Rome Declaration calls for human control over AI and nuclear weapons

Nobel laureates, scientists, religious leaders and former heads of state and government have signed the Rome Declaration for an Unarmed and Disarming Peace in the Age of Artificial Intelligence, Nuclear and Autonomous Weapons, New Digital Protocols, and Emerging Models of Digital Development.

The declaration was adopted on 16 July on Rome’s Capitoline Hill following the Global Nobel Laureates Assembly on Artificial Intelligence and Nuclear War, hosted by the Vatican.

The declaration calls for renewed international cooperation to address the challenges posed by AI, nuclear weapons and other emerging technologies. It stresses that decisions concerning life and death, peace and war, and the future of humanity should remain under meaningful human control, while highlighting the importance of ensuring that technological progress is guided by ethics, responsibility and respect for human dignity.

The declaration concludes the Global Nobel Laureates Assembly, which brought together more than 200 participants from research institutions, international organisations and civil society. The organisers said the initiative seeks to encourage dialogue on the governance of AI, nuclear weapons and other technologies with significant implications for international peace and security.

Why does it matter?

The declaration reflects growing international efforts to address AI alongside nuclear risks and other emerging technologies through a common governance framework. It also adds to ongoing discussions about maintaining meaningful human control over decisions involving the use of force and other technologies with potentially existential consequences.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot

White House launches GOLD EAGLE cybersecurity initiative

The White House has announced the launch of GOLD EAGLE, a cybersecurity vulnerability coordination initiative established under President Donald Trump’s Executive Order 14410, Promoting Advanced Artificial Intelligence Innovation and Security.

According to the administration, the initiative brings together federal agencies, open-source software partners and operators of critical infrastructure to accelerate the identification and remediation of cybersecurity vulnerabilities using AI.

The initiative is being implemented through collaboration between the White House, the Department of the Treasury, the Department of Homeland Security, including the Cybersecurity and Infrastructure Security Agency (CISA), and the Department of War. The administration said GOLD EAGLE is intended to reduce duplicative vulnerability scanning, improve exploit detection and provide prioritised threat and remediation information to government and private-sector defenders.

According to the announcement, GOLD EAGLE has already begun receiving and prioritising reported cybersecurity vulnerabilities from multiple sectors, coordinating verification efforts and supporting remediation activities. The White House said the initiative represents a new operational model for cyber defence that combines government resources with private-sector capabilities to strengthen the resilience of critical infrastructure and software systems.

Why does it matter?

GOLD EAGLE marks a shift towards more centralised public-private coordination of cybersecurity vulnerability management in the USA. By combining AI-assisted vulnerability prioritisation with information sharing across government agencies and critical infrastructure operators, the initiative aims to accelerate the detection and remediation of cyber threats.

It also reflects the Trump administration’s broader strategy of linking AI innovation with national cybersecurity and critical infrastructure protection.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot

UK publishes government data breach response framework

The UK government has published a Model Action Plan establishing a coordinated approach for responding to significant personal data breaches across government departments and arm’s-length bodies.

The plan prioritises the wellbeing, privacy, safety and legal rights of people affected by personal data breaches. It also introduces mandatory central reporting to help identify systemic weaknesses, analyse incident trends and share lessons across government.

A breach may be considered significant if it creates a risk of serious harm to large numbers of people, affects vulnerable or high-profile individuals, threatens national security or critical infrastructure, involves multiple organisations, or could cause major financial, operational or reputational damage.

The framework is organised into four response phases, beginning with preparation before an incident occurs. Organisations are expected to maintain response plans, clear escalation procedures, information asset registers and defined responsibilities, while ensuring suppliers report suspected breaches within 12 to 24 hours. Departments should also prepare alternative communication channels, notification templates and evidence preservation procedures.

The government recommends regular testing of response plans, including annual tabletop exercises, to ensure organisations can make timely decisions and meet the statutory 72-hour reporting deadline.

