ENISA introduces cybersecurity assessment tool for SMEs

The European Union Agency for Cybersecurity (ENISA) has introduced a Cyber Resilience Maturity Assessment Model to help micro, small and medium-sized enterprises (SMEs) strengthen cybersecurity and prepare for the EU’s Cyber Resilience Act (CRA). The framework offers a structured way for organisations to assess their current cyber resilience, identify weaknesses and improve product security over time.

Designed primarily for manufacturers of products with digital elements, the framework provides a structured way for organisations to assess their cyber resilience, identify weaknesses and improve product security over time. It evaluates five areas, such as governance, risk management, vulnerability management, product lifecycle management and cybersecurity skills.

Businesses are classified as having basic, intermediate or advanced cybersecurity maturity. A downloadable assessment tool allows organisations to track progress through repeated self-assessments, although ENISA notes that achieving a higher maturity level does not replace compliance with the CRA.

Alongside the framework, ENISA published the results of a survey of 194 organisations across 31 countries. While 66% of respondents were aware of the CRA, many said they had only a limited understanding of its practical requirements. Medium-sized companies generally demonstrated stronger cybersecurity maturity than micro-enterprises, with incident response and product lifecycle management emerging as the weakest areas.

More than 70% of SMEs said they needed practical support, including technical guidance and secure development templates. Respondents also cited limited budgets, staff and time as major barriers to compliance, prompting ENISA to recommend targeted guidance, financial support and stronger outreach to smaller businesses.

Why does it matter?

SMEs make up a large share of Europe’s digital economy and supply chains, yet many lack the resources needed to meet increasingly demanding cybersecurity requirements. ENISA’s maturity model gives organisations a practical way to assess their readiness, strengthen product security and prepare for compliance with the Cyber Resilience Act.

The findings also highlight that regulation alone is unlikely to improve cybersecurity. Smaller businesses will need practical guidance, technical support and investment to meet new standards, making implementation as important as the legislation itself.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our chatbot!

MIT develops safer way to detect harmful AI models

MIT researchers have developed a new auditing method to detect whether generative AI models have been adapted to produce child sexual abuse material without generating illegal content during testing.

The technique was developed with Thorn, a child safety nonprofit focused on protecting children from sexual abuse and exploitation online.

Traditional AI safety testing often involves prompting a model and checking its outputs, but that approach cannot be used for child sexual abuse material, which is illegal to generate in the US and many other jurisdictions.

MIT said the problem has become more urgent as open-source generative AI models become easier to download, adapt and redistribute.

The researchers’ method examines internal changes during fine-tuning, rather than testing the model by generating images.

In tests, the auditing procedure identified model variants adapted to generate child sexual abuse material with 100% accuracy.

MIT said hosting platforms could use the method to flag unsafe models, block uploads or remove harmful adaptations before they spread more widely online.

The researchers also plan to test whether the approach can detect harmful capabilities in a larger set of model variants and in base models before adaptation.

Why does it matter?

The research addresses a serious AI safety blind spot: some harmful model capabilities cannot be tested safely or legally by generating outputs. A non-generative auditing method could give hosting platforms, auditors and law enforcement a safer way to detect models adapted for child sexual abuse material before they are distributed. It also points to a broader governance challenge around open-source generative AI: platforms may need scalable tools to assess harmful adaptations without exposing reviewers to illegal or traumatic content.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

Ofcom proposes tougher rules on scam ads

Ofcom has proposed new rules requiring major online platforms to do more to prevent scam advertising, including verifying advertisers, blocking repeat fraudsters and making fraudulent adverts easier to report.

The draft Fraudulent Advertising Code is being developed under the UK’s Online Safety Act and would apply to some of the country’s largest social media platforms, search engines and other online services.

According to Ofcom, more than half of UK adults have encountered potentially fraudulent adverts online, while victims lose an estimated £200 million each year. The regulator said online platforms have not done enough to stop criminals exploiting their advertising systems.

The proposed code sets out nearly 40 measures, including banning accounts that publish scam adverts, preventing repeat offenders from opening new accounts, verifying the identity of advertisers and confirming that firms promoting banking or investment services are properly authorised.

Platforms would also be expected to strengthen account security, reduce the risk of account hijacking, test AI-powered advertising tools against misuse and establish dedicated reporting channels for trusted organisations, including law enforcement agencies, to flag fraudulent adverts for rapid removal.

