France adopts law banning under-15s from social media

France’s parliament has approved legislation that will prohibit children under 15 from accessing social media, making it the first European country to introduce a nationwide ban of this kind. The law, backed by both the National Assembly and the Senate, will be implemented in two phases, with age verification for all new accounts beginning in September 2026 and extending to all existing accounts from January 2027.

Under the new rules, social media platforms will be required to use age verification systems approved by the French data protection authority (CNIL). From January 2027, every user in France will have to verify that they are at least 15 years old to continue accessing social media services.

French Digital Minister Anne Le Hénanff said the timetable is achievable because age verification technologies are already available, while President Emmanuel Macron welcomed the law as a key step in protecting young people online.

The legislation comes as European governments are increasingly considering stricter safeguards for minors’ online activity. The UK plans to prohibit under-16s from accessing social media from January 2027, while the European Commission is examining additional measures to strengthen child protection online. France follows Australia, which introduced a similar ban for under-16s in late 2025, although early evidence suggests many children continue to access social media despite the restrictions.

Privacy advocates and digital rights experts have questioned whether age verification technologies can be implemented without compromising users’ privacy. Others have warned that determined teenagers may circumvent the restrictions or migrate to less regulated online platforms. Experts have also argued that involving young people in designing such policies could improve their effectiveness and reduce unintended consequences, including reduced access to news and civic participation.

Why does it matter?

France’s legislation reflects a growing shift from platform self-regulation towards direct government intervention in protecting children online. Rather than relying primarily on platforms to introduce safety features, lawmakers are increasingly imposing mandatory age verification and restricting access to online services through legislation.

The law also highlights the policy trade-offs at the centre of the online child safety debate. While stronger age assurance measures may reduce children’s exposure to harmful content, they also raise questions about privacy, the proportionality of mandatory identity checks, and the practical effectiveness of enforcing age-based restrictions. As other European countries and the EU consider similar measures, France’s approach is likely to become an important test case for future online safety regulation.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

Meta expands Threads parental controls for teenagers

Meta is expanding parental supervision on Threads with new tools that allow parents and guardians to monitor activity, set screen-time limits and manage privacy settings for teenage users.

The tools will begin rolling out in the United States next week through Meta’s Family Center. They build on the company’s existing Teen Accounts, which provide private profiles and restrictions on potentially sensitive content by default.

Parents will be able to view a teenager’s Threads usage over the previous seven days, including average daily screen time, set daily usage limits and block access during selected hours or days.

The restrictions apply across devices, while supervision also extends to overnight use through sleep mode, which mutes notifications and enables automatic replies between 10 pm and 7 am by default.

Parents can also manage who is allowed to tag teenagers in posts and approve changes to selected privacy and sensitive-content settings.

For users under 16, parents may decide whether default Teen Account protections can be relaxed.

Meta said the expanded supervision tools are intended to provide families with a single place to manage teenage experiences across its apps and that additional features will be introduced over time.

The controls can be activated through Meta’s Family Center once supervision has been established between a parent and teenager.

Why does it matter?

The expanded supervision tools reflect growing pressure on social media platforms to provide parents with greater oversight of children’s online experiences. Features such as screen-time limits, overnight restrictions and stronger privacy controls are increasingly becoming standard expectations rather than optional additions.

The effectiveness of these measures, however, will depend on accurate age verification, teenagers’ ability to circumvent restrictions and the extent to which parental controls are complemented by platform-wide safety measures. The announcement also reflects a wider regulatory trend, with governments increasingly expecting platforms to offer stronger protections for younger users.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

Spanish regulator clarifies GDPR accuracy rules for AI data

The Spanish Data Protection Agency (AEPD) has published guidance examining how data quality relates to the GDPR’s accuracy principle when personal data is processed using AI. The document argues that, although closely linked, data quality is broader than the GDPR’s concept of accuracy because it also applies to non-personal data and encompasses requirements beyond the regulation.

According to the guide, properties such as veracity and currentness should only be required where they are genuinely necessary for the intended purpose.

