UNIDIR publishes guidance on gender-responsive cybersecurity

The United Nations Institute for Disarmament Research (UNIDIR) has published a compendium of good practices to help governments integrate gender perspectives into cybersecurity policies and strengthen the implementation of responsible state behaviour in cyberspace.

Drawing on a series of multistakeholder workshops held with the Stimson Center in 2025, the report brings together existing initiatives and practical examples from governments and other stakeholders. It also identifies lessons learned and recommendations for incorporating gender considerations into national ICT architectures and implementing the UN Framework for Responsible State Behaviour in Cyberspace.

The compendium covers four themes: the gendered impacts of ICTs, the application of international law in cyberspace, the integration of gender into national cybersecurity institutions and strategies, and gender-responsive cyber capacity building. It also includes practical recommendations and a toolbox of resources for policymakers and practitioners.

UNIDIR said the compendium is intended to help governments and other stakeholders strengthen cybersecurity governance through more inclusive policy development and implementation.

Why does it matter?

The compendium reflects growing recognition that cybersecurity governance should consider how cyber threats, policies and digital technologies affect different groups of people. Rather than treating gender as a standalone issue, the report presents it as an element of effective, inclusive cybersecurity policymaking.

By collecting practical examples and recommendations from governments and the wider multistakeholder community, the publication also supports international efforts to strengthen responsible state behaviour in cyberspace and build more inclusive national cyber capacity.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot

UN Global Mechanism on cybersecurity begins work with focus on participation and consensus

The United Nations’ new permanent mechanism on international cybersecurity has begun its substantive work, opening a new phase of multilateral discussions on responsible state behaviour in cyberspace.

The first substantive session of the Global Mechanism on Developments in the Field of ICTs in the Context of International Security opened on 20 July at UN Headquarters in New York under the chairmanship of Ambassador Egriselda López of El Salvador. The meeting marked the first time member states had convened within a standing UN framework dedicated to ICT security and responsible state behaviour.

The mechanism succeeds years of negotiations under the Open-Ended Working Group and is intended to provide a permanent, single-track forum for discussions across five established pillars, such as existing and potential ICT threats, rules and norms of state behaviour, the application of international law, confidence-building measures, and capacity development.

In a pre-recorded statement, UN Under-Secretary-General and High Representative for Disarmament Affairs Izumi Nakamitsu described the mechanism as holding ‘tremendous promise’. She highlighted its permanent and consensually agreed character and called for stakeholder engagement to take place in a systematic, sustained, and substantive manner.

A permanent forum takes shape

Opening the session, López described the meeting as a historic moment that would help shape not only the first two-year cycle of the mechanism but also the UN’s wider approach to ICT security in the years ahead.

She acknowledged that the forum was beginning its work amid a complex international environment marked by attacks against critical infrastructure, disruptions to digital supply chains, the use of ICTs in conflicts, and the growing interaction between cybersecurity and emerging technologies such as AI.

The Chair also emphasised that agreement would require sustained diplomatic effort.

‘Consensus is not automatic,’ López told delegations, arguing that it must be built through commitment, flexibility, and political will.

She noted that multilateral processes are often advanced through ‘small steps, difficult compromises, and the willingness to keep talking even when there are differences’.

The session achieved an early procedural milestone with the adoption, by consensus, of the provisional agendas for the 2026 and 2027 plenary sessions. The mechanism also noted its provisional programme of work, creating a framework for the substantive discussions scheduled for the week.

The mechanism tests its approach to stakeholder participation

A substantial part of the opening discussion focused on how non-governmental stakeholders should participate in the mechanism.

Under the agreed accreditation procedure, applications are accepted unless a member state submits a written objection. The Chair reported that she had held consultations with states that raised objections, although the positions of the concerned governments remained unchanged.

Several delegations expressed concern that a large proportion of stakeholder applicants had not received accreditation. They argued that technical experts, civil society organisations, industry representatives, and academic institutions can provide knowledge that supports informed negotiations and practical implementation.

The issue was particularly important for smaller and developing states, some of which said they rely heavily on external partners because they have limited domestic technical and diplomatic capacity.

Kiribati emphasised that technical partners and regional organisations had contributed to its national cybersecurity posture and helped shift international discussions from problem identification to solution delivery. It called for greater transparency around objections, arguing that explanations could help states understand and potentially address the concerns raised.