Ofcom also wants platforms to use proactive technologies to detect and block fraudulent advertising before it reaches users. A separate consultation on those proposals is expected this autumn alongside a broader package of online safety measures.

The consultation remains open until 2 October, with final decisions expected next year. Once approved by Parliament, companies that fail to comply could face fines of up to £18 million or 10% of global annual revenue, whichever is higher.

Alongside the advertising proposals, Ofcom also published draft rules for Category 1 services under the Online Safety Act. These include stronger protections for journalistic content and democratic debate, improved user controls over harmful content, more effective complaints procedures and greater transparency through published risk assessment summaries.

Why does it matter?

The proposals would expand platform responsibility beyond user-generated content to the advertising systems that increasingly enable online fraud. By introducing requirements for advertiser verification, proactive detection and stronger enforcement against repeat offenders, Ofcom is seeking to make scam prevention a core responsibility of online platforms rather than relying primarily on users to identify fraudulent adverts.

The draft code also reflects a broader regulatory trend towards greater accountability for digital advertising ecosystems. As AI-generated content and increasingly sophisticated scams become more common, regulators are placing greater emphasis on platform governance, advertiser verification and proactive risk management.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

Cybercrime accounts for one in five crimes in Spain

Spain recorded 488,426 cybercrimes in 2025, accounting for 19.8% of all reported crime, according to the Spanish Ministry of Interior’s latest Cybercrime Report. The figure shows a 5.1% increase from 2024, demonstrating the growing threat of digital crime nationwide.

Computer fraud and online scams continued to dominate cybercrime, accounting for nearly nine in ten reported offences with 429,677 cases. Internet-related forgery increased by 11.3% to 21,690 cases, while sexual offences rose by 21% and illegal access or interception offences surged by 40.7%, highlighting the growing diversity of cybercriminal activity.

The number of cybercrime victims reached 383,285, up 9.3% from 2024. People aged 51 to 65 were the most frequently targeted, particularly through credit card fraud and travel cheque scams, accounting for 146,737 victims. Although most victims were male, the types of cybercrime varied considerably across age groups and demographics.

Critical infrastructure operators experienced 90 cyberattacks in 2025, a 43.8% decrease from the previous year. The transport sector accounted for 42.2% of incidents, followed by the information and communications technology sector with 15.5%.

Why does it matter?

The report shows that cybercrime has become a mainstream form of criminal activity, accounting for nearly one in five reported offences in Spain. The continued growth in fraud, online scams and unauthorised access highlights how digital crime is evolving alongside greater reliance on online services by individuals, businesses and public institutions.

Although attacks on critical infrastructure declined, the overall increase in cybercrime and victim numbers suggests that law enforcement and cybersecurity authorities will need stronger investigative capabilities, cross-border cooperation and preventive measures to keep pace with increasingly sophisticated digital threats.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot

European Commission panel recommends social media restrictions for under-13s

A special panel convened by the European Commission has recommended restricting access to social media and other high-risk digital services for children under 13, arguing that platforms should prove they are safe before minors are allowed to use them.

The report was prepared by the co-chairs of the Special Panel on Child Safety Online, Prof. Dr. Jörg M. Fegert and Dr. Maria Melchior, whom European Commission President Ursula von der Leyen appointed in March 2026 to advise on child safety online and possible age restrictions for social media.

The panel met three times between March and June 2026 to examine scientific evidence on the impact of social media and digital environments on minors, review existing EU and national rules, and develop recommendations to better protect and empower children online.

The report uses the term ‘social media+’ to describe social media and other digital services that expose minors to potentially harmful features, including addictive design, infinite scroll, autoplay, recommender systems, persistent notifications, AI companions, video games and video-sharing platforms.

The co-chairs argue that providers, not children or parents, should bear the burden of demonstrating that their services are safe by design and appropriate for young users. Until then, they recommend restricting access for children under 13, while allowing member states to introduce additional precautionary measures for older adolescents if needed.

The recommendations also call for proportionate age-assurance systems, stronger safety-by-design requirements, limits on addictive platform features, more effective complaints mechanisms for minors and stronger enforcement of existing EU legislation, including the Digital Services Act, GDPR and AI Act.

The report also urges the EU to close legislative gaps on child sexual abuse online by adopting permanent obligations requiring providers to prevent, detect, report and block abuse, including in interpersonal communications.

Beyond restrictions, the report emphasises digital empowerment through stronger media literacy for children, parents, teachers and caregivers, greater participation by young people in policymaking, improved parental guidance, increased support for civil society organisations and helplines, and more investment in offline activities such as sports, arts and youth spaces.

