across regions.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our chatbot!  

Meta unveils Incognito Chat for private AI conversations

Meta has introduced Incognito Chat with Meta AI on WhatsApp and the Meta AI app, adding a privacy-focused option for users interacting with AI.

The company said the feature is intended for sensitive or personal questions, such as health issues, loan details or career advice. Incognito Chat is built on WhatsApp’s Private Processing technology and is designed to process conversations in a secure environment that Meta says it cannot access.

Messages in Incognito Chat are not saved and disappear by default. Meta says the feature creates temporary AI conversations that are visible only to the user, reducing concerns about long-term retention and access to sensitive prompts.

Meta also contrasted the feature with other incognito-style AI tools, saying those services may still be able to see user prompts and generated responses. The company claims its approach prevents anyone, including Meta, from reading the content exchanged during these conversations.

The company said Incognito Chat will roll out on WhatsApp and the Meta AI app over the coming months. It also plans to introduce Side Chat on WhatsApp, which will provide AI assistance linked to ongoing conversations while using the same Private Processing infrastructure.

Why does it matter?

As AI assistants become embedded in messaging, work, finance and health-related conversations, users are likely to share increasingly sensitive information with chatbots. Meta’s Incognito Chat points to growing competition in privacy-preserving AI, where companies are trying to show that AI interactions can be useful without exposing prompts, responses, or personal context to long-term storage or platform access.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our chatbot!  

Taiwan urges stronger defences amid AI-driven cyber threats

Taiwan’s Administration for Cyber Security has warned that emerging AI models are lowering the cost and increasing the scale of cyberattacks, urging companies and government agencies to strengthen basic cyber resilience.

The agency said advanced AI models, including Anthropic’s Claude Mythos and OpenAI’s GPT-5.5, are showing stronger capabilities in vulnerability discovery and offensive cyber techniques. It said such developments could help attackers identify weaknesses faster and turn vulnerabilities into practical attack tools more efficiently.

According to the agency, recent international cybersecurity assessments suggest Claude Mythos Preview has identified thousands of high-severity vulnerabilities across major operating systems and web browsers. At the same time, GPT-5.5 could increase the efficiency and scale of existing attack methods.

Taiwan outlined three responses to the emerging threat. The administration said it would monitor defensive tools and international experience related to AI-enabled cyber operations, convene government, industry and academic decision-makers to discuss national-level response strategies, and strengthen support for small and medium-sized enterprises through TWCERT/CC.

The agency also urged organisations to return to cybersecurity basics, including vulnerability management, offline and recoverable backups, business continuity planning, least-privilege access, multi-factor authentication, passkeys based on FIDO2 standards, and the disabling of unnecessary external services and test interfaces.

Taiwan’s cyber agency said AI is changing the speed and cost of attacks, but not the core principles of cybersecurity. It said organisations should shift from focusing only on preventing breaches towards improving resilience, recovery time and damage control.

Why does it matter?

The warning shows how governments are beginning to treat AI-enabled vulnerability discovery and exploitation as a practical cybersecurity risk, not a future scenario. As AI reduces the time and expertise needed to identify and exploit weaknesses, organisations may need to place greater emphasis on resilience, rapid recovery, access controls and continuous vulnerability management, especially where smaller businesses and public bodies lack advanced cyber capabilities.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our chatbot!  

Worldwide AI adoption surges, new report shows

Ireland remains one of the world’s leading markets for AI adoption, with 48.4% of its working-age population using AI tools, according to Microsoft’s Global AI Diffusion Report for the first quarter of 2026.

Microsoft said Ireland recorded a quarterly increase of 3.8 percentage points, placing it fourth globally and close to surpassing the 50% milestone. If current trends continue, Ireland could overtake Norway, which currently ranks third for AI adoption.

Globally, AI usage increased from 16.3% to 17.8% of the working-age population during the first quarter of 2026. Adoption remains uneven, with 26 economies now exceeding 30% usage, while the United Arab Emirates leads globally at 70.1%.

Regional trends show strong momentum in Asia, driven in part by improved AI capabilities for Asian languages. Microsoft said South Korea, Thailand and Japan recorded some of the greatest movement during the quarter.

At the same time, the gap between the Global North and Global South widened, with AI usage reaching 27.5% in developed regions compared with 15.4% elsewhere. Microsoft said it measures AI diffusion as the share of people aged 15 to 64 who used a generative AI product during the reported period.

Advances in AI-assisted coding also affected software development. Microsoft said global git pushes increased 78% year on year, while US software developer employment reached about 2.2 million in 2025 and was about 4% higher in March 2026 than in March 2025. The report cautions that it is still too early to determine the full labour-market impact of AI-assisted coding.

Why does it matter?

The report shows how quickly generative AI is becoming part of everyday work and digital activity, but also how uneven that adoption remains across countries and regions. If high-adoption economies continue to move faster, AI could widen existing digital and economic divides, especially where infrastructure, language support, skills and access remain weaker.

The findings also show why governments and businesses are under pressure to adapt workforce training, regulation and digital infrastructure as AI use spreads. Rising adoption may support productivity gains, but it also raises questions about who benefits, which regions fall behind and how labour markets adjust as AI tools become more embedded in software development and services.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our chatbot!