UN Global Mechanism on ICT security advances work, shifts focus to implementation

The United Nations Global Mechanism on developments in the field of ICTs in the context of international security and advancing responsible state behaviour in the use of ICTs held its second meeting, during which member states conducted a general exchange of views on the work of the newly established permanent forum.

The session, chaired by Ambassador Egriselda López of El Salvador, focused on agenda item four, during which 61 member states and three intergovernmental organisations delivered statements on priorities for the mechanism.

Delegations emphasised the transition from the previous Open-Ended Working Group (OEWG) to the new permanent mechanism, highlighting the need to build on existing agreements and move towards practical implementation. Several speakers stressed that the mechanism should focus on translating the agreed framework for responsible state behaviour in cyberspace into concrete outcomes, rather than negotiating new commitments.

Across statements, member states reaffirmed the five-pillar framework covering threats, norms and principles, the application of international law, confidence-building measures, and capacity development.

Capacity development was highlighted as a cross-cutting priority, particularly by developing countries and Small Island Developing States, which pointed to the need for demand-driven and sustainable approaches to strengthen cybersecurity capabilities. Delegations also noted challenges, including ransomware, threats to critical infrastructure, and the impact of emerging technologies such as AI.

Member states welcomed the establishment of two dedicated thematic groups, one addressing substantive ICT security challenges and another focused on capacity development, as a means to support more detailed discussions and implementation.

Several delegations reaffirmed that international law, including the UN Charter, applies to cyberspace and called for further work on its practical implementation. Many also emphasised the importance of maintaining a consensus-based, intergovernmental process, while enabling contributions from stakeholders, including the private sector, academia, and civil society, in line with agreed modalities.

The meeting forms part of the initial phase of the Global Mechanism’s work, following its establishment as a permanent UN forum on ICT security. The mechanism is expected to convene its first substantive plenary session in July 2026, alongside dedicated thematic group meetings scheduled for December 2026.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot

UNESCO initiative drives new digital platform governance frameworks in South Asia

South Asia is strengthening digital platform governance through a rights-based approach shaped by regional cooperation and international guidance.

A workshop led by UNESCO brought together policymakers, civil society and academics to align platform regulation with principles of freedom of expression and access to information.

The discussions focused on addressing governance gaps linked to misinformation, platform accountability and transparency. Participants examined national experiences and identified shared regulatory challenges, emphasising the need for coordinated regional responses instead of fragmented national measures.

An initiative that also validated regional toolkits designed for policymakers and civil society, translating global principles into practical guidance. These tools aim to support the implementation of governance frameworks that reflect local contexts while upholding international human rights standards.

The process builds on UNESCO’s Internet for Trust guidelines, reinforcing a human-centred model of digital governance. Continued collaboration across South Asia is expected to strengthen regulatory capacity and ensure that digital platforms operate with greater accountability and public trust.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!  

EU funding platform drives competitiveness in strategic technologies

The European Commission has highlighted the growing impact of the Strategic Technologies for Europe Platform (STEP), which has mobilised €29 billion to strengthen innovation and competitiveness across key sectors.

An initiative that supports the development and manufacturing of critical technologies, reinforcing the Union’s strategic autonomy.

Funding has been directed toward digital and deep-tech innovation, clean technologies, biotechnology and defence, combining resources from EU programmes and Member States.

Such a coordinated approach reflects efforts to reduce strategic dependencies instead of relying on fragmented investment strategies.

The platform has also improved access to funding, with hundreds of calls and projects supported across all Member States. Tools such as the STEP Seal and the planned AI-based access systems aim to simplify processes and attract further public and private investment into high-potential projects.

Looking ahead, the initiative is shaping broader reforms, including proposals for a European Competitiveness Fund. These developments signal a continued focus on streamlining funding mechanisms while supporting innovation ecosystems and long-term economic growth across Europe.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!  

New quantum threat could weaken cryptocurrency encryption systems

A new warning from Google says advances in quantum computing could weaken widely used cryptographic systems protecting cryptocurrencies and digital infrastructure. A new whitepaper suggests future quantum machines may need fewer resources than previously estimated to break elliptic curve cryptography.