‘Transparency here costs the objecting state little; silence costs the rest of us a great deal,’ the delegation said.

Other delegations placed greater emphasis on ensuring that participating organisations meet the agreed standards of objectivity and impartiality. They maintained that the non-objection procedure was negotiated by consensus and that states retained the right to raise concerns about individual applicants.

The discussion, therefore, reflected a broader institutional question of how the mechanism can preserve state oversight while gaining access to the technical expertise needed for meaningful cybersecurity cooperation.

Participation rules remain important for thematic work

Delegations also considered how stakeholder participation should function in the Dedicated Thematic Groups scheduled to meet from 7 to 11 December.

The mechanism will operate two such groups. One will address general substantive issues, while the other will focus on capacity development. Their purpose is to enable more detailed and interactive discussions that build on the work of the annual plenary.

Some delegations argued that, because the thematic groups are informal, they should be able to include a wide range of experts and stakeholders without requiring the same accreditation process used for formal plenary sessions.

Others maintained that the agreed participation modalities for the mechanism should apply consistently across all its formats. From this perspective, applying different rules to the thematic groups could weaken their intergovernmental character or create uncertainty over the status of their outcomes.

The debate highlighted the need for predictable working methods before the December meetings. Clear guidance on participation, expert briefings, meeting formats, and reporting procedures will be particularly important for delegations with limited resources.

Procedural questions shape preparations for thematic discussions

The Chair also announced the appointment of four co-facilitators for the thematic groups, selected from Australia, Egypt, Malaysia, and the Netherlands.

López said the appointments reflected geographic and gender balance and that the co-facilitators would serve in their personal capacities under the principles of neutrality, impartiality, and inclusion.

Many delegations welcomed the appointments as a practical step towards ensuring that preparations for the December meetings could move forward. They viewed the selection of facilitators as consistent with practices used in other UN processes.

Other delegations preferred the appointments to be formally agreed upon by consensus among all member states. They argued that the mechanism’s state-led character requires collective agreement on both procedural and substantive decisions.

The exchange demonstrated that the meaning of consensus will remain an important issue as the new forum develops its institutional practices. The challenge will be to preserve the confidence of all states while allowing the mechanism to carry out the organisational work needed to function effectively.

From general debate to practical cooperation

Beyond the procedural questions, delegations began outlining how the thematic groups could contribute to the mechanism’s wider objectives.

Several countries supported focused, scenario-based discussions addressing concrete challenges such as ransomware, attacks against critical infrastructure, AI security, operational technology, quantum readiness, and post-quantum cryptography.

Others emphasised that the groups should maintain a balanced approach across all five pillars of the framework and avoid prioritising specific topics without the agreement of member states.

Capacity development emerged as a particularly important theme. Developing and smaller states highlighted the role of partnerships with governments, international organisations, industry, academia, and civil society in strengthening national cyber resilience.

Questions of accessibility were also raised. Colombia and Mexico called for simultaneous interpretation to support participation by experts from different linguistic communities, while Mauritius stressed the need for clear rules, timelines, and coordination between the two thematic groups.

These proposals suggest that the success of the mechanism will depend not only on reaching agreements at the diplomatic level but also on translating them into practical cooperation that responds to national needs.

Building consensus in a permanent mechanism

The opening plenary showed that establishing a permanent international forum involves more than adopting a mandate. Member states must also develop shared expectations about participation, decision-making, working methods, and the relationship between formal negotiations and technical expertise.

Despite differing interpretations of some procedures, delegations broadly reaffirmed their support for the Global Mechanism and its objective of strengthening international cooperation on ICT security.

The consensus adoption of the agenda provided a foundation for the substantive work ahead. The Chair also pledged to continue consultations with states and maintain sustained dialogue with stakeholders.

The mechanism’s first session, therefore, represents both an institutional achievement and an early test of multilateral cooperation. Its ability to deliver practical results will depend on whether member states can balance inclusivity, state leadership, procedural predictability, and the consensus principle on which the forum was founded.

As the mechanism moves towards its first Dedicated Thematic Group meetings in December, the immediate priority will be to turn its permanent mandate into working arrangements capable of supporting trust, resilience, and responsible state behaviour in cyberspace.

