EPO highlights Europe’s growing quantum innovation ecosystem

The European Patent Office (EPO) highlighted Europe’s growing quantum and AI innovation ecosystem during Servus Scale Up 2026 in Munich, pointing to rapid growth in quantum patenting and new initiatives to help startups commercialise deep-tech innovation.

The event brought together around 200 French and Bavarian startups, investors, researchers, technology transfer experts and policymakers to strengthen cross-border cooperation and support deep-tech entrepreneurship in strategically important technologies.

EPO Vice President Christoph Ernst said quantum patenting in Europe has increased fivefold over the past decade. According to recent EPO findings, annual growth has averaged around 20%, significantly outpacing overall patent growth.

Europe’s share of international patent families in quantum technologies also increased from 19% to 25%, reinforcing the continent’s position in one of the world’s fastest-growing technology fields.

The EPO also showcased initiatives designed to support innovators and investors. Its Deep Tech Finder now includes nearly 150 European quantum startups.

Other initiatives, including the EPO Observatory on Patents and Technology, the joint OECD study on quantum technologies, the Quantum Technology Platform and the recently launched EPO Data Desk, provide patent intelligence, market insights and analytical tools to help identify emerging opportunities and support investment decisions.

The EPO noted that although Europe has a strong research and innovation base in quantum technologies, access to funding remains more limited than in the United States. By combining patent data with market intelligence, the Office aims to help startups scale, attract investment and strengthen Europe’s long-term competitiveness in quantum technologies and AI.

Why does it matter?

Quantum technologies are expected to play an increasingly important role in fields ranging from cybersecurity and communications to healthcare and advanced computing. Strong patent activity suggests Europe remains competitive in research, but commercial success will also depend on access to investment and the ability to scale innovative companies.

By combining patent intelligence with tools for investors and startups, the EPO is seeking to strengthen Europe’s deep-tech ecosystem and improve the commercialisation of emerging technologies. This reflects a broader European effort to translate scientific leadership into long-term industrial competitiveness.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

South Korea prioritises AI and semiconductor investment in the 2027 budget

South Korea plans to introduce a record national budget exceeding KRW 800 trillion (around €500 billion) in 2027, with semiconductors, AI and youth employment at the centre of its investment strategy.

Announced during the National Fiscal Strategy Meeting, the proposed budget would increase by more than 10% compared with 2026, reflecting the government’s focus on strengthening industrial competitiveness, technological leadership and long-term economic growth.

A significant share of the funding will support three flagship initiatives focused on semiconductors, AI data centres and physical AI technologies.

The government also plans to accelerate the development of Yongin and the Honam region as major semiconductor manufacturing hubs through administrative measures including fast-track licensing and exemptions from preliminary feasibility studies for strategic projects.

Beyond industrial policy, the budget includes measures aimed at supporting citizens directly. A new Future Response Fund will finance the training of 200,000 young professionals, help create around 300,000 jobs and improve housing stability.

South Korea also plans to expand employment insurance and workers’ compensation coverage for platform workers while establishing a new K-Labour Council to strengthen labour protections.

To address fiscal sustainability, the government announced a comprehensive review of public spending aimed at generating around KRW 50 trillion in efficiency savings, described as the largest restructuring of government expenditure in the country’s history.

According to the government, the combination of strategic investment and spending reforms is intended to promote innovation while maintaining long-term fiscal sustainability.

Why does it matter?

The budget demonstrates how industrial policy is becoming a central tool for strengthening technological competitiveness. By prioritising semiconductors, AI infrastructure and advanced manufacturing, South Korea is seeking to reinforce its position in sectors that are increasingly viewed as critical to economic growth and national security.

The package also shows that governments are increasingly pairing technology investment with workforce development and labour reforms. Building AI and semiconductor capacity will require not only infrastructure and capital but also a skilled workforce capable of supporting long-term innovation.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!  

European Parliament committee backs stronger online protections for children

The European Parliament’s Committee on Culture and Education has adopted a report calling for stronger enforcement of existing EU digital legislation to create a safer online environment, particularly for children and young people.