The research focuses on the elliptic curve discrete logarithm problem, which underpins much of today’s blockchain security. Findings suggest quantum algorithms like Shor’s could run with fewer qubits and gates, increasing concerns about cryptographic resilience.

To address the risk, the paper recommends a transition to post-quantum cryptography, which is designed to resist quantum attacks. It also outlines short-term blockchain measures, including avoiding reuse of vulnerable wallet addresses and preparing digital asset migration strategies.

Google also introduced a responsible disclosure approach using zero-knowledge proofs to communicate vulnerabilities without exposing exploitable details.

The company says this balances transparency and security, supporting coordinated efforts across crypto and research communities to prepare for quantum threats.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot

Cloudflare adds LLM layer to client-side security detection pipeline

Cloudflare has announced two changes to its client-side security offering, making Client-Side Security Advanced available to self-serve customers and offering domain-based threat intelligence at no extra cost to all users on the free Client-Side Security bundle. The update is focused on browser-based attacks that can steal data via malicious scripts without visibly disrupting a website’s normal operation.

Cloudflare says its client-side security system assesses 3.5 billion scripts per day and monitors an average of 2,200 scripts per enterprise zone. According to the company, the product relies on browser reporting, including Content Security Policy signals, rather than scanners or application instrumentation, and requires only that traffic be proxied through Cloudflare.

A central part of the announcement is a new detection pipeline combining a Graph Neural Network (GNN) with a Large Language Model (LLM). Cloudflare says the GNN analyses the Abstract Syntax Tree of JavaScript code to identify malicious intent even when scripts are minified or obfuscated. Scripts flagged as suspicious are then passed to an open-source LLM running on Workers AI for a second-stage semantic assessment intended to reduce false positives.

Cloudflare says the GNN is tuned for high recall to identify novel and zero-day threats, but that false alarms remain a challenge at internet scale. Internal evaluation results cited by the company show that the secondary LLM layer reduced false positives in the JS Integrity threat category by nearly three times across the total analysed traffic, lowering the rate from about 0.3% to about 0.1%. On unique scripts, Cloudflare says the false-positive rate fell from about 1.39% to 0.007%.

The company also describes a recent case involving a heavily obfuscated malicious script named core.js. According to Cloudflare, the payload targeted Xiaomi OpenWrt-based home routers, altered DNS settings, and attempted to change admin passwords. Cloudflare says the script was injected through compromised browser extensions rather than by directly compromising a website, and adds that its GNN detected the malicious structure while the LLM confirmed the intent.

Cloudflare argues that the two-stage design provides structural detection via the GNN and broader semantic filtering via the LLM, enabling the company to lower the GNN decision threshold without sharply increasing alert volume. Every script flagged by the GNN is also logged to Cloudflare R2 for later auditing, which the company says helps it review cases where the LLM overrode the initial verdict.

Domain-based threat intelligence is now being made available to all Client-Side Security customers, including those not using the Advanced tier. Cloudflare says the move is partly a response to attacks seen in 2025 against smaller online shops, especially on Magento, where client-side compromises continued for days or weeks after public disclosure. By extending domain-based signals more broadly, the company says site owners can more quickly identify malicious JavaScript or suspicious connections and investigate possible compromises.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

EPO strengthens industry collaboration on European patent innovation

The European Patent Office (EPO) has reinforced cooperation with industry stakeholders through discussions with the German Association of Industry IP Experts, focusing on strengthening the European patent system and supporting innovation.

A meeting that brought together representatives from major industrial actors to align priorities and explore future collaboration.

Discussions between the EPO and the stakeholders centred on enhancing technology transfer, empowering startups and fostering economic growth across Europe.

Participants emphasised the importance of inclusive engagement among patent system users instead of fragmented approaches, ensuring that innovation strategies reflect both industrial and societal needs.

The Unitary Patent system was highlighted as gaining traction, particularly among smaller entities such as SMEs, individual inventors and research organisations. Such a trend reflects broader efforts to improve accessibility and scalability within the European innovation ecosystem.

AI also featured prominently, with both sides recognising its growing role in improving efficiency and quality in patent processes.