The AEPD also stresses that non-personal data feeding into processes involving personal data must meet appropriate quality standards whenever it could influence the outcome. Assessing quality should not stop at the input stage: without objective metrics to evaluate the quality of outputs, the guide argues, organisations cannot determine whether a system is fulfilling its intended purpose.

The guidance has particular significance for AI datasets, stating that data which does not meet the required quality standards cannot be considered necessary for processing. Access to such data may therefore only be justified for the purpose of assessing its quality.

Why does it matter?

The guidance addresses a practical challenge that has become increasingly important as AI adoption expands. Organisations need large volumes of data to develop effective systems, while data protection law requires that personal data be limited to what is genuinely necessary. By distinguishing the broader concept of data quality from the GDPR’s narrower accuracy principle, the AEPD provides organisations with a more practical framework for deciding how much veracity, precision or currentness their data actually requires for a given purpose.

The emphasis on evaluating outputs as well as inputs also reflects a broader evolution in AI governance. Rather than treating data protection as a one-off compliance exercise at the point of data collection, the guidance encourages organisations to embed data quality assessment, accountability and multidisciplinary oversight throughout an AI system’s entire life cycle.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot

Zambia and South Sudan tighten cybercrime laws amid free speech concerns

Zambia and South Sudan have stepped up enforcement of cybercrime laws amid concerns over their potential effects on privacy, journalism and freedom of expression.

Zambia’s government has reminded citizens and public officials that the Cyber Crimes Act No. 4 of 2025 remains fully operational, warning against the unauthorised recording and circulation of private communications.

The law, which entered into force in May 2025, makes it an offence to record a private conversation without notifying the participants.

Exceptions include unintentional recordings, certain law-enforcement situations and cases where recording is reasonably necessary to protect the lawful interests of a party to the conversation.

The renewed enforcement focus follows the detention of a Zambian journalist accused of recording and publishing audio from a private meeting. Press freedom advocates argue that the material is a matter of public interest.

South Sudan has meanwhile begun coordinated implementation of its Cybercrime and Computer Misuse Act, 2026, after President Salva Kiir instructed government institutions to enforce the legislation.

Authorities say the law will strengthen cybersecurity, protect critical infrastructure and address offences including hacking, fraud, identity-related crimes and cyber harassment.

Civil society and media rights groups have raised concerns about provisions covering ‘undesirable content’ and ‘false or misleading information’.

Critics warn that broadly worded offences could be used against journalists, political opponents and people expressing legitimate criticism online, particularly without independent oversight and clear enforcement guidelines.

Why does it matter?

The two cases demonstrate the tension between tackling genuine cybercrime and protecting fundamental rights online. Broad offences covering private communications, reputational harm and vaguely defined harmful content may create legal uncertainty for journalists, whistleblowers and ordinary users, especially when enforcement powers lack clear public-interest safeguards and independent oversight.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our chatbot!

Singapore issues personal data guidance for generative AI

Singapore’s Personal Data Protection Commission (PDPC) has issued guidance explaining how organisations should handle personal data throughout the development and deployment of generative AI systems.

Published jointly with the Infocomm Media Development Authority (IMDA), the guidance explains how organisations should comply with the Personal Data Protection Act (PDPA) during the development, deployment and post-deployment use of generative AI.

Developers may rely on the PDPA’s exception for publicly available information when collecting personal data from openly accessible websites. However, information behind paywalls, registration requirements or other digital barriers may not qualify, meaning organisations may need consent or another legal basis for processing.

Where personal data is used to develop AI models, organisations should also provide AI-specific privacy notices explaining why the information is collected, how it will be processed and how individuals can withdraw consent.

The guidance assigns responsibilities across the AI supply chain. Model providers must comply with data retention and protection obligations, while system providers should review security arrangements and communicate safeguards to downstream users.

Organisations deploying AI systems retain primary responsibility for compliance, including defining lawful processing purposes, protecting personal data throughout deployment and regularly reviewing safeguards, particularly for agentic AI applications.

Individuals retain the right to request access to or correction of their personal data after it has been used in AI development. Organisations are expected to establish practical processes for handling such requests, even where training datasets are large or stored differently from conventional databases.

