UN Global Mechanism on ICT Security shifts from agreements to operational implementation

The UN’s permanent cyber mechanism continued its transition from developing policy frameworks to implementing them, with member states focusing on practical measures to operationalise confidence-building measures (CBMs), strengthen cyber capacity, and ensure agreed commitments can function effectively during real-world cyber incidents.

During the seventh substantive plenary meeting of the Global Mechanism on ICT Security, delegations concentrated on translating previous political agreements into operational tools. Discussions centred on the Global Points of Contact (POC) Directory, the role of the Dedicated Thematic Groups (DTGs), regional cooperation, and capacity development as the foundation for responsible state behaviour in cyberspace.

Across regional groups, delegates broadly agreed that implementation has become the mechanism’s principal challenge, particularly for developing countries and small island developing states with limited technical and institutional resources.

States seek to operationalise cyber confidence-building measures

Delegations reaffirmed that confidence-building measures are intended to reduce misunderstandings, improve communication, and lower the risk of escalation before cyber incidents develop into political crises.

The Global Points of Contact Directory was widely described as the most tangible achievement inherited from the previous Open-ended Working Group (OEWG). However, speakers stressed that its success depends not simply on the number of participating states, but on regular testing, timely responses, and practical use during incidents.

Several delegations emphasised that the directory should complement, not replace, existing diplomatic, technical, and regional communication channels, while remaining proportionate to the capacities of smaller administrations.

Practical experience shapes future cooperation

Rather than proposing new confidence-building measures, many countries shared lessons from real cyber incidents.

Tonga highlighted cooperation following a cyberattack on its national health system, explaining that trusted regional relationships enabled rapid assistance and coordinated public attribution. Vanuatu similarly argued that confidence is built through predictable cooperation and routine communication rather than by creating additional mechanisms or reporting requirements.

The Dominican Republic also distinguished between confidence-building measures and operational incident response, noting that CBMs create the trust necessary for rapid technical cooperation but are not themselves emergency response mechanisms.

Dedicated Thematic Groups become implementation platform

Many delegations identified the Dedicated Thematic Groups as the mechanism’s primary vehicle for turning agreed commitments into practical action.

Countries proposed that the DTGs facilitate exchanges of national experience, scenario-based exercises, practical guidance, and technical recommendations while avoiding duplication of plenary negotiations. Regional organisations were likewise encouraged to share their implementation experience so that successful practices could inform global discussions.

Simulation exercises, regular communication checks, and joint training activities were repeatedly highlighted as practical ways to ensure confidence-building measures function effectively before crises occur.

Capacity development recognised as the foundation

The second half of the session focused on capacity building, which delegations consistently described as underpinning every pillar of the UN cyber framework.

The Pacific Islands Forum, the African Group, the European Union, CARICOM, and a Latin American coalition argued that countries cannot effectively implement voluntary norms, apply international law, or participate in confidence-building measures without sufficient legal, institutional, and technical capacity. Several speakers proposed expanding international support through fellowship programmes, a voluntary UN ICT Security Capacity Building Fund, stronger national computer emergency response teams (CERTs), and a Global ICT Security Cooperation and Capacity Building Portal.

Delegations also stressed that future capacity-building efforts should remain demand-driven, nationally owned, and adapted to local priorities while avoiding duplication of existing initiatives.

Ensuring no country is left behind

Throughout the discussion, developing countries and small island developing states emphasised that practical implementation must take account of widely differing national capacities.

Several delegations called for greater inclusion of regional organisations, civil society, academia, the private sector, and youth in implementation efforts, arguing that broad participation will be essential if the mechanism is to deliver practical improvements in global cybersecurity.

Closing the session, Chair Egriselda LĂłpez noted the broad support for translating agreed confidence-building measures into practical implementation and confirmed that discussions on capacity development would continue during the afternoon session.

Track all key moments from the First substantive session of the UN Global Mechanism on cybersecurity on our dedicated page.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

India strengthens national 6G strategy through industry alliance

India is strengthening its national 6G strategy through closer cooperation between government, industry and academia, with the Bharat 6G Alliance expanding to 90 members and advancing work on spectrum planning, research and international standards.