MEPs argue that platforms should be held more accountable for the impact of their services through stronger safeguards, greater algorithmic transparency and stricter protections against addictive digital design.

The European Parliament report calls for a ban on the most harmful addictive platform features and supports introducing a dedicated ‘youth mode’ that would disable targeted advertising and reduce minors’ exposure to addictive design practices.

MEPs also propose greater transparency around recommender systems so users can better understand why content is promoted, restricted or removed. They further suggest introducing personal liability for serious and persistent failures to comply with child protection obligations.

Beyond platform design, the report recommends an EU-wide code of conduct for influencers and stronger safeguards against practices such as kidfluencing and sharenting, where children are used in commercial content or exposed excessively online.

MEPs also call for mandatory ethical standards for AI companions, greater transparency around AI model training, measures against AI-generated impersonation scams, stronger protection against synthetic child sexual abuse material, and systematic monitoring of children’s digital habits across the EU.

The committee said these measures should complement existing legislation, including the Digital Services Act, AI Act, GDPR and Audiovisual Media Services Directive, creating a more coherent EU framework for protecting minors online. The report will now be submitted to Parliament’s plenary session in September 2026.

Why does it matter?

The report signals growing political support for strengthening children’s online safety by making platforms more accountable for the design and operation of their services. Rather than relying solely on new legislation, MEPs are urging stronger enforcement of existing EU rules alongside targeted measures addressing addictive design, recommender systems and AI-powered services.

Although the report is not legally binding, it could influence future EU legislation and enforcement priorities by reinforcing the shift towards safety-by-design, greater transparency and stronger protections for minors across digital platforms.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

Digital Omnibus on AI: The EU’s AI Act simplification and new AI Office powers

On 29 June 2026, the Council of the European Union gave its final green light to the Digital Omnibus on AI, a package of amendments that eases and delays parts of the EU AI Act, completing a legislative procedure that began when the European Commission published its proposal on 19 November 2025. It amends the EU AI Act, together with the EU’s civil aviation rules and machinery regulation. According to the European Parliament’s Legislative Observatory, the final act was signed on 8 July 2026, and the Digital Omnibus is now awaiting publication in the Official Journal of the European Union, a necessary step before it can enter into force, ahead of the original 2 August 2026 deadline for several high-risk AI obligations.

Much of the public attention on the Digital Omnibus has focused on the delay to high-risk AI rules and the new ban on AI-generated intimate imagery. The full legal text of the amending regulation also reorganises, in detail, responsibility for supervising AI systems that operate within very large online platforms regulated under the Digital Services Act, and amends several other elements of the way the AI Act is enforced, points that have drawn less attention so far.

The Council describes this regulation as part of a wider legislative package known as Omnibus VII, one of several ‘omnibus’ simplification efforts the Commission has proposed across different policy areas. It was also listed in the Parliament and the Council in their Joint Declaration on EU legislative priorities for 2026, signalling the priority both institutions attached to its rapid finalisation.

Why the Commission proposed the amendments

 Architecture, Building, Office Building, City, Urban, High Rise, Flag

According to the recitals of the Digital Omnibus on AI, the amendments respond to problems identified once parts of the AI Act began to apply in August 2024. The recitals point to delays in the preparation of harmonised technical standards needed by providers of high-risk AI systems in order to demonstrate compliance, as well as delays by several member states in setting up the national authorities and conformity assessment bodies responsible for checking that compliance. Taken together, the recitals state that these delays created a heavier compliance burden than originally expected.

The Commission’s proposal also links the amendments to a broader competitiveness rationale, describing them as part of a wider effort by EU leaders to reduce administrative burdens on business, following the recommendations of the Draghi and Letta reports on European competitiveness. Industry associations also lobbied for the amendments throughout 2025.

The trade group DIGITALEUROPE told policymakers that compliance with the AI Act could cost companies in the region of EUR 3.3 billion a year across the EU, and that a company of around 50 employees developing an AI-based product could face initial compliance costs of between EUR 320,000 and EUR 600,000.