During the first 24 hours after identifying a significant breach, organisations should contain the incident, assess its severity and escalate it internally. Where the significance threshold is met, departments must activate crisis response arrangements and appoint a senior incident manager.

Breaches meeting the statutory threshold must be reported to the Information Commissioner’s Office within 72 hours, with the government stressing that an incomplete report submitted on time is preferable to a complete report filed late.

Departments must also notify relevant government bodies, including the Government Security Group, the Government Data Protection team and, where appropriate, the Government Cyber Coordination Centre and National Cyber Security Centre.

Significant incidents reported to the ICO must also be reported centrally to support government-wide analysis and annual public reporting.

Where a breach poses a high risk to individuals, affected people should generally be informed directly and told what happened, the likely consequences and available support. The guidance stresses that protecting affected individuals should take priority over limiting reputational damage and notes that organisations may need to provide helplines, identity monitoring or welfare support.

After an incident, organisations must conduct a comprehensive review, update their breach registers and report lessons and mitigation progress quarterly. The aim is to ensure that findings lead to practical reforms rather than being recorded without further action.

Why does it matter?

The action plan reflects a shift from treating data breaches primarily as compliance incidents towards managing them as coordinated public-sector resilience challenges. Standardised reporting, preparedness exercises and shared lessons could help government organisations respond more consistently while reducing the impact on affected individuals.

The framework also reinforces the principle that effective breach management extends beyond regulatory reporting. By prioritising support for affected people and requiring continuous organisational learning, the government is encouraging departments to treat data protection as an ongoing governance responsibility rather than a one-off compliance exercise.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

OpenAI calls for aligned US AI safety framework

OpenAI has called for closer alignment between US state and federal AI safety efforts, arguing that a common framework is needed to govern frontier AI systems.

In a policy blog post, the company said recent frontier AI legislation in California, New York and Illinois shows how states can help create a shared baseline before a single federal framework is in place.

OpenAI describes this process as ‘reverse federalism’, where state laws move in similar directions and gradually shape a de facto national standard.

The company says core elements should include documented safety frameworks, risk assessments for frontier models, public disclosure of results, serious incident reporting and independent audits.

At the federal level, OpenAI argues that the US government should lead testing and evaluation of the most advanced AI systems, particularly when national security and cybersecurity are at stake.

It says a consistent federal testing framework would help advanced AI tools reach trusted users, including government agencies, critical infrastructure defenders, allies and other partners.

OpenAI also supports clearer requirements for companies developing the most capable systems, including strong security standards, incident reporting, independent audits and whistle-blower protections.

The company warns that neither a fragmented patchwork of state laws nor an undefined federal process would create a coherent frontier safety regime.

Why does it matter?

OpenAI’s proposal highlights the growing tension in US AI governance between state-led action, federal oversight and international standard-setting. A shared framework could reduce regulatory fragmentation and create clearer expectations for frontier model developers. Still, the company’s position also reflects the interests of a major AI lab seeking predictable rules for deployment, testing and access. The debate will shape how the US balances safety, innovation, national security and global influence in AI governance.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot

India approves €13 billion Semicon 2.0 strategy

The Government of India has approved Semicon 2.0, a long-term strategy worth Rs. 1.275 trillion (approximately €13 billion) to accelerate the development of the country’s semiconductor design and manufacturing ecosystem.

Building on Semicon 1.0, the programme aims to strengthen India’s position across the semiconductor value chain through sustained public investment, industrial incentives and workforce development.

The strategy is organised around six pillars, such as semiconductor design, manufacturing equipment and materials, fabrication facilities, advanced packaging technologies, research and development, and talent development.

India plans to expand chip design capabilities, attract additional fabrication plants, encourage investment in ATMP and OSAT facilities, strengthen domestic production of critical materials and manufacturing equipment, and support the development of advanced semiconductor technologies.