The Alliance brings together telecom operators, equipment manufacturers, start-ups, research institutions and universities, and has established seven working groups covering areas such as 6G technologies, spectrum, applications, devices and sustainability. It aims to strengthen domestic research, innovation and intellectual property through industry-academia collaboration and the development of testbeds.

The Alliance’s spectrum working group has published a Spectrum Roadmap for 6G in India, while the Department of Telecommunications has released its own roadmap following consultations with stakeholders, including the Bharat 6G Alliance.

India is also investing in research infrastructure. A three-year project supported by the Telecom Technology Development Fund will establish a 6G Terahertz testbed at the Society for Applied Microwave Electronics Engineering & Research (SAMEER) in collaboration with the Indian Institutes of Technology in Madras, Guwahati and Patna. A high-data-rate line-of-sight link developed through the project was demonstrated at the India Mobile Congress 2025.

India has also contributed to the International Telecommunication Union’s IMT-2030 framework, advocating the inclusion of ubiquitous connectivity among the framework’s usage scenarios alongside coverage, interoperability and sustainability.

Why does it matter?

India’s latest initiatives illustrate how countries are beginning to compete not only in deploying future mobile networks but also in shaping the technologies and standards that underpin them. By combining spectrum planning, research funding, industry collaboration and international standardisation, governments are increasingly treating 6G as a strategic technology rather than simply the next generation of telecommunications.

The emphasis on domestic research, testbeds and intellectual property also reflects a broader ambition to strengthen technological sovereignty. Active participation in global standard-setting bodies such as the ITU could allow India to influence future 6G specifications while supporting the competitiveness of its domestic telecom ecosystem.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot

Microsoft gives communities greater control over AI image training

Microsoft has developed a research tool that allows communities to help shape how they are represented in AI-generated images, addressing long-standing concerns that AI training data often reflects incomplete or biased online content rather than the perspectives of the people depicted.

Instead of relying solely on existing online datasets, communities, including people with disabilities and others with shared lived experiences, can work through advocacy organisations to create their own image and video libraries. Each image is accompanied by descriptions explaining what is important about the scene, giving AI systems contextual information based on the community’s own perspective rather than visual appearance alone.

Developed by Microsoft’s Accessibility Team, the process guides participants from selecting meaningful images to curating a library of around 400 real-world examples organised around shared themes such as family life and everyday routines. These annotated collections are then used to generate AI images, which community members review and evaluate against their own standards of accurate representation, creating a feedback loop intended to improve future outputs.

A central feature of the project is that advocacy organisations retain ownership of the resulting datasets and decide whether, how and with whom they are shared, including publication on platforms such as Hugging Face. Communities can also withdraw their data if consent changes over time.

Why does it matter?

The project addresses one of the central challenges in AI governance: who decides how people and communities are represented in training data. Many AI systems are built using large-scale datasets collected from the internet with limited transparency, consent or community involvement, increasing the risk of inaccurate, stereotypical or exclusionary outputs.

By giving communities ownership of their data and a direct role in defining what constitutes fair representation, Microsoft’s approach shifts part of the AI development process towards participatory governance. If adopted more widely, it could provide a model for building datasets that are not only more representative but also more transparent, accountable and consent-based.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot

EU-funded project advances multilingual AI for public-interest media

The EU-funded MOSAIC pilot project has demonstrated how AI can help make public-interest media accessible across languages while allowing broadcasters to retain control over their own content, supporting the EU’s broader vision of a multilingual digital public sphere.

Over 18 months, an 11-partner European consortium developed and tested a federated architecture enabling media organisations to share and enrich content without giving up ownership.

The project delivered AI-powered transcription, translation and subtitling across eight languages, including under-resourced languages such as Catalan, Slovenian and Estonian, alongside multimodal archive search and automated metadata enrichment. Pilots involved public and private broadcasters in six EU member states.

The results support the objectives of the European Democracy Shield and the Apply AI Strategy’s Media Flagship, while informing the next phase of the European TV and Video News Portal, a citizen-facing service intended to improve multilingual access to trusted news and public-interest information.