How the Digital Omnibus was negotiated

 People, Person, Audience, Crowd, Indoors, Lecture, Room, Seminar, Adult, Male, Man, Female, Woman, Head

The AI-specific amendments were separated from the wider Digital Omnibus package, which also proposes amendments to the GDPR, the ePrivacy Directive, the Data Act, and the NIS2 Directive on cybersecurity, due to the approaching deadline for high-risk AI obligations. According to the Legislative Observatory’s procedure record, Parliament’s Internal Market Committee voted on the proposed regulation on 18 March 2026, and the Parliament adopted its first-reading position on 26 March 2026.

The Parliament and the Council negotiators reached a political agreement on the Digital Omnibus early on 7 May 2026. The Council’s Permanent Representatives Committee confirmed the agreement in a letter dated 13 May 2026. The Parliament formally adopted the Digital Omnibus on 16 June 2026, the Council gave its final approval on 29 June 2026, and the final act was signed on 8 July 2026.

The regulation’s preamble records that the European Central Bank was consulted and issued a formal opinion, published in the Official Journal in April 2026, as required under EU legislation for measures affecting payments and financial infrastructure. The European Economic and Social Committee delivered its opinion on 18 March 2026, and the Committee of the Regions gave its opinion on 7 May 2026. National parliaments, including those of Czechia, Italy, the Netherlands, Portugal, Romania, Germany, Poland and France, also submitted subsidiarity contributions during the process. The Parliament’s public transparency register separately records meetings on this regulation between the two co-rapporteurs and organisations, including Google, the AI start-up Mistral AI, the digital rights group EDRi, the privacy group noyb, and the standards and conformity body TIC Council, reflecting the range of interests, from large technology firms to civil society, that engaged with the negotiations.

New deadlines for high-risk AI obligations

Under the amended Article 113 of the AI Act, the obligations for high-risk AI systems set out in Sections 1 to 3 of Chapter III will now apply from 2 December 2027 for systems classified as high-risk under Article 6(2) and Annex III, which covers areas such as biometrics, critical infrastructure, education, employment, law enforcement, migration and border management. For systems classified as high-risk under Article 6(1) and Annex I, meaning AI systems embedded in products already covered by other EU safety legislation, such as machinery or medical devices, the new deadline is 2 August 2028. Both deadlines were originally set for 2 August 2026.

A separate provision clarifies how the AI Act’s grace period for so-called legacy systems, set out in Article 111(2), applies. Once at least one unit of a given type and model of high-risk AI system has been lawfully placed on the market before the relevant cut-off date, further units of the same type and model can continue to be placed on the market or put into service without additional certification, as long as the system’s design does not change significantly. Any significant redesign after the cut-off date triggers full compliance with the AI Act, including conformity assessment.

To help providers meet the new deadlines, the Digital Omnibus requires the Commission to request that European standardisation bodies develop technical standards aligned with existing product-safety standards, reducing duplication for companies that have to comply with both the AI Act and sectoral legislation. The Commission must also publish guidance on post-market monitoring plans by 2 September 2027, as well as guidance to help providers of Annex I high-risk systems apply the AI Act alongside sectoral rules by 1 August 2027. Watermarking obligations for AI-generated content, which allow such content to be detected and traced, benefit from a separate four-month transitional period for systems already on the market before 2 August 2026.

Changes to AI literacy and the use of sensitive data for bias correction

 Person, Security, First Aid, Fungus, Plant

A further amendment loosens the AI Act’s AI literacy obligation. Instead of requiring providers and deployers to ensure a sufficient level of AI literacy among their staff, the amended Article 4 requires them to take measures supporting the development of that literacy among staff and other people involved in the operation of their AI systems. The European Artificial Intelligence Board is tasked with adopting recommendations that set common objectives to guide how the Commission and member states support this obligation.

A new Article 4a allows providers and deployers of AI systems to process special categories of personal data, such as data revealing ethnicity or health status, for the specific purpose of detecting and correcting bias, subject to a list of privacy safeguards, including data minimisation, restrictions on transferring the data to third parties, and deletion once the bias has been corrected. The final text requires this processing to be strictly necessary, a stricter standard than the version originally proposed by the Commission. This followed a joint opinion issued by the European Data Protection Board and the European Data Protection Supervisor in January 2026, which recommended reinstating the stricter standard.