The report concludes that protecting children online requires an ecosystem-wide approach involving regulators, digital service providers, educators, parents, caregivers and children themselves. It argues that children’s rights should apply online just as they do offline, balancing protection with opportunities to learn, participate and communicate.

Why does it matter?

The report could significantly influence future EU policy on children’s access to digital services, platform design and online safety. By recommending a default restriction for children under 13 and placing responsibility on providers to demonstrate that their services are safe, it shifts the debate away from parental responsibility towards platform accountability.

Although the recommendations are not legally binding, they are likely to inform future discussions on the Digital Services Act, the AI Act and wider EU child protection policies. If adopted, they could reshape how online platforms design services for younger users across Europe.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

UK brings major cloud providers under financial oversight

The UK government has designated Microsoft, Google Cloud, Amazon Web Services (AWS) and Oracle as Critical Third Parties (CTPs), bringing the major cloud providers under direct financial regulatory oversight for the first time.

From 13 July 2026, the four companies will come under direct oversight by the Bank of England, the Prudential Regulation Authority (PRA) and the Financial Conduct Authority (FCA), with the aim of strengthening the operational resilience of the UK financial system.

The new regime reflects the financial sector’s growing dependence on cloud infrastructure. Regulators will be able to assess the resilience of critical services, gather operational information and require providers to address risks that could disrupt banking, insurance or financial market infrastructure.

The oversight applies only to services considered systemically important to the financial sector, rather than to the companies’ wider commercial operations.

The UK government described the framework as a proportionate, risk-based approach designed to reduce the likelihood of widespread service disruptions affecting millions of consumers and businesses. It also said additional technology providers could be designated in the future if they meet the statutory threshold for systemic importance.

Microsoft, Google Cloud, AWS and Oracle all welcomed the framework, saying they would comply with the new requirements and continue supporting the resilience of the UK’s financial sector.

Why does it matter?

The designation marks a significant shift in financial regulation by extending direct oversight beyond banks and financial institutions to the technology providers that underpin critical financial services. As cloud infrastructure becomes increasingly central to banking, payments and financial markets, regulators are treating operational resilience as a systemic issue rather than solely a commercial responsibility.

The UK’s approach could also influence regulators in other jurisdictions. As financial institutions become more dependent on a small number of hyperscale cloud providers, governments may increasingly seek direct oversight of technology companies whose services have become essential to the stability of critical sectors.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

Swiss Army moves from Microsoft 365 to OpenDesk

The Swiss Armed Forces’ Cyber Command is replacing Microsoft 365 with OpenDesk, an open-source office and collaboration suite developed by Germany’s Centre for Digital Sovereignty in Public Administration (ZenDiS).

According to the Swiss magazine Republik, all employees of the Cyber Command and its Cyber and Electromagnetic Activities unit are expected to migrate to OpenDesk by October 2026.

The move reflects concerns that Microsoft’s increasing reliance on cloud-based services no longer meets the military’s operational requirements. Cyber Command chief Simon Müller said products subject to legislation such as the US CLOUD Act are unsuitable for certain military contexts, while the migration is intended to give the Swiss military greater control over its data and software environment.

The transition also aligns with Switzerland’s broader efforts to strengthen digital sovereignty by increasing the use of open-source software. OpenDesk is being developed by ZenDiS to provide public administrations with an alternative to proprietary office and collaboration platforms while reducing dependence on individual technology providers.

Why does it matter?

The migration highlights how digital sovereignty is increasingly influencing public-sector technology choices, particularly in defence and cybersecurity. By reducing reliance on foreign cloud providers and adopting open-source alternatives, governments seek greater control over sensitive data, software infrastructure and procurement. Switzerland’s move also reflects a broader European trend towards diversifying digital infrastructure and reducing strategic dependence on major US technology companies.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot

Greece launches €10 million call to accelerate municipal digital transformation

The Greek Ministry of Digital Governance and Artificial Intelligence has launched a €10 million funding programme to accelerate digital transformation across 35 municipalities, supporting the modernisation of local public services and digital infrastructure.

Municipalities in Greece will be able to develop and upgrade digital public services, citizen request management platforms and mobile applications. The programme also supports projects in civil protection, crisis management, telemedicine, remote care for vulnerable groups and digital tourism, including interactive maps, virtual and augmented reality applications, and the digitisation of historical and cultural archives.