Building on the pilot, the consortium identified four priorities for future work, such as developing services around the needs of citizens, journalists and broadcasters; embedding editorial standards, transparent provenance and quality safeguards; and connecting future initiatives with complementary projects such as ChatEurope and the European Language Data Space.

Why does it matter?

MOSAIC illustrates how AI can support a more integrated European information space by reducing language barriers without requiring media organisations to centralise or surrender control over their content. The project’s federated approach demonstrates that multilingual access can be expanded while preserving editorial independence, data ownership and institutional autonomy.

The initiative also reflects a broader EU strategy of treating trusted media infrastructure as part of digital public infrastructure. By linking AI-powered language technologies with media pluralism, transparency and shared governance, MOSAIC provides a model for strengthening access to reliable information while supporting Europe’s linguistic diversity and democratic resilience.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot

EU launches generative AI pilots for public administrations

Three new pilot projects supporting the adoption of generative AI in European public administrations have officially begun under the Digital Europe Programme, marking another step in the European Commission’s efforts to bring trustworthy AI into everyday government services.

The projects, FLOODS & DROUGHTS, EUNOMIA.AI and EuropAI, will develop and test trustworthy generative AI solutions designed to improve public services while addressing practical challenges faced by public authorities.

Participating public administrations will procure, test and deploy AI solutions tailored to their operational needs through direct procurement. The pilots are expected to support decision-making, administrative efficiency, accessibility and simpler public services while ensuring compliance with legal, operational and societal requirements.

The initiative contributes to the European Commission’s Apply AI Strategy, which seeks to accelerate responsible AI adoption across strategic sectors, including public administration. By bringing together governments, research organisations and technology providers, the projects aim to develop interoperable AI solutions whose methodologies and implementation models can be replicated across the EU.

The Commission said participating administrations will play a central role in shaping these systems through procurement, testing and deployment, supporting wider adoption across Member States.

Why does it matter?

The pilots illustrate how the EU is moving from developing AI rules to creating practical mechanisms for deploying trustworthy AI in the public sector. Rather than limiting its role to regulation, the European Commission is increasingly using public procurement to encourage the development of AI systems that meet European standards for transparency, interoperability and legal compliance.

If successful, the projects could provide reusable models for public administrations across the EU, reducing duplication while accelerating digital transformation. They also demonstrate how governments can influence the AI market by acting not only as regulators but also as major customers for trustworthy AI solutions.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!  

UN Global Mechanism on ICT Security highlights growing role of stakeholders

The UN’s permanent cyber mechanism devoted a full session to accredited stakeholders, with technical organisations, civil society groups, humanitarian actors, and youth representatives calling for greater participation in shaping international cybersecurity cooperation and urging member states to make stakeholder engagement a practical part of implementing the UN cyber framework.

The sixth meeting of the first substantive plenary session of the Global Mechanism on ICTs in the Context of International Security combined stakeholder interventions with discussions on international law and confidence-building measures (CBMs). Throughout the day, speakers argued that responsible state behaviour in cyberspace increasingly depends on close cooperation with the technical community, researchers, industry, humanitarian organisations, and civil society.

A recurring concern was the exclusion of more than 60 accredited organisations from formal participation. Multiple stakeholders called on member states to adopt transparent, criteria-based accreditation procedures, arguing that meaningful implementation of the UN cyber framework requires inclusive multistakeholder participation.

Technical community highlights operational expertise

Several organisations emphasised that many of the practical tools needed to strengthen cybersecurity already exist outside governments.

ICANN outlined its work on strengthening the resilience of the internet’s domain name system, while the Internet Society highlighted initiatives supporting routing security, internet exchange points, and critical cybersecurity infrastructure. FIRST, representing hundreds of incident response teams worldwide, stressed the importance of international cooperation among technical responders, responsible vulnerability disclosure, and operational collaboration during cyber incidents.

Other stakeholders focused on implementation challenges. Chatham House argued that practical guidance alone is insufficient unless states also possess the institutional capacity to apply it, while Developing Capacity LTD highlighted existing resources and cyber capacity-building initiatives that could support the work of the Dedicated Thematic Groups (DTGs).