AI Office gains exclusive powers over general-purpose AI and large platforms

 Logo, Nature, Night, Outdoors, Text, Symbol

Article 75 of the AI Act, which governs the market surveillance of AI systems, has been substantially rewritten. Under the new provisions, the Commission’s AI Office becomes exclusively responsible for supervising two categories of AI systems. The first category comprises AI systems built on general-purpose AI models, where the same provider, or providers belonging to the same undertaking, developed both the underlying model and the AI system built on it. This exclusive competence carries several exceptions. It does not apply to AI systems related to products already covered by EU product-safety legislation, AI systems used as critical infrastructure, systems provided by law enforcement authorities, border management authorities or financial institutions in specific circumstances, or certain systems used in the administration of justice, all of which remain under national supervision.

The second category covers AI systems that constitute, or are integrated into, a very large online platform or a very large online search engine designated under the Digital Services Act (DSA), the EU’s rulebook for online platforms. The recitals state that empowering the Commission, through the AI Office, to act as a market surveillance authority for these systems is intended to ensure that enforcement of the AI Act and the DSA is carried out consistently, given the scale and potential societal impact of very large platforms and search engines.

For AI systems that are embedded in, or form part of, a designated very large platform or search engine, the Digital Omnibus specifies that the DSA’s own risk assessment, mitigation, and audit obligations, laid down in Articles 34, 35, and 37 of that regulation, serve as the first point of entry for assessing the AI system. This is without prejudice to the AI Office’s separate power to investigate and enforce breaches of the AI Act after the fact. The Commission services that enforce the DSA and the AI Office are required to coordinate, exchange views regularly, and take account of any fines already imposed on the same company for the same conduct, so that the combined penalties remain proportionate and do not amount to double punishment for the same infringement.

Outside this narrower platform-related category, national market surveillance authorities retain a role. Where a national authority has well-founded reasons to suspect that a provider or deployer of an AI system under the AI Office’s exclusive competence has breached the AI Act, it may ask the AI Office, through a designated national contact point, to investigate. The AI Office must tell that authority within four months whether it intends to act, and keep it informed of major developments and the eventual outcome.

The recitals acknowledge that taking on this expanded role will require the AI Office to be adequately staffed and resourced. Whether the Commission allocates sufficient capacity for the AI Office to supervise both general-purpose AI models and large platforms is an operational question that will only become clear as implementation proceeds, rather than one resolved by the legislation itself.

New ban on AI-generated intimate imagery and child sexual abuse material

image

The Digital Omnibus amends Article 5 of the AI Act, which lists AI practices that are prohibited outright. It adds a prohibition against placing on the market, putting into service, or using AI systems that generate or manipulate realistic images, video or audio of an identifiable person’s intimate parts, or of that person engaged in sexually explicit activity, without that person’s free, specific, informed and unambiguous consent. It adds a parallel prohibition covering AI systems that generate or manipulate child sexual abuse material, subject to a narrow exception for activities that are lawful under national law, such as material generated by law enforcement authorities for the purposes of criminal investigation.

For providers, the prohibition applies in two situations: where generating or manipulating such material is the system’s intended purpose, or where that outcome is a reasonably foreseeable and reproducible result of the system’s design and the provider has not put in place reasonable and adequate safeguards, such as content filtering or abuse-detection mechanisms, to prevent it. For deployers, the prohibition applies only where the AI system is actually used for that purpose, meaning the ordinary use of a lawful system for unrelated purposes is not covered, nor is accidental generation of such content.

The prohibited material is defined narrowly. It covers realistic depictions, meaning a person’s face, voice or body shown in a credible, real-life manner, and specifically named intimate parts or depictions of sexually explicit activity. Cartoonish or physically impossible depictions fall outside the prohibition, as does content generated with the depicted person’s consent, non-realistic artistic nude work that does not depict an identifiable person, and legitimate medical applications such as anatomical simulations. Simple enhancements to existing images, such as adjusting brightness or adding a caption, are not treated as prohibited manipulation unless they increase the level of nudity or explicitness shown. Companies have to ensure that their systems comply with these rules by 2 December 2026.