The government also highlighted progress under Semicon 1.0. Twelve semiconductor manufacturing facilities have been approved with cumulative investments exceeding Rs. 1.64 trillion, covering silicon fabrication, silicon carbide, gallium nitride display manufacturing and advanced packaging. Three facilities have already entered commercial production, while additional projects are expected to become operational during 2026.

On the design side, 24 semiconductor startups have received financial support and 105 have gained access to advanced chip design tools to develop technologies for AI, IoT, telecommunications, satellite communications and smart devices.

According to the government, Semicon 2.0 is intended to strengthen India’s technological sovereignty, improve semiconductor supply chain resilience and establish the country as a globally competitive hub for semiconductor innovation, manufacturing and intellectual property.

Why does it matter?

Semicon 2.0 reflects the growing use of industrial policy to strengthen domestic semiconductor ecosystems amid global competition for advanced chip manufacturing. By investing across design, production, research and skills, India is seeking to reduce external dependencies while building long-term technological capacity.

The strategy also demonstrates that semiconductor competitiveness increasingly depends on developing the entire value chain rather than attracting fabrication plants alone. If successfully implemented, the programme could strengthen India’s position in global semiconductor supply chains while supporting wider ambitions in AI, telecommunications and advanced manufacturing.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

European Commission accepts X commitments on DSA transparency requirements

The European Commission has accepted corrective measures proposed by X to address alleged breaches of the Digital Services Act (DSA) relating to advertising transparency and researchers’ access to public data.

The action plan requires X to improve its advertising repository so that researchers, civil society organisations and users can more effectively examine advertisements and assess the platform’s systemic risks.

X will introduce new search filters based on advertising content and targeting criteria, display search results directly within the repository, improve response times and provide more complete information about advertisements, including their full content and destination URLs. The company will also make the repository accessible through an application programming interface (API).

The platform will provide additional information about advertisements, including their full content and the URLs to which users are redirected. It will also make the repository accessible through an application programming interface.

The commitments also strengthen researchers’ access to public data. X must improve its application process, provide eligible researchers with timely access to appropriate volumes of data free of charge and avoid unnecessary procedural delays.

The platform will also update its terms and conditions to clarify that eligible researchers are not contractually prohibited from scraping publicly available data.

X now has six months to implement the commitments under an enhanced supervision regime. The Commission said implementation will be verified through an independent audit and close monitoring, following concerns from the Board for Digital Services that the company’s original proposal did not sufficiently address several requirements.

The Commission said it will closely monitor X’s DSA compliance, particularly in areas the Board identified as insufficiently addressed.

Why does it matter?

The commitments strengthen two key pillars of the DSA: transparency in online advertising and independent scrutiny of very large online platforms. Better access to advertising data and public platform information could improve research into systemic risks, political advertising and platform accountability.

The case also demonstrates that accepting corrective measures does not end regulatory oversight. The Commission’s enhanced supervision and independent audit requirements show that compliance under the DSA will increasingly be judged by implementation rather than commitments alone.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

Ofcom investigates TikTok age assurance under UK’s Online Safety Act

Ofcom has opened an investigation into TikTok age assurance and the platform’s compliance with child safety duties under the UK’s Online Safety Act.

The investigation will examine whether TikTok uses proportionate systems and processes to prevent children from encountering content classified as harmful under the Act.

Since 25 July 2025, user-to-user services likely to be accessed by children have been required to prevent minors from encountering primary priority content harmful to children. Platforms must also protect different age groups from other forms of harmful material.

Where primary priority content is available, providers must use age-assurance systems that are highly effective at determining whether a user is a child, unless the content is prohibited for all users under the platform’s terms of service.

Ofcom said the investigation follows its review of measures adopted by major platforms and findings from its report on children’s online experiences, which raised concerns about minors encountering harmful content on TikTok.

A separate report on age assurance also suggested that age-estimation models, including those used by TikTok, may have failed to identify a significant proportion of children correctly.