Youth, civil society and humanitarian perspectives

The Discover MUN Foundation, speaking on behalf of the UN Major Group for Children and Youth, called for age-disaggregated data on malicious cyber activity, dedicated youth capacity-building initiatives, and recognition of youth engagement itself as a confidence-building measure.

Human rights organisations drew attention to the disproportionate impact of cyber threats on vulnerable communities, while Access Now highlighted the growing number of internet shutdowns during armed conflicts and called for greater attention to the human consequences of cyber operations. The Centre for Humanitarian Dialogue introduced another emerging issue by encouraging states to begin developing confidence-building measures specifically for post-conflict cyber environments.

States back stronger cooperation with stakeholders

During the interactive dialogue, several member states acknowledged the value of stakeholder expertise.

Canada, the European Union, Japan, Chile, Germany, and Mexico encouraged stronger collaboration with technical organisations, academia, and civil society, particularly within the DTGs. Delegations also criticised the exclusion of numerous accredited organisations, arguing that broader participation would strengthen implementation of the UN framework rather than complicate negotiations.

Stakeholders responded by offering practical implementation resources, including policy guidance, technical expertise, training programmes, capacity-building platforms, and operational tools that could support future work under the Global Mechanism.

International law discussions remain implementation-focused

The session also continued discussions on the application of international law to cyberspace.

Switzerland and Australia argued that the mechanism should build on existing areas of legal convergence by examining practical cyber scenarios through the DTGs. The International Committee of the Red Cross called for greater attention to how international humanitarian law protects civilian infrastructure and addresses emerging technologies such as AI in armed conflict.

While Algeria and Nicaragua continued to support the eventual development of legally binding international instruments, the United States maintained that existing international law remains sufficient and that discussions should focus on implementation rather than negotiating new treaties.

Confidence-building measures move towards implementation

The final part of the session focused on operationalising the confidence-building measures agreed during the previous UN Open-ended Working Group.

Many delegations identified the Global Points of Contact Directory as one of the mechanisms’ most practical achievements, describing it as an important tool for crisis communication and incident response. Small island developing states, including Kiribati and Nauru, emphasised that reliable communication channels are essential for countries with limited diplomatic and technical resources.

Regional initiatives such as the Pacific Cybersecurity Operational Network were repeatedly cited as examples of how regular cooperation, information sharing, and practical exercises can build trust before cyber incidents occur.

Closing the meeting, the Chair thanked both member states and stakeholders for their extensive contributions and noted that discussions on confidence-building measures would continue the following day.

Track all key moments from the First substantive session of the UN Global Mechanism on cybersecurity on our dedicated page.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

UN Global Mechanism on ICT security shifts focus to implementing international law in cyberspace

The UN’s permanent cyber mechanism continued its substantive work by focusing on how international law should be applied in cyberspace, with member states broadly agreeing that the priority is no longer whether international law applies, but how to translate that consensus into practical implementation.

During the fifth substantive plenary session of the Global Mechanism on Developments in the Field of ICTs in the Context of International Security, delegations reaffirmed that international law, including the UN Charter, applies to state conduct in cyberspace. Discussions instead centred on deepening common understanding through scenario-based exchanges, legal capacity development, and practical implementation within the mechanism’s Dedicated Thematic Groups (DTGs).

While some states continued to advocate for new legally binding international instruments, the prevailing view was that the immediate priority should be strengthening the implementation of the existing legal framework and helping all countries participate meaningfully in its development.

From legal principle to practical application

A broad cross-regional coalition led by Switzerland argued that the mechanism should focus on clarifying how international law applies in practice rather than revisiting questions already settled through previous UN processes.

The group identified five priority areas for future discussions, such as sovereignty and non-intervention, state responsibility and due diligence, the prohibition of the use of force and self-defence, international humanitarian law (IHL), and international human rights law. It also encouraged scenario-based discussions examining issues such as cyber operations targeting hospitals, water systems, and energy infrastructure.

The Pacific Islands Forum, represented by Tonga, similarly reaffirmed that international law applies to cyberspace while stressing that legal capacity development should become a cross-cutting priority before discussions turn to new legally binding obligations. The Forum proposed regional workshops, peer exchanges, expert briefings, and practical exercises to help states develop national legal positions.