The final guidance reflects feedback from a public consultation involving technology companies, banks, airlines, healthcare organisations and other stakeholders.

Why does it matter?

The guidance clarifies that responsibility for protecting personal data does not disappear as information moves through increasingly complex AI supply chains. By defining the obligations of developers, providers and deployers, Singapore is reinforcing the principle that accountability must accompany every stage of the AI lifecycle.

The document also illustrates how privacy regulation is adapting to generative AI without creating a separate legal regime. Instead, it applies established data protection principles—such as consent, transparency, security and individual rights—to emerging AI technologies, providing organisations with clearer expectations for responsible deployment.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

Kenya restricts presidential website after cybersecurity incident

Kenya temporarily restricted access to the President’s official website after detecting a cybersecurity incident, the Ministry of Information, Communications and the Digital Economy announced.

The ICT Authority activated its established incident response procedures after reports of the attack. Access to the website was restricted as a precaution to support containment, forensic analysis and restoration.

The ministry said mitigation measures had already been implemented and work to restore the website was underway. Officials added that there was no evidence of unauthorised access to sensitive data, data exfiltration or information loss, and that other government systems and digital services remained secure and operational.

The ICT Authority of Kenya is continuing to work with government agencies and technical partners to investigate the incident and determine its full scope and cause.

Why does it matter?

Government websites are high-profile targets because they provide official public information and can influence trust in state institutions even when no sensitive systems are compromised. Temporary restrictions and forensic investigations are standard measures that help contain potential threats while authorities assess the scope of an incident.

The case also highlights the importance of transparent incident reporting. Confirming what was, and was not, affected can help maintain public confidence while allowing investigators time to establish the cause and strengthen future cyber resilience.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

China releases international AI ethics governance action plan

China has released an Action Plan on International Artificial Intelligence Ethics Governance during the 2026 World AI Conference and High-Level Meeting on Global AI Governance in Shanghai, outlining its vision for international AI governance and ethical cooperation.

Issued under the guidance of the Ministry of Industry and Information Technology and relevant partners, the plan seeks to strengthen international cooperation on AI ethics within the framework of the UN Pact for the Future and its Global Digital Compact.

The action plan encourages countries to develop AI governance according to their national circumstances while promoting ethical oversight across the entire AI lifecycle. It advocates risk-based governance, agile regulation, stronger cooperation across AI supply chains and greater international policy coordination based on consultation, joint participation and shared benefits.

China also committed to working with international organisations to implement the plan, expand multilateral cooperation and strengthen dialogue among governments, industry and academia. Particular emphasis is placed on supporting developing countries through capacity building, improving access to AI governance resources and promoting a more inclusive global AI governance ecosystem.

The plan further encourages research and open-source collaboration on AI explainability, privacy protection and bias mitigation. It also calls for integrating AI ethics into education, protecting vulnerable groups, including women, children, older persons and persons with disabilities, and helping narrow the digital divide.

Why does it matter?

The action plan reinforces China’s ambition to play a leading role in shaping international AI governance through multilateral institutions, ethical standards and capacity building. By linking the initiative to the UN Global Digital Compact and the Pact for the Future, Beijing is positioning its governance approach within ongoing global discussions on AI regulation.

The emphasis on flexible national implementation, support for developing countries and open-source collaboration also reflects China’s broader effort to influence how international AI governance evolves, particularly in areas where global rules and standards are still taking shape.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

Researchers demonstrate prompt injection attacks on Gemini

Kaspersky security researchers have demonstrated new attack techniques that could manipulate Google’s Gemini AI assistant into performing unauthorised actions via prompt injection. The study found that malicious instructions hidden in calendar invites, emails or text messages could bypass safeguards by exploiting how large language models process information.

According to the research, attackers could combine indirect prompt injection, memory poisoning and delayed execution to influence Gemini’s behaviour. Potential outcomes include sending emails, launching applications, controlling compatible smart home devices, displaying false information or embedding malicious instructions into the assistant’s long-term memory, provided the user has granted the necessary permissions.