Track all key moments from the First substantive session of the UN Global Mechanism on cybersecurity on our dedicated page.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

Victoria proposes tougher child safety laws for social media and AI

Victoria’s Labor government plans to introduce child safety laws that would make it easier for families to bring legal claims against social media and AI companies accused of harming children.

The proposed reforms would remove the requirement for claims brought on behalf of minors to demonstrate permanent psychiatric impairment of at least 10% before proceedings against social media or AI providers can begin.

The government argues that addictive platform features can damage children’s mental health and that the current legal threshold creates an unnecessary barrier for affected families seeking compensation.

The reforms would also give the Victorian Civil and Administrative Tribunal (VCAT) new powers to issue ‘demasking orders’, requiring social media companies to reveal the identities of anonymous users accused of online vilification.

Premier Jacinta Allan said families should be able to hold technology companies accountable when their platforms harm children and that anonymity should not shield users responsible for hateful conduct.

The government will also consider whether the lower legal threshold should apply to claims involving adults before finalising the legislation. The reforms will be developed through targeted consultations with VCAT, the courts and other stakeholders before being introduced to parliament.

Why does it matter?

The proposed reforms reflect a growing international trend towards holding technology companies more accountable for the real-world impacts of platform design, particularly where children are concerned. Lowering the threshold for legal claims could make it easier for families to seek redress while increasing pressure on platforms to address features that may contribute to harm.

The introduction of ‘demasking orders’ also illustrates how online safety policy is expanding beyond content moderation to include stronger legal mechanisms for identifying anonymous users and enforcing accountability. If adopted, the legislation could influence similar debates in other jurisdictions considering tougher platform liability rules.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

Kenya restricts presidential website after cybersecurity incident

Kenya temporarily restricted access to the President’s official website after detecting a cybersecurity incident, the Ministry of Information, Communications and the Digital Economy announced.

The ICT Authority activated its established incident response procedures after reports of the attack. Access to the website was restricted as a precaution to support containment, forensic analysis and restoration.

The ministry said mitigation measures had already been implemented and work to restore the website was underway. Officials added that there was no evidence of unauthorised access to sensitive data, data exfiltration or information loss, and that other government systems and digital services remained secure and operational.

The ICT Authority of Kenya is continuing to work with government agencies and technical partners to investigate the incident and determine its full scope and cause.

Why does it matter?

Government websites are high-profile targets because they provide official public information and can influence trust in state institutions even when no sensitive systems are compromised. Temporary restrictions and forensic investigations are standard measures that help contain potential threats while authorities assess the scope of an incident.

The case also highlights the importance of transparent incident reporting. Confirming what was, and was not, affected can help maintain public confidence while allowing investigators time to establish the cause and strengthen future cyber resilience.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

IWF partners with Tuteliq to strengthen child online safety

The Internet Watch Foundation (IWF) has partnered with Swedish behavioural detection technology company Tuteliq to strengthen the early detection of online grooming and child sexual abuse material (CSAM).

As a new IWF Member, Tuteliq will integrate the organisation’s URL List and Image Hash List into its detection platform, enabling online services to identify and block known CSAM more effectively.

Unlike traditional moderation systems that analyse individual messages or files, Tuteliq’s technology examines how conversations evolve over time to identify behavioural patterns associated with grooming, coercion and online sexual exploitation before abuse occurs.

The platform analyses text, voice, images and video across 27 languages and is intended for youth-focused apps, gaming platforms, sports organisations and other online communities.

The partnership combines Tuteliq’s behavioural analysis with the IWF’s verified databases of known CSAM, aiming to strengthen prevention alongside detection by enabling earlier intervention before harmful content is created or shared.

Tuteliq said its platform retains no user data, is hosted within the EU and is designed to comply with the General Data Protection Regulation (GDPR)..

Beyond the technical integration, Tuteliq will also draw on the IWF’s research, policy expertise and threat intelligence to further develop its detection models. According to the organisations, the collaboration reflects a broader shift towards combining behavioural analysis with verified intelligence to improve online child protection.

Why does it matter?

The partnership reflects a broader shift from reactive content moderation towards preventing online abuse before illegal material is created or shared. Behavioural AI capable of identifying grooming patterns could allow platforms to intervene earlier, potentially reducing harm before exploitation escalates.

