Singapore issues personal data guidance for generative AI

Singapore’s Personal Data Protection Commission (PDPC) has issued guidance explaining how organisations should handle personal data throughout the development and deployment of generative AI systems.

Published jointly with the Infocomm Media Development Authority (IMDA), the guidance explains how organisations should comply with the Personal Data Protection Act (PDPA) during the development, deployment and post-deployment use of generative AI.

Developers may rely on the PDPA’s exception for publicly available information when collecting personal data from openly accessible websites. However, information behind paywalls, registration requirements or other digital barriers may not qualify, meaning organisations may need consent or another legal basis for processing.

Where personal data is used to develop AI models, organisations should also provide AI-specific privacy notices explaining why the information is collected, how it will be processed and how individuals can withdraw consent.

The guidance assigns responsibilities across the AI supply chain. Model providers must comply with data retention and protection obligations, while system providers should review security arrangements and communicate safeguards to downstream users.

Organisations deploying AI systems retain primary responsibility for compliance, including defining lawful processing purposes, protecting personal data throughout deployment and regularly reviewing safeguards, particularly for agentic AI applications.

Individuals retain the right to request access to or correction of their personal data after it has been used in AI development. Organisations are expected to establish practical processes for handling such requests, even where training datasets are large or stored differently from conventional databases.

The final guidance reflects feedback from a public consultation involving technology companies, banks, airlines, healthcare organisations and other stakeholders.

Why does it matter?

The guidance clarifies that responsibility for protecting personal data does not disappear as information moves through increasingly complex AI supply chains. By defining the obligations of developers, providers and deployers, Singapore is reinforcing the principle that accountability must accompany every stage of the AI lifecycle.

The document also illustrates how privacy regulation is adapting to generative AI without creating a separate legal regime. Instead, it applies established data protection principles—such as consent, transparency, security and individual rights—to emerging AI technologies, providing organisations with clearer expectations for responsible deployment.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

Kenya restricts presidential website after cybersecurity incident

Kenya temporarily restricted access to the President’s official website after detecting a cybersecurity incident, the Ministry of Information, Communications and the Digital Economy announced.

The ICT Authority activated its established incident response procedures after reports of the attack. Access to the website was restricted as a precaution to support containment, forensic analysis and restoration.

The ministry said mitigation measures had already been implemented and work to restore the website was underway. Officials added that there was no evidence of unauthorised access to sensitive data, data exfiltration or information loss, and that other government systems and digital services remained secure and operational.

The ICT Authority of Kenya is continuing to work with government agencies and technical partners to investigate the incident and determine its full scope and cause.

Why does it matter?

Government websites are high-profile targets because they provide official public information and can influence trust in state institutions even when no sensitive systems are compromised. Temporary restrictions and forensic investigations are standard measures that help contain potential threats while authorities assess the scope of an incident.

The case also highlights the importance of transparent incident reporting. Confirming what was, and was not, affected can help maintain public confidence while allowing investigators time to establish the cause and strengthen future cyber resilience.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

China releases international AI ethics governance action plan

China has released an Action Plan on International Artificial Intelligence Ethics Governance during the 2026 World AI Conference and High-Level Meeting on Global AI Governance in Shanghai, outlining its vision for international AI governance and ethical cooperation.

Issued under the guidance of the Ministry of Industry and Information Technology and relevant partners, the plan seeks to strengthen international cooperation on AI ethics within the framework of the UN Pact for the Future and its Global Digital Compact.

The action plan encourages countries to develop AI governance according to their national circumstances while promoting ethical oversight across the entire AI lifecycle. It advocates risk-based governance, agile regulation, stronger cooperation across AI supply chains and greater international policy coordination based on consultation, joint participation and shared benefits.

China also committed to working with international organisations to implement the plan, expand multilateral cooperation and strengthen dialogue among governments, industry and academia. Particular emphasis is placed on supporting developing countries through capacity building, improving access to AI governance resources and promoting a more inclusive global AI governance ecosystem.

The plan further encourages research and open-source collaboration on AI explainability, privacy protection and bias mitigation. It also calls for integrating AI ethics into education, protecting vulnerable groups, including women, children, older persons and persons with disabilities, and helping narrow the digital divide.

Why does it matter?

The action plan reinforces China’s ambition to play a leading role in shaping international AI governance through multilateral institutions, ethical standards and capacity building. By linking the initiative to the UN Global Digital Compact and the Pact for the Future, Beijing is positioning its governance approach within ongoing global discussions on AI regulation.

The emphasis on flexible national implementation, support for developing countries and open-source collaboration also reflects China’s broader effort to influence how international AI governance evolves, particularly in areas where global rules and standards are still taking shape.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

Researchers demonstrate prompt injection attacks on Gemini

Kaspersky security researchers have demonstrated new attack techniques that could manipulate Google’s Gemini AI assistant into performing unauthorised actions via prompt injection. The study found that malicious instructions hidden in calendar invites, emails or text messages could bypass safeguards by exploiting how large language models process information.

According to the research, attackers could combine indirect prompt injection, memory poisoning and delayed execution to influence Gemini’s behaviour. Potential outcomes include sending emails, launching applications, controlling compatible smart home devices, displaying false information or embedding malicious instructions into the assistant’s long-term memory, provided the user has granted the necessary permissions.

Researchers also warned that smartphones significantly expand the potential attack surface because Gemini can access notifications containing SMS messages, instant messages and social media alerts. Although Google has addressed the specific vulnerabilities identified in the research, the report argues that prompt injection remains a fundamental challenge for AI systems and that new attack methods are likely to emerge.