Other simplification measures

The Digital Omnibus extends several compliance simplifications that previously applied only to small and medium-sized enterprises to a new category of small mid-cap enterprises, companies that have outgrown the SME definition but remain much smaller than large corporations. It also gives all SMEs, including start-ups, the option to comply with parts of the AI Act’s quality management system requirements in a simplified way, an option previously limited to microenterprises.

The deadline for each member state to have at least one operational national AI regulatory sandbox, a controlled environment in which providers can test AI systems under regulatory supervision, has been extended to 2 August 2027. The same provisions allow the AI Office itself to set up an EU-level sandbox for AI systems that fall under its exclusive competence, with priority access for SMEs, start-ups and small mid-cap enterprises, operating alongside, and not instead of, national sandboxes.

A further change moves the EU machinery regulation from one section of the AI Act’s product-safety annex to another, shifting AI-enabled machinery towards a more sector-specific approach. Under the new arrangement, the Commission must adopt delegated acts by 2 August 2028 incorporating the AI Act’s health and safety requirements directly into the machinery regulation, rather than requiring manufacturers to apply both frameworks in parallel.

Data protection authorities raise fundamental rights concerns

 Guitar, Musical Instrument, Accessories, Diamond, Gemstone, Jewelry

Before the political agreement was reached, the European Data Protection Board and the European Data Protection Supervisor issued a joint opinion on the Commission’s initial proposal. The two authorities said they supported the general aim of addressing implementation issues, but raised concerns that several measures could weaken human rights protections built into the AI Act. They warned that extending the legacy systems exception would allow more high-risk AI systems to reach the market without being subject to the Act’s safeguards and urged the co-legislators to keep any delay to transparency obligations as short as possible.

The two authorities also opposed the Commission’s original plan to remove the registration obligation for providers who conclude that their Annex III systems are not high-risk, arguing that this would weaken accountability and make it harder for market surveillance authorities to respond quickly to problem systems. That registration obligation was retained, in a streamlined form, in the Digital Omnibus as finally approved in June. As set out above, the authorities’ recommendation to apply a strict necessity standard to the processing of sensitive data for bias correction was also reflected in the final version of the Digital Omnibus.

Not all of the authorities’ recommendations were taken on board in the same way. Their broader concern, that postponing obligations for high-risk AI systems may leave fundamental rights protections unenforced for longer in a fast-moving technological area, remains a live point of disagreement between the co-legislators and civil society groups, as discussed further below.

Reactions: competitiveness framing meets rights concerns

 Astronomy, Outer Space

Council and Parliament negotiators presented the changes as a way to make the AI Act more workable without altering its underlying risk-based structure. Co-rapporteur Arba Kokalari said the agreement showed that politics can move just as quickly as technology, linking the simplification to the Commission’s broader competitiveness agenda. Co-rapporteur Michael McNamara said the deal combined simplification measures with new safeguards against nudification apps and AI-generated child sexual abuse material.

Civil society organisations took a more critical view of the overall direction of the package. The digital rights group Liberties argued that the final agreement weakens several safeguards contained in the original AI Act, and described the postponement of high-risk obligations as a delay to fundamental rights protections that were due to take effect in August 2026.

Industry associations generally welcomed the changes. DIGITALEUROPE, which had been among the most vocal critics of the AI Act’s original compliance costs and timeline, broadly supported the direction of the simplification package, while continuing to call for further alignment between the AI Act and other overlapping EU digital rules.

What happens next

The Digital Omnibus on AI will enter into force once it is published in the Official Journal of the European Union. Until then, the AI Act’s original provisions and timeline remain legally in force, including the prohibitions on unacceptable AI practices and the obligations applicable to general-purpose AI models that have applied since August 2025.