At the same time, expanding behavioural detection raises important questions about transparency, privacy and accountability. As platforms increasingly analyse patterns of user behaviour rather than individual pieces of content, ensuring appropriate safeguards and oversight will become an important part of child online safety governance.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!  

Germany and France strengthen AI safety and digital sovereignty cooperation

Germany and France have agreed to deepen cooperation on AI, AI safety and digital sovereignty following the Franco-German Ministerial Council, reinforcing their joint role in shaping Europe’s technology agenda.

The partnership centres on closer collaboration between France’s AI safety institute, INESIA, and Germany’s newly established AI Safety and Security Institute to strengthen the evaluation and secure deployment of advanced AI models.

The two governments will coordinate AI safety research, institutional expertise and risk assessments while supporting implementation of the European AI Office’s work under the AI Act. They also reaffirmed their commitment to advancing AI safety cooperation through the EU, NATO and the United Nations, positioning it as a shared strategic priority.

Beyond AI safety, Germany and France agreed to strengthen digital sovereignty by jointly shaping the forthcoming EU Tech Sovereignty Package, building on their common definition of digital sovereignty presented at VivaTech 2026.

They also called on the European Commission to reinforce the Digital Fitness Check, deepen cooperation on public sector modernisation and promote a coordinated European spectrum policy to support secure and competitive satellite communications.

The agreement builds on earlier cooperation under the Treaty of Aachen and the Franco-German economic and technological sovereignty agenda. By strengthening collaboration on AI governance, digital infrastructure and strategic technologies, both countries aim to reinforce Europe’s technological resilience and influence over global AI governance.

Why does it matter?

The agreement reflects a broader European effort to strengthen technological sovereignty by combining AI governance, industrial policy and security cooperation. Rather than treating AI safety as a purely technical issue, Germany and France are positioning it as part of Europe’s wider strategy for digital resilience and strategic autonomy.

By coordinating national AI safety institutes while supporting EU institutions such as the AI Office, the partnership could also contribute to a more coherent European approach to evaluating advanced AI systems and shaping international AI governance.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!  

Meta adds suicide prevention safeguards to AI chats for teens

Meta has announced new safety measures for teenagers using Meta AI, including parental alerts when supervised teens show signs of suicide or self-harm during conversations with the chatbot. The company said alerts will be sent only after manual review and will include guidance to help parents support their child.

The company is also developing a system to notify emergency services when AI conversations indicate someone may face an imminent risk of suicide. The approach builds on the company’s existing practice of referring serious suicide risks identified on Facebook and Instagram to emergency responders.

Meta said it worked with more than 75 mental health clinicians to improve how its AI responds when teenagers discuss suicide or self-harm. The updated responses are intended to acknowledge users’ feelings while directing them towards appropriate offline support and crisis services.

The company is also extending its stricter ‘Limited Content’ setting to Meta AI chats, restricting a wider range of sensitive conversations for supervised teens. The parental alerts are now available in the US, UK, Australia and Canada, with global rollout planned by the end of the year.

Why does it matter?

The measures illustrate how AI safety is expanding beyond preventing harmful content to managing situations in which users may face immediate risks to their wellbeing. As conversational AI becomes more widely used by teenagers, developers are increasingly expected to incorporate safeguards, human oversight and access to professional support into their systems.

The announcement also highlights the growing convergence between AI governance and child online safety. Features such as parental notifications, clinically informed responses and emergency escalation suggest that AI assistants are beginning to adopt safety frameworks previously developed for social media platforms, raising new questions about privacy, duty of care and appropriate intervention.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot

Researchers demonstrate prompt injection attacks on Gemini

Kaspersky security researchers have demonstrated new attack techniques that could manipulate Google’s Gemini AI assistant into performing unauthorised actions via prompt injection. The study found that malicious instructions hidden in calendar invites, emails or text messages could bypass safeguards by exploiting how large language models process information.

According to the research, attackers could combine indirect prompt injection, memory poisoning and delayed execution to influence Gemini’s behaviour. Potential outcomes include sending emails, launching applications, controlling compatible smart home devices, displaying false information or embedding malicious instructions into the assistant’s long-term memory, provided the user has granted the necessary permissions.