Practical implementation takes centre stage

The European Union, Australia and several cross-regional coalitions argued that the mechanism should build on the work already undertaken through successive UN Groups of Governmental Experts (GGEs) and Open-ended Working Groups (OEWGs).

Delegations highlighted the growing number of national and regional statements explaining how countries interpret the application of international law in cyberspace, describing these as important confidence-building measures that improve transparency and reduce the risk of misunderstanding.

Many speakers also identified the DTGs as the most appropriate venue for examining practical legal questions through realistic case studies, expert briefings, and exchanges of national experience.

Legal capacity emerges as a central issue

One of the session’s strongest themes was the need to ensure that all states can participate effectively in discussions on international law.

Kiribati offered a particularly candid account of the resource constraints facing many small developing countries, explaining that international law represents their principal means of protection despite having limited legal and technical capacity.

The delegation argued that legal capacity building is not a secondary issue but a prerequisite for meaningful participation, advocating practical, scenario-based exercises to help governments translate legal principles into operational understanding.

This emphasis was echoed by the African Group, Mauritius, Malawi, Singapore, Botswana, Vanuatu, and many other delegations, which called for tailored capacity-building programmes, regional cooperation, and support for the development of national positions on international law.

International humanitarian law remains an important focus

The applicability of international humanitarian law to cyber operations featured prominently throughout the debate.

Numerous delegations argued that recognising IHL in cyberspace does not legitimise cyberwarfare or militarise cyberspace, but instead ensures that civilians and protected infrastructure continue to benefit from established legal protections during armed conflict.

Several countries nevertheless argued that cyberspace presents unique legal challenges requiring greater caution or the future development of additional international rules, reflecting one of the principal areas of continuing disagreement.

Diverging views on future legal instruments

Although there was broad agreement on the applicability of international law, member states remained divided over whether additional legally binding instruments were needed.

Russia, China, Iran, Cuba, and Venezuela argued that the distinctive characteristics of cyberspace justify the development of new international legal frameworks alongside existing commitments. By contrast, a larger group of states, including the European Union, the Pacific Islands Forum, the Republic of Korea, Canada, Ireland, France, and New Zealand, maintained that existing international law provides an adequate foundation, with efforts better directed towards improving common understanding and implementation.

Despite these differences, the discussion revealed broad convergence around the practical direction of the Global Mechanism. Delegations consistently supported greater transparency through national legal positions, stronger legal capacity development, and scenario-based discussions that enable governments to apply international law to real-world cyber incidents.

As the session concluded, the Chair confirmed that discussions on international law would continue before the mechanism moved to its next agenda item on confidence-building measures.

Track all key moments from the First substantive session of the UN Global Mechanism on cybersecurity on our dedicated page.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

China launches zero-carbon factory programme for industry and computing

China has launched a nationwide programme to establish national-level zero-carbon factories, extending its industrial decarbonisation strategy to both manufacturing and computing facilities as part of its broader climate and digital development agenda.

According to the Ministry of Industry and Information Technology (MIIT), the initiative will encourage manufacturers and computing facilities to reduce carbon dioxide emissions within their operations to near-zero levels through technological innovation, structural optimisation and improved management.

The programme in China will select manufacturing facilities and computing centres with strong low-carbon foundations, credible decarbonisation roadmaps and a commitment to meeting the programme’s targets within a defined timeframe. Participating organisations will implement measures including process decarbonisation, smart carbon management, carbon offsetting and transparent emissions reporting.

To support implementation, MIIT has introduced a trial evaluation framework setting out core requirements and guiding indicators for participating organisations. Rather than relying on one-off certification, the programme emphasises continuous emissions reductions supported by regular inspections and formal evaluations before facilities can be recognised as national-level zero-carbon factories.

The initiative supports China’s broader climate goals of peaking carbon dioxide emissions before 2030 and achieving carbon neutrality before 2060.

By explicitly including computing facilities alongside traditional manufacturing, it also acknowledges the growing environmental impact of digital infrastructure and AI-related computing.

Why does it matter?