A separate Commission exercise, the Digital Fitness Check, is expected to examine the DSA and the wider digital rulebook directly, with a report on its findings due in the first quarter of 2027 according to legal commentary on the process. That exercise, rather than the AI Omnibus itself, is where the more direct question of simplifying the DSA is likely to be decided and where the institutional link now established between the AI Office and DSA-regulated platforms may be revisited.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

Japan reviews legal protection for AI voice imitation

Japan’s Justice Ministry has prepared a draft report on civil liability for the unauthorised use of people’s voices and images through generative AI.

The draft focuses on the protection of famous individuals, including celebrities, singers and voice actors, as AI tools make it easier to imitate real voices and appearances.

It was submitted to an expert committee on 13 July, with a final report expected as early as August.

The ministry said the report could serve as a reference in lawsuits and AI development, as Japanese courts have not yet issued clear rulings on rights related specifically to voice imitation.

One scenario examined in the draft involves AI-generated audio that could mislead the public into believing a voice actor had read obscene material online for profit.

The draft says such use could be illegal if it harms a person’s dignity, honour or peace of mind beyond a tolerable limit.

It also outlines criteria for assessing whether an AI-generated voice is similar to that of a famous person and whether it may infringe publicity rights.

At the same time, the draft suggests that parody, impersonation and artistic mimicry would generally not infringe publicity rights when they are presented as expressive acts based on resemblance.

The review comes amid growing concern in Japan over AI covers and the unauthorised use of singers’ and voice actors’ voices in synthetic performances.

Why does it matter?

Japan’s draft report shows how generative AI is forcing legal systems to revisit personality, publicity and dignity protections. Voice imitation is especially sensitive because it can affect reputation, commercial value and personal autonomy even when no copyrighted recording is copied. The Japanese approach could influence how courts and AI developers assess consent, similarity, commercial use and harm in cases involving synthetic voices, AI covers and celebrity likenesses.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our chatbot!

Nobel laureates call for urgent AI economic planning

Sixteen Nobel laureates have joined leading economists and AI researchers in calling for urgent preparation for the economic changes that more powerful AI systems could trigger.

The statement, titled We Must Act Now: A Statement on AI’s Transformation of the Economy, was released by the Stanford Digital Economy Lab.

It was organised by economists Erik Brynjolfsson, Ajay Agrawal, Anton Korinek and Tom Cunningham, and has been signed by more than 200 experts.

The statement warns that AI may become radically more powerful over the next decade, potentially driving an economic transformation larger than the Industrial Revolution but unfolding over a much shorter period.

The signatories say AI could bring major gains in living standards, but also risks, including large-scale job displacement.

They argue that economists, policymakers and technology leaders must act now to understand these impacts and prepare society for the transition.

The statement calls for incentives, guardrails and institutions that steer AI towards complementing human labour and benefiting society.

Its authors stress that the economic outcome of AI is not predetermined and will depend on choices made by governments, companies and researchers.

Why does it matter?

The statement adds weight to the debate over AI’s economic impact because it brings together Nobel laureates, economists, AI researchers and technology leaders around a common warning: societies may have far less time to adapt to AI than they had during earlier technological shifts. Its central message is not that job displacement is inevitable, but that policy choices made now will shape whether AI raises living standards broadly or concentrates economic power and leaves many workers behind.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

UK MPs call for clearer sovereign AI strategy

UK MPs have called on the government to set out a clearer strategy for building sovereign AI and other critical technology capabilities.

A new report from the Science, Innovation and Technology Committee warns that the UK may not be able to rely on allies for access to technologies essential to economic growth and national security.

The committee said the government has not clearly defined what sovereign capability means, how it should be measured or what success would look like.

MPs also criticised the absence of a coherent strategic framework for using the UK’s scientific research and institutions to support wider diplomatic and economic goals.

Instead, the report says the government has taken an opportunistic approach to international science and technology agreements, risking substituting activity for strategy.

AI is identified as a central arena for global competition and collaboration.

The committee said recent US restrictions on access to advanced AI models show how reliance on partners can leave the UK exposed if access to critical technologies changes suddenly.

MPs called on the government to define sovereign capability in key technology areas, identify critical supply-chain dependencies and use those assessments to guide investment, procurement and research funding.