The regulator will assess whether TikTok’s age-assurance measures meet the legal standard of being ‘highly effective’ and whether any shortcomings may have left children exposed to harmful content.

The regulator stressed that opening the investigation does not mean it has concluded that TikTok breached the law. Its first step will be to use formal information-gathering powers to collect and analyse evidence.

TikTok may choose to follow Ofcom’s Protection of Children Codes of Practice or adopt alternative measures. However, any alternative approach must still satisfy the platform’s legal obligations under the Online Safety Act.

If Ofcom identifies failures involving TikTok age assurance or other child protection systems, it could impose a fine of up to £18 million or 10% of qualifying worldwide revenue, whichever is greater.

In the most serious cases, Ofcom can seek a court order requiring third parties, including payment providers, advertisers and internet service providers, to withdraw services from or block access to a platform in UK.

The investigation is expected to take at least three months, with Ofcom planning to publish an update in October 2026.

Why does it matter?

The investigation will provide an early test of how rigorously Ofcom enforces the Online Safety Act’s child protection duties against major platforms. Its outcome could help define what constitutes ‘highly effective’ age assurance and shape industry expectations for protecting minors online.

The case also reflects a broader shift towards holding platforms accountable not only for removing harmful content but for demonstrating that their safety systems work in practice. Any enforcement action is likely to influence how other online services approach age verification and child safety compliance in the UK.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

Ofcom finalises tougher rules against mobile messaging scams

Ofcom has finalised new rules requiring mobile providers to block, limit and disrupt mobile messaging scams, alongside strengthened guidance to tackle international calls that spoof UK mobile numbers.

The regulator said criminals increasingly use text messages and business messaging services to impersonate friends, companies and public bodies, pressuring victims to transfer money, disclose sensitive information or click malicious links.

Fraud accounted for an estimated 45% of reported crime incidents in England and Wales, with £1.28 billion lost to criminals in 2025. Ofcom also found that 40% of UK mobile users had received at least one suspicious message during the previous three months.

The measures target two main forms of messaging fraud: person-to-person messages sent through SIM cards and mass business messages distributed through commercial messaging infrastructure.

For person-to-person scams, mobile providers must collect intelligence on fraudulent messages, malicious links and phone numbers from customers and anti-fraud organisations. They must use that information to block numbers associated with scammers and stop messages containing malicious links or phone numbers from being delivered across their networks.

Providers must also impose volume limits on pay-as-you-go SIM cards, making it harder for criminal groups to send large numbers of fraudulent messages. The measures complement the government’s proposed ban on SIM farms and commitments made by operators under the Fraud Sector Charter.

Business messaging providers and aggregators must carry out initial and ongoing Know Your Customer (KYC) checks on organisations sending messages and monitor their activity through Know Your Traffic controls.

Providers will also verify alphanumeric sender IDs, which display company names instead of telephone numbers. The checks are intended to prevent scammers from impersonating trusted businesses, delivery services and government agencies.

Where providers identify fraudulent messaging activity, they must investigate its source, apply incident management procedures, and block malicious sender IDs, links and telephone numbers. Companies that fail to carry out appropriate checks may also face regulatory action.

Ofcom has separately strengthened its guidance on international calls that spoof UK mobile numbers. Telecoms companies should withhold the caller ID for calls that appear to originate from a UK mobile number roaming abroad unless they can verify that the number is genuine.

The regulator said spoofing makes overseas calls appear more trustworthy and increases the likelihood that potential victims will answer. However, it cautioned that legitimate organisations may also use withheld numbers, meaning users should continue to assess unexpected calls carefully.

Mobile providers already block more than 600 million suspected scam messages each year, but Ofcom said inconsistent protections across the sector continue to leave consumers exposed.

Consumers can report suspicious calls and messages by forwarding them to 7726, enabling mobile operators to update their fraud-detection and network-protection systems.

Why does it matter?