Researchers also warned that smartphones significantly expand the potential attack surface because Gemini can access notifications containing SMS messages, instant messages and social media alerts. Although Google has addressed the specific vulnerabilities identified in the research, the report argues that prompt injection remains a fundamental challenge for AI systems and that new attack methods are likely to emerge.

The researchers recommend reducing Gemini’s access to notifications, connected apps and system functions where possible, turning off unnecessary AI features and limiting permissions to minimise the impact of future attacks. They also advise users to review AI assistant settings regularly as security protections continue to evolve.

Why does it matter?

Prompt injection represents a major challenge for AI security because it targets how large language models interpret and prioritise information. As AI assistants gain broader access to personal data and connected devices, stronger safeguards will be needed to reduce potential risks.

The research highlights the importance of developing more robust AI security frameworks, including improved permission management and continuous testing, to ensure reliable and responsible adoption of AI technologies.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our chatbot!

ONS reports growing concern about AI in Great Britain

Public concern about AI is growing across Great Britain, with more adults believing its risks outweigh its benefits, according to new data from the Office for National Statistics (ONS).

The survey found that 38% of adults believed AI’s risks outweighed its benefits, up from 25% in August 2024. Only 13% said the benefits outweighed the risks, while 43% considered them broadly balanced.

Despite growing concerns, 36% of respondents said AI would benefit them personally, although 27% disagreed, the highest share recorded since the ONS began asking the question in November 2023. Younger adults remained considerably more optimistic than older respondents.

Misinformation, privacy and security emerged as the public’s main concerns. Around 81% of respondents believed AI would make fake information harder to identify, 77% worried personal data could be used without consent and 63% expected greater exposure to cybercrime.

Nearly half of adults under 50 also believed AI could threaten their jobs, while trust remained very low for high-impact uses such as government decision-making (4%) and caregiving (5%).

Public concern contrasted with more limited expectations of personal benefit. While respondents identified education, workplace assistance and household support as AI’s main advantages, 41% said the technology would have no positive impact on their own lives.

Why does it matter?

The findings suggest that public acceptance of AI is becoming a key governance challenge alongside technological development. Growing concerns about misinformation, privacy, cybersecurity and employment could make citizens less willing to embrace AI unless governments and companies demonstrate that effective safeguards are in place.

The survey also highlights a widening gap between rapid AI deployment and public confidence. As AI becomes more deeply integrated into public services and everyday life, trust, transparency and accountability may prove just as important as technical capability in determining how quickly the technology is adopted.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

South Korea strengthens investigations into AI and semiconductor technology leaks

South Korea has restructured its specialised intellectual property investigation system to strengthen efforts against leaks of advanced technologies, including semiconductors and AI, amid growing concerns over economic security.

The reforms establish new investigative and analytical divisions while expanding the technology police force from 27 to 61 officers.

A new Technology Divulgence Police Division will investigate trade secret theft and the leakage of advanced technologies. Its 21 investigators will include specialists in electrical, chemical and mechanical engineering alongside patent examiners, attorneys and other technical experts.

The government also plans to expand investigative authority to cover violations involving National Core Technologies and National High-Tech Strategic Technologies.

A separate Intellectual Property Protection Analysis Division will use patent data and other intelligence to identify technologies, companies and institutions at high risk of technology leakage.

It will also cooperate with businesses, research organisations and law enforcement agencies to detect warning signs, support intelligence-led investigations and strengthen security awareness, particularly among smaller companies.

The restructuring creates an Intellectual Property Protection Standards Division responsible for investigative procedures, oversight and human rights safeguards.

Planned reforms in South Korea include clearer rules for compulsory investigations, external review through a Criminal Investigation Review Committee, stronger access to legal counsel, wider use of video recording and regular updates for parties involved in investigations.

Why does it matter?

As geopolitical competition increasingly centres on semiconductors, AI and other strategic technologies, governments are treating intellectual property protection as a matter of economic and national security. South Korea’s reforms aim to strengthen its ability to detect, investigate and prevent technology leakage before commercially valuable innovations are transferred abroad.

The restructuring also reflects a broader trend towards combining specialised technical expertise with intelligence-led enforcement and stronger procedural safeguards. This approach seeks to improve both the effectiveness and accountability of investigations involving advanced technologies.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!