The report also warned that the UK continues to struggle to turn world-class research into large domestic technology companies, with many promising firms forced to scale overseas.

It called for targeted investment, stronger public procurement and later-stage funding to help commercialise homegrown innovation in strategic sectors.

Why does it matter?

The report places sovereign AI inside a wider debate about technology dependence, national security and economic resilience. AI capability increasingly depends on access to compute, models, talent, data, infrastructure and supply chains that foreign governments or companies may control. The committee warns that the UK cannot treat partnerships as a substitute for strategy. It needs to decide which capabilities it must own, where it should collaborate and where reliable access is enough.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

OpenAI brings ChatGPT back to WhatsApp across the EEA

OpenAI has restored ChatGPT on WhatsApp across the European Economic Area (EEA), allowing users to access the chatbot through the verified 1-800-CHATGPT contact number.

Users can start chatting by messaging +1-800-242-8478 on WhatsApp without creating or linking a ChatGPT account. Availability is determined by the country code associated with the user’s WhatsApp number and may roll out gradually across the region.

ChatGPT on WhatsApp supports text conversations in multiple languages, image uploads, voice notes, and image generation. Users who link their ChatGPT accounts receive higher usage limits, though linking remains optional.

Usage limits, and OpenAI says the service is intended for users aged 13 and over. As with other ChatGPT products, the company warns that responses may contain mistakes.

The launch expands OpenAI’s presence of messaging platforms, following ChatGPT integrations with Kakao in South Korea and Viber in supported markets.

Why does it matter?

The return of ChatGPT on WhatsApp makes generative AI more accessible by bringing it into one of the world’s most widely used messaging platforms. Users can interact with the chatbot without downloading a dedicated app or creating an account, lowering barriers to adoption.

The rollout also reflects a broader trend towards embedding AI assistants within familiar communication platforms rather than requiring users to switch between separate applications. As messaging services become gateways to AI, they are increasingly evolving into everyday productivity and information tools.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

Google open-sources k8s-aibom to detect shadow AI

Google has open-sourced k8s-aibom, a lightweight Kubernetes controller designed to detect unregistered AI workloads and generate standardised inventories of the AI models, runtimes and frameworks operating inside a cluster.

The tool targets shadow AI: workloads deployed by developers without formal registration or integration with an organisation’s security and governance systems. Such deployments can evade conventional security scanners, particularly where organisations avoid privileged agents, kernel-level access or manual changes to Kubernetes workloads.

Google says k8s-aibom addresses that gap by continuously monitoring Kubernetes APIs and container environments. It detects running AI components and generates CycloneDX 1.6 Machine Learning Bills of Materials (ML-BOMs) based on what is actually executing, rather than what was intended during the build process.

The controller runs as a single unprivileged deployment in the k8s-aibom-system namespace. It does not require sidecars, eBPF modules, privileged DaemonSets or modifications to developers’ continuous integration and deployment pipelines.

The controller monitors KServe resources, deployments, StatefulSets, DaemonSets and jobs across a cluster. It then analyses container images, environment variables and command-line arguments to identify different categories of AI workloads.

Supported systems include inference runtimes such as vLLM, Triton Inference Server, TGI, and Ollama; agent frameworks including LangChain, AutoGen, and CrewAI; retrieval and vector database tools such as Milvus, Qdrant, and pgvector; and distributed training and evaluation workloads.

Once identified, the components are compiled into CycloneDX ML-BOM documents. These records can be stored as Kubernetes custom resources or exported to destinations including Google Cloud Storage and webhook endpoints.

Google also designed the tool to produce identical ML-BOM documents when given identical cluster inputs. This deterministic behaviour is intended to support GitOps workflows, allowing security and reliability teams to compare records and identify changes when AI dependencies drift.

Unlike build-time scanners, which document what organisations intended to deploy, k8s-aibom observes live clusters to identify which AI systems are actually running, how they are connected and how those findings were established.

A confidence model separates detected components into three categories. Declared assets are explicitly specified in workload configurations, inferred assets are identified through runtime patterns, and unresolved assets indicate that an AI presence was detected but the precise model, version, or weights could not be established.