The programme illustrates how climate policy is increasingly extending beyond traditional heavy industry to include digital infrastructure. As demand for AI, cloud computing and data centres continues to grow, governments are beginning to treat computing facilities as strategic assets whose environmental performance must be managed alongside economic development.

The emphasis on continuous monitoring and measurable emissions reductions also reflects a broader shift towards outcome-based industrial policy. Rather than rewarding one-time compliance, China’s framework seeks to embed ongoing carbon management into industrial operations, offering a model that could influence how other countries approach decarbonisation in manufacturing and digital infrastructure.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot

NVIDIA launches AI video detector with 92% accuracy

NVIDIA has introduced Synthetic Video Detector, an AI-powered microservice designed to help media organisations identify potentially AI-generated video.

The system analyses footage frame by frame and produces a probability score indicating whether it contains synthetic content.

Editorial teams can use the result to prioritise clips for review, quarantine suspicious footage or escalate it for more detailed verification.

NVIDIA said the tool is intended to supplement established fact-checking and forensic practices rather than determine authenticity on its own.

In company testing, the detector achieved up to 92% accuracy on uncompressed video. Accuracy declined to 87% at 15% compression and 82% at 50% compression.

The system can process 1080p video in as little as 22 milliseconds on NVIDIA RTX systems and around 30 milliseconds on NVIDIA L40 GPUs.

Its architecture uses an ensemble of DINOv2 and DINOv3 vision transformer backbones and focuses on artefacts introduced by generative video systems.

Synthetic Video Detector forms part of the NVIDIA AI for Media platform and can be deployed in on-premises, edge, hybrid and approved air-gapped environments.

NVIDIA said the flexible deployment options could help broadcasters, government agencies and other organisations analyse sensitive footage while retaining control over their data.

Why does it matter?

Synthetic video is becoming harder to identify during fast-moving news events, increasing pressure on media organisations to verify footage before publication. NVIDIA’s detector could provide an additional screening signal and help editorial teams focus limited verification resources. Still, its declining performance on compressed material shows why automated detection cannot replace source checks, forensic analysis and human judgement.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our chatbot!

Google launches Gemini 3.6 Flash for more efficient AI agents

Google has launched Gemini 3.6 Flash, describing it as a faster and more efficient model for developers building AI agents, coding tools and enterprise workflows while reducing the cost of deploying AI at scale.

According to Google, the model uses 17% fewer output tokens than Gemini 3.5 Flash on the Artificial Analysis Index and requires fewer reasoning steps and tool calls for multi-stage tasks, reducing the cost of running production AI agents.

Google has priced Gemini 3.6 Flash at US$1.50 per million input tokens and US$7.50 per million output tokens. The company says it improves coding, computer use, document analysis, chart interpretation and report drafting while reducing unnecessary edits and execution loops.

The company also reported gains on benchmarks including DeepSWE and OSWorld-Verified, alongside stronger safeguards against cyber-offence and chemical, biological, radiological and nuclear misuse.

Google also introduced Gemini 3.5 Flash-Lite, its fastest and lowest-cost model in the 3.5 family, targeting high-volume workloads such as search, document processing and data extraction.

In addition, a specialised Gemini 3.5 Flash Cyber model will power Google’s CodeMender security agent to detect, validate and patch software vulnerabilities. Owing to its potential for misuse, access will initially be restricted to governments and trusted partners through a pilot programme.

Gemini 3.6 Flash and Flash-Lite are available through the Gemini API, Google AI Studio, Android Studio, Gemini Enterprise and the Gemini app, with Flash-Lite also rolling out in Google Search.

Google said Gemini 3.5 Pro remains in partner testing while work is already underway on what it describes as its most ambitious pre-training run yet for Gemini 4.

Why does it matter?

The launch reflects a broader shift in AI development from simply increasing model size towards improving efficiency, reliability and cost-effectiveness for real-world deployment. As AI agents become more widely adopted, reducing inference costs and improving task execution are becoming increasingly important competitive advantages.

The restricted release of Gemini’s cybersecurity model also illustrates how AI developers are adopting more differentiated access policies for high-risk capabilities. Rather than making every model broadly available, companies are increasingly limiting advanced cyber tools to trusted users while attempting to balance defensive benefits with concerns about misuse.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!