The new rules shift greater responsibility onto mobile providers to prevent scams before they reach consumers. By requiring stronger customer verification, sender authentication, network-level filtering and SIM controls, Ofcom is moving fraud prevention further upstream rather than relying primarily on users to recognise suspicious messages.

The measures also reflect a broader regulatory trend towards placing more accountability on communications providers to combat digital fraud. If successful, the framework could reduce large-scale messaging scams while serving as a model for other jurisdictions seeking to strengthen telecoms security.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

Spain promotes national cybersecurity support helpline

Spain’s National Cybersecurity Institute (INCIBE) has highlighted its free and confidential 017 helpline, which provides specialist advice on digital security issues for citizens, businesses, professionals and educational institutions.

The helpline provides guidance on scams, phishing, identity theft, compromised accounts, social media privacy, cyberbullying, device security and protecting personal information. It also advises on parental controls, online child safety, digital identity management and the safe use of apps and social media platforms.

INCIBE stressed that 017 is a cybersecurity advisory service rather than a reporting channel or technical support line. Specialists explain appropriate reporting procedures, direct users to the relevant authorities where necessary and assess each case individually.

The service is available daily from 8:00 to 23:00 via telephone, WhatsApp, Telegram, an online form and, by appointment, in person at INCIBE’s headquarters in León.

Why does it matter?

As cyber threats become more common, many users need trusted advice before or after an incident rather than only technical assistance or law enforcement support. Services such as INCIBE’s 017 helpline can help individuals and organisations respond more effectively while improving awareness of everyday cyber risks.

The initiative also reflects a broader shift towards strengthening national cyber resilience through public support services. By combining technical, legal and practical guidance in a single point of contact, governments can encourage earlier reporting, better cyber hygiene and more effective responses to digital security incidents.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot

UK plans default overnight social media restrictions for teenagers

The UK government plans to introduce default overnight social media restrictions for 16- and 17-year-olds, alongside measures to limit features designed to encourage prolonged platform use.

Social media platforms will be expected to activate overnight restrictions from midnight to 6 a.m. by default for users in this age group. Teenagers will be able to change the settings, but the protections will be enabled automatically.

Autoplay and continuously personalised content feeds will also be disabled by default. The government said these features can encourage prolonged use and reinforce potentially addictive patterns of engagement.

The measures are intended to avoid a sudden reduction in online protections when children turn 16. They complement the government’s previously announced plans to prohibit social media services from being offered to children under 16 from spring 2027.

The proposals follow a government pilot involving more than 300 teenagers and parents across the UK. Participating families said the overnight restrictions became part of their routines and helped improve sleep and concentration.

Technology Secretary Liz Kendall said older teenagers should retain greater independence while continuing to receive protection from features that could negatively affect their wellbeing.

The government also plans additional protections for children using AI chatbots. Proposed measures include encouraging regular breaks for users under 18 and taking action against services that provide dangerous, misleading or unverified mental health advice.

Ministers will work with regulators and other government departments to consider further restrictions, including possible bans on chatbots considered to pose a serious risk to children. Guidance for children, parents and guardians will also be added to the Kids Online Safety Hub.

Schools will strengthen media literacy through Relationships, Sex and Health Education classes covering AI, chatbots, misinformation and harmful online content. From September 2028, media literacy will also be embedded across the National Curriculum, including lessons on AI, data science, source analysis and technological bias.

The first regulations supporting the under-16 social media restrictions are expected to be presented to Parliament by the end of 2026, with implementation and enforcement planned for spring 2027.

Why does it matter?

The proposals reflect a growing shift from focusing solely on access to social media towards regulating how digital services are designed and used. By targeting autoplay, personalised feeds and AI chatbots alongside age-based protections, the government is seeking to address features that may contribute to excessive use and online harms.

If adopted, the measures could further shape debates on youth online safety beyond the UK, reinforcing the trend towards safety-by-design, stronger protections for minors and greater platform responsibility for children’s digital wellbeing.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!