Unresolved findings can therefore be prioritised for further security review, while declared and inferred classifications help auditors distinguish documented engineering intent from conclusions reached by the controller.

Google says the controller follows least-privilege principles and can export records using a dedicated identity with permission to create objects in Cloud Storage. Creation preconditions can prevent existing ML-BOM records from being silently overwritten, strengthening the historical evidence available to security and compliance teams.

Google also positions k8s-aibom as a tool for regulatory and standards compliance. Runtime inventories could help organisations gather evidence relevant to the EU AI Act, the NIST AI Risk Management Framework and ISO/IEC 42001 requirements for AI asset management.

Why does it matter?

Shadow AI has become a growing governance challenge as developers deploy AI tools outside formal security and compliance processes. Without visibility into what is actually running in production, organisations may struggle to assess risk, investigate incidents or demonstrate regulatory compliance.

By generating inventories of live AI workloads rather than relying solely on build-time records, k8s-aibom could help organisations improve AI governance while supporting audits, security operations and compliance with emerging AI standards and regulations.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

AI is beginning to carry out live cyberattacks, Check Point warns

AI is moving beyond assisting cybercriminals to carrying out operational tasks during live intrusions, according to Check Point Research’s Annual AI Security Report 2026.

The report argues that AI-enabled cyber operations are entering a new phase in which AI systems can execute parts of an attack rather than simply helping attackers write code, research targets or prepare phishing campaigns. The shift could make cyber operations faster and less dependent on continuous human oversight.

Check Point said it observed AI carrying out hands-on tasks during incidents ranging from China-linked campaigns to a criminal breach affecting several Mexican government agencies. According to the company, these capabilities are spreading beyond state-backed actors to financially motivated cybercriminals.

AI is also being used to create deployment-ready malware and offensive frameworks. One developer reportedly used an AI coding environment to build VoidLink, an 88,000-line command-and-control framework, in less than a week. Check Point noted that AI involvement may be difficult to identify once the finished tool is deployed.

According to the report, attackers increasingly favour commercial AI models over self-hosted alternatives. Rather than relying solely on jailbreak prompts, some are targeting agentic architectures by planting configuration files that AI agents continue to trust across multiple sessions.

The market supporting AI cyberattacks is also becoming more established. Check Point identified phishing-as-a-service products that embed language models with built-in restrictions bypasses, alongside conversational voice-agent services used for vishing and one-time-password theft.

The report warns that synthetic identities are weakening traditional trust signals. Convincing imitations of voices, faces, identity documents, and live video can now be combined across multiple channels, making social engineering operations more coordinated and harder to detect.

AI systems themselves are also emerging as an important attack surface. Models may struggle to distinguish instructions from the content they process, allowing attackers to manipulate AI agents through malicious files, webpages and other external data sources.

Indirect prompt injection is emerging as one of the most important threats to AI systems. Check Point said detections of longer malicious payloads increased roughly fivefold between March and May 2026, reaching close to 1% of observed prompts. Longer payloads are commonly associated with content-based and agentic attack paths.

Enterprise data leakage through generative AI also remains a growing concern. The share of prompts classified as high risk doubled from 2% to 4% over the previous year, while organisations used an average of ten AI applications each month, including tools that had not received official approval.

Exposure varied considerably by sector. Business services recorded the highest rate of high-risk generative AI prompts, at 5.91%, meaning approximately one in every 17 interactions presented a significant risk of exposing sensitive information.

The findings suggest organisations must prepare for threats from two directions: adversaries using AI to automate cyber operations and employees or AI systems exposing sensitive data through insecure adoption.

Why does it matter?

The report suggests AI is reshaping cybersecurity on both sides of the equation. Attackers are increasingly using AI to automate complex tasks, while organisations adopting AI are creating new attack surfaces and data security risks.

As AI systems become more autonomous, cybersecurity strategies will need to extend beyond traditional endpoint and network protection to include AI agents, model security, prompt injection defences, identity verification and governance over how AI is deployed across the enterprise.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!