The programme also places a strong emphasis on cybersecurity, the long-term sustainability of digital services and the resilience of municipal information systems.

According to the ministry, the initiative forms part of Greece’s broader strategy to build more resilient, modern and citizen-centred municipalities by investing in digital infrastructure tailored to local needs.

Why does it matter?

The programme reflects Greece’s continued effort to extend digital transformation beyond central government and strengthen the digital capabilities of local authorities. By investing in public services, cybersecurity, telemedicine and smart city applications, the initiative aims to improve service delivery while supporting more resilient and connected communities.

It also highlights the growing role of municipalities in national digital strategies. As local governments increasingly deliver services through digital platforms, investment in secure infrastructure and modern public administration is becoming an important part of broader digital transformation efforts across Europe.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

EU-Australia Digital Dialogue focuses on AI and online safety

The EU and Australia have reaffirmed their digital partnership during the third EU-Australia Digital Dialogue, advancing cooperation on AI, cybersecurity, digital policy and secure infrastructure.

The online meeting was co-chaired by Renate Nikolay, Deputy Director-General for Communications Networks, Content and Technology at the European Commission, and Helen Wilson, Deputy Secretary of the Science and Technology Group at Australia’s Department of Industry, Science and Resources.

Discussions covered critical technologies, secure connectivity and digital infrastructure, cybersecurity, online safety and data policy. The two sides also exchanged views on their respective priorities for AI infrastructure, AI capabilities and AI safety.

The dialogue also addressed secure international connectivity and the importance of resilient digital infrastructure. Both sides reviewed progress on online safety cooperation, with particular attention to protecting children online.

The EU and Australia agreed to continue discussions across these areas and explore further opportunities for collaboration, including through Australia’s association with the EU’s Horizon Europe research programme.

Why does it matter?

The dialogue reflects the growing strategic importance of digital partnerships between like-minded countries. As AI, cybersecurity, digital infrastructure and data governance become central to economic competitiveness and national security, international cooperation is increasingly focused on aligning policies as well as developing joint research and technology initiatives.

The reference to Horizon Europe also highlights the practical dimension of the partnership. Beyond policy discussions, cooperation could expand into collaborative research, innovation and technology development, strengthening ties between the EU and Australia’s digital ecosystems.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

OECD warns AI could affect trust in official statistics

The OECD has warned that generative AI is changing how people access official statistics, creating new challenges for data quality, context and public trust.

In a blog published by the OECD Centre on Well-being, Inclusion, Sustainability and Equal Opportunity, Romina Boarini and Cameroon Tiati A Biscene argue that citizens, journalists and policymakers increasingly obtain official statistics through chatbots and AI assistants rather than directly from national statistical institutes or government websites.

According to the OECD, this lengthens the chain between data producers and users. As statistics pass through AI systems and other digital intermediaries, important context, including reference periods, revision notes, methodological caveats and source attribution, can be lost.

The blog notes that AI can make official statistics easier to discover and understand, particularly for non-specialist audiences. However, it warns that AI-generated summaries often obscure how information has been selected, interpreted and simplified before reaching users.

The OECD also highlights several data quality risks. AI systems may fail to recognise when official statistics have been revised, corrected or withdrawn, while retrieval quality depends heavily on how well statistical information is structured and machine-readable. Poorly organised data can therefore increase the risk of inaccurate or misleading outputs.

The report also raises concerns about representativeness. General-purpose AI systems are trained on vast amounts of online content, but abundance does not guarantee representative data. As a result, AI-generated or synthetic representations of populations may fail to reflect real-world conditions accurately.

Access is another concern. Although official statistics remain publicly available, meaningful access may increasingly depend on private AI assistants, paid interfaces and concentrated digital infrastructure, potentially making a public good less accessible in practice.

The OECD argues that national statistical institutes may need to expand their role by making datasets more structured and machine-readable, monitoring how statistics are reformulated by AI systems, developing standards for unofficial data sources and preserving the institutional independence that underpins public trust.

Why does it matter?

The OECD’s warning highlights that official statistics can remain accurate at source yet become misleading once AI systems summarise, simplify or detach them from their original context. As more people rely on AI assistants rather than official websites, preserving context and source attribution will become increasingly important for maintaining trust in public data.

The findings also suggest that national statistical institutes will need to adapt to an AI-mediated information environment by designing datasets not only for human users but also for AI systems that increasingly act as intermediaries between governments and the public.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!