A human-centric approach remains essential, ensuring that AI deployment supports responsible innovation while maintaining high standards in patent examination and services.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!  

Italy fines major bank over data protection failures

The Italian Data Protection Authority has imposed a €31.8 million fine on Intesa Sanpaolo following serious shortcomings in its handling of personal data.

The case stems from unauthorised access by an employee to thousands of customer accounts, raising concerns about internal oversight and data protection safeguards.

Investigations revealed that monitoring systems failed to detect repeated unjustified access to sensitive financial information over an extended period. The breach also involved high-risk individuals, highlighting weaknesses in risk-based controls instead of robust, targeted protection measures.

Authorities in Italy identified violations of core data protection principles, including integrity, confidentiality and accountability. Additional concerns arose from delays in notifying both regulators and affected individuals, limiting the ability to respond effectively to the incident.

The case of Intesa Sanpaolo underscores increasing regulatory scrutiny of data governance practices in the financial sector. Strengthening internal controls and ensuring timely breach reporting remain essential for maintaining trust and compliance in data-driven banking environments.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!  

UK authorities have fined an Apple subsidiary over a sanctions breach

The UK has fined Apple Inc. subsidiary Apple Distribution International £390,000 for breaching sanctions linked to Russia. The penalty relates to payments routed through a UK bank to a Russian streaming platform.

The payments, totalling more than £635,000, were made to Okko from a UK-based account. The subsidiary, responsible for Apple product sales across Europe and the Middle East, instructed the transfers despite the platform’s ownership links to sanctioned entities.

The Office of Financial Sanctions Implementation found the funds were linked to Sberbank and a company later sanctioned after the 2022 Ukraine invasion. Payments were made shortly after those restrictions came into force.

Regulators said the firm had voluntarily disclosed the transactions and had not been aware of the sanctions breach at the time. Apple stated it follows all applicable laws and has strengthened its compliance procedures following the incident.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!

FTC accuses OkCupid of sharing user data contrary to privacy promises

The US Federal Trade Commission has taken action against OkCupid and Match Group Americas over allegations that the dating app shared users’ personal information, including photos and location data, with an unrelated third party despite privacy promises saying such sharing would not occur without notice or an opportunity to opt out.

According to the FTC’s complaint, OkCupid gave the third party access to personal data from millions of users even though the recipient was not a service provider, business partner, or affiliate within the company’s corporate family. The agency says consumers were not informed and were not given a chance to opt out.

The complaint says the third party sought large OkCupid datasets because OkCupid’s founders were financial investors in that company, despite there being no business relationship with the app. The FTC alleges that OkCupid provided access to nearly 3 million user photos, along with location and other information, without formal or contractual limits on how the data could be used.

Christopher Mufarrige, Director of the FTC’s Bureau of Consumer Protection, said: ‘The FTC enforces the privacy promises that companies make. We will investigate, and where appropriate, take action against companies that promise to safeguard your data but fail to follow through—even if that means we have to enforce our Civil Investigative Demands in court.’

The FTC also alleges that, since September 2014, Match and OkCupid have taken extensive steps to conceal and deny that the apps shared users’ personal information with the data recipient, including conduct the agency says obstructed its investigation. One example cited in the complaint is that, after a news report revealed the third party had obtained large OkCupid datasets, the company told the media and users that it was not involved with that third party.

Under the proposed settlement, OkCupid and Match would be permanently prohibited from misrepresenting how they collect, maintain, use, disclose, delete, or protect personal information, including photos, demographic data, and geolocation data. Restrictions would also cover how they describe the purposes of data collection and disclosure, as well as how they present privacy controls and consumer choices under state privacy laws.

The Commission vote authorising staff to file the complaint and stipulating the final order was 2-0. The FTC filed both in the US District Court for the Northern District of Texas, Dallas Division. The agency notes that a complaint reflects its view that it has ‘reason to believe’ the law has been or is about to be violated, while stipulated final orders carry the force of law only if approved and signed by the district court judge.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

UK-backed SPOQC mission launches to test space-based quantum communications

A UK-led research mission aimed at advancing space-based quantum communications has launched aboard a SpaceX Transporter-16 rocket from Vandenberg Space Force Base in California. The Satellite Platform for Optical Quantum Communications, or SPOQC, was developed under the Integrated Quantum Networks (IQN) Hub led by Heriot-Watt University and was launched on 30 March 2026.