Researchers also warned that smartphones significantly expand the potential attack surface because Gemini can access notifications containing SMS messages, instant messages and social media alerts. Although Google has addressed the specific vulnerabilities identified in the research, the report argues that prompt injection remains a fundamental challenge for AI systems and that new attack methods are likely to emerge.

The researchers recommend reducing Gemini’s access to notifications, connected apps and system functions where possible, turning off unnecessary AI features and limiting permissions to minimise the impact of future attacks. They also advise users to review AI assistant settings regularly as security protections continue to evolve.

Why does it matter?

Prompt injection represents a major challenge for AI security because it targets how large language models interpret and prioritise information. As AI assistants gain broader access to personal data and connected devices, stronger safeguards will be needed to reduce potential risks.

The research highlights the importance of developing more robust AI security frameworks, including improved permission management and continuous testing, to ensure reliable and responsible adoption of AI technologies.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our chatbot!

ONS reports growing concern about AI in Great Britain

Public concern about AI is growing across Great Britain, with more adults believing its risks outweigh its benefits, according to new data from the Office for National Statistics (ONS).

The survey found that 38% of adults believed AI’s risks outweighed its benefits, up from 25% in August 2024. Only 13% said the benefits outweighed the risks, while 43% considered them broadly balanced.

Despite growing concerns, 36% of respondents said AI would benefit them personally, although 27% disagreed, the highest share recorded since the ONS began asking the question in November 2023. Younger adults remained considerably more optimistic than older respondents.

Misinformation, privacy and security emerged as the public’s main concerns. Around 81% of respondents believed AI would make fake information harder to identify, 77% worried personal data could be used without consent and 63% expected greater exposure to cybercrime.

Nearly half of adults under 50 also believed AI could threaten their jobs, while trust remained very low for high-impact uses such as government decision-making (4%) and caregiving (5%).

Public concern contrasted with more limited expectations of personal benefit. While respondents identified education, workplace assistance and household support as AI’s main advantages, 41% said the technology would have no positive impact on their own lives.

Why does it matter?

The findings suggest that public acceptance of AI is becoming a key governance challenge alongside technological development. Growing concerns about misinformation, privacy, cybersecurity and employment could make citizens less willing to embrace AI unless governments and companies demonstrate that effective safeguards are in place.

The survey also highlights a widening gap between rapid AI deployment and public confidence. As AI becomes more deeply integrated into public services and everyday life, trust, transparency and accountability may prove just as important as technical capability in determining how quickly the technology is adopted.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

Germany expands Social Platform into national digital welfare portal

Germany has decided to expand its existing Social Platform into the country’s central digital portal for social services, creating a single entry point for accessing welfare benefits online. The decision was taken by the expert panel on the digitalisation of welfare state reform and builds on infrastructure already developed between 2021 and 2023.

The platform will gradually evolve into a nationwide one-stop shop supporting fully digital benefit applications, processing and notifications. It already provides benefit searches, online applications and advisory services, while integrating with Germany’s National Once-Only Technical System (NOOTS) to retrieve data from public registers.

Secure identification is currently provided through BundID, with support for the future European Digital Identity Wallet (EUDI Wallet) planned.

The initiative also lays the foundation for common data governance across Germany’s social administration. Future work will define shared data standards, interfaces and governance mechanisms while integrating the platform with the planned Deutschland-App. The expert panel overseeing the reform will continue its work until the end of 2027.

The government said the reform is intended to simplify access to social benefits, improve administrative efficiency and modernise employment and social administration through interoperable digital public services.

Why does it matter?

The initiative represents one of Germany’s most significant digital government reforms, replacing fragmented access to welfare services with a common digital platform. By combining shared infrastructure, interoperable data systems and digital identity, the project aims to simplify how citizens interact with public administration while improving efficiency across government.

The integration of NOOTS, BundID and the future EUDI Wallet also aligns Germany’s welfare modernisation with wider European efforts to build interoperable digital public services. The project illustrates how digital identity, data governance and common technical standards are becoming central components of public-sector transformation.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!