The mission builds on research and development carried out first through the Quantum Communications Hub and later through the IQN Hub, both funded by the Engineering and Physical Sciences Research Council. Five UK research institutions are involved in the collaboration, which is intended to strengthen UK capabilities in space-based quantum communications as governments and researchers prepare for the cybersecurity implications of more powerful quantum computing systems.

SPOQC is now in the final stages of commissioning before it begins transmitting quantum signals to receivers at the Hub Optical Ground Station at Heriot-Watt University in Edinburgh. The CubeSat is operating in a low Earth, Sun-synchronous orbit and passes over the UK about twice a day, with most measurements expected to take place during night-time passes, when experimental conditions are more favourable.

The mission’s wider policy relevance lies in its connection to the UK’s National Quantum Strategy, which views quantum technologies as important to national resilience, digital infrastructure, and long-term competitiveness. The project presents satellite-based systems as the most practical route towards resilient international quantum communication, since terrestrial fibre links face distance-related limitations that can degrade quantum signals over time.

A distinctive feature of the mission is its dual quantum source payload. One source uses discrete quantum signals at the single-photon level and was developed by the University of Bristol team, while the other uses continuous-variable signals and was developed by researchers at the University of York. Both connect to dedicated receivers at the optical ground station, allowing researchers to compare two established but technically different communication methods under varying atmospheric and orbital conditions.

‘The SPOQC mission is the culmination of outstanding collaborations between leading UK Universities, STFC RAL Space, and external industry partners. It offers a world-first platform to critically compare different quantum communication modalities, including the first use of continuous variable approaches from space. Through the IQN Hub, the SPOQC mission is a vital enabler towards truly global quantum communication via integration into terrestrial UK networks.’, said Professor Gerald Buller, Director of the IQN Hub.

The collaboration brings together the Universities of Bristol, Heriot-Watt, Strathclyde and York, alongside the Science and Technology Facilities Council’s RAL Space. STFC RAL Space contributed engineering, systems integration and mission support, while Heriot-Watt is operating the optical ground station. ISISPACE provided the satellite and technical support.

Researchers say the mission will also test whether quantum technologies can be scaled down to a 12U CubeSat, roughly the size of a microwave oven, as a proof of concept for future compact and lower-cost satellite quantum networks. SPOQC follows the November 2025 launch of SpeQtre, a UK-Singapore collaboration led by STFC RAL Space and SpeQtral, making it the second quantum mission supported by UK research to launch within six months.

Full quantum communication experiments are expected to begin in the second half of 2026 once commissioning is complete. Professor Tim Spiller from the University of York said: ‘As Director of the preceding Quantum Communications Hub, it is very pleasing to see six years of R&D by that Hub team to develop SPOQC and HOGS finally be rewarded with the launch of SPOQC. However, this will add a crucial link to the UK’s expanding quantum networking capability. I look forward to the first quantum demonstrations from SPOQC and HOGS later this year.’

Andy Vick, Disruptive Technology Programme Lead at STFC RAL Space, said: ‘The launch of two quantum CubeSats in close succession highlights the UK’s growing leadership in quantum technology. While both missions share a common satellite platform, SPOQC has united new partners to address new challenges. The RAL Space team is proud to have contributed from the outset, working closely with the Quantum Communications Hub, whose initial work laid strong foundations for the mission, and now supporting its delivery under the leadership of the IQN Hub. SPOQC is a big step for all the teams involved, one that we hope will pave the way for the UK’s national quantum network mission.’

Dr Kedar Pandya, Executive Director of EPSRC’s Strategy Directorate, said: ‘The SPOQC mission is a powerful example of how UK research leadership is shaping the future of secure global communications. By uniting world-class expertise across our quantum research hubs, we’re demonstrating not only scientific excellence but real technological ambition. This launch marks a major step toward quantum-secure networks that will help safeguard the UK’s digital infrastructure for decades to come.’

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!