The researchers recommend reducing Gemini’s access to notifications, connected apps and system functions where possible, turning off unnecessary AI features and limiting permissions to minimise the impact of future attacks. They also advise users to review AI assistant settings regularly as security protections continue to evolve.

Why does it matter?

Prompt injection represents a major challenge for AI security because it targets how large language models interpret and prioritise information. As AI assistants gain broader access to personal data and connected devices, stronger safeguards will be needed to reduce potential risks.

The research highlights the importance of developing more robust AI security frameworks, including improved permission management and continuous testing, to ensure reliable and responsible adoption of AI technologies.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our chatbot!

ONS reports growing concern about AI in Great Britain

Public concern about AI is growing across Great Britain, with more adults believing its risks outweigh its benefits, according to new data from the Office for National Statistics (ONS).

The survey found that 38% of adults believed AI’s risks outweighed its benefits, up from 25% in August 2024. Only 13% said the benefits outweighed the risks, while 43% considered them broadly balanced.

Despite growing concerns, 36% of respondents said AI would benefit them personally, although 27% disagreed, the highest share recorded since the ONS began asking the question in November 2023. Younger adults remained considerably more optimistic than older respondents.

Misinformation, privacy and security emerged as the public’s main concerns. Around 81% of respondents believed AI would make fake information harder to identify, 77% worried personal data could be used without consent and 63% expected greater exposure to cybercrime.

Nearly half of adults under 50 also believed AI could threaten their jobs, while trust remained very low for high-impact uses such as government decision-making (4%) and caregiving (5%).

Public concern contrasted with more limited expectations of personal benefit. While respondents identified education, workplace assistance and household support as AI’s main advantages, 41% said the technology would have no positive impact on their own lives.

Why does it matter?

The findings suggest that public acceptance of AI is becoming a key governance challenge alongside technological development. Growing concerns about misinformation, privacy, cybersecurity and employment could make citizens less willing to embrace AI unless governments and companies demonstrate that effective safeguards are in place.

The survey also highlights a widening gap between rapid AI deployment and public confidence. As AI becomes more deeply integrated into public services and everyday life, trust, transparency and accountability may prove just as important as technical capability in determining how quickly the technology is adopted.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

Germany expands Social Platform into national digital welfare portal

Germany has decided to expand its existing Social Platform into the country’s central digital portal for social services, creating a single entry point for accessing welfare benefits online. The decision was taken by the expert panel on the digitalisation of welfare state reform and builds on infrastructure already developed between 2021 and 2023.

The platform will gradually evolve into a nationwide one-stop shop supporting fully digital benefit applications, processing and notifications. It already provides benefit searches, online applications and advisory services, while integrating with Germany’s National Once-Only Technical System (NOOTS) to retrieve data from public registers.

Secure identification is currently provided through BundID, with support for the future European Digital Identity Wallet (EUDI Wallet) planned.

The initiative also lays the foundation for common data governance across Germany’s social administration. Future work will define shared data standards, interfaces and governance mechanisms while integrating the platform with the planned Deutschland-App. The expert panel overseeing the reform will continue its work until the end of 2027.

The government said the reform is intended to simplify access to social benefits, improve administrative efficiency and modernise employment and social administration through interoperable digital public services.

Why does it matter?

The initiative represents one of Germany’s most significant digital government reforms, replacing fragmented access to welfare services with a common digital platform. By combining shared infrastructure, interoperable data systems and digital identity, the project aims to simplify how citizens interact with public administration while improving efficiency across government.

The integration of NOOTS, BundID and the future EUDI Wallet also aligns Germany’s welfare modernisation with wider European efforts to build interoperable digital public services. The project illustrates how digital identity, data governance and common technical standards are becoming central components of public-sector transformation.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

EU orders Google to open Android AI features

The European Commission has issued two sets of binding measures under the Digital Markets Act requiring Google to improve competition in AI assistants and online search.

The first decision requires Google to give competing AI services access to 11 key Android features on terms equivalent to those available to its own services, including Gemini.

Users will be able to activate their preferred AI assistant via voice commands and have it to perform tasks across apps, such as sending messages, booking services, or retrieving contextual information.

Alternative providers will also gain access to features covering device context, background execution, on-device models, system integration and automated actions, subject to user consent and security safeguards.

Google must implement most of the measures in Android 18 and no later than 1 August 2027. Concurrent voice activation for multiple AI assistants must be introduced with Android 19 by August 2028.

The second decision requires Google to share anonymised search data with eligible third-party search engines, including AI chatbots that provide online search functions.

The data may include queries, rankings, clicks and views that Google uses to improve its own search service. Recipients may use it to develop search technology, improve retrieval and ground AI-generated answers in current online information.

The measures do not require Google to share its search algorithms, and recipients cannot use the data to train general-purpose AI models or for advertising and consumer profiling.

Google must also establish a transparent application process and a pricing model based primarily on the costs of providing access.

The Commission said the measures are intended to expand consumer choice and prevent Google’s advantages in Android and search from limiting competition in AI services.

Why does it matter?

The decisions apply established DMA interoperability and data-access rules directly to the emerging AI market. Rival assistants could gain deeper access to Android, while search providers and AI chatbots may use Google’s data to improve retrieval and compete more effectively. The measures could lower barriers created by control over operating systems and search data, although implementation will require careful protection of privacy, cybersecurity and commercially sensitive information.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our chatbot!

UK publishes government data breach response framework

The UK government has published a Model Action Plan establishing a coordinated approach for responding to significant personal data breaches across government departments and arm’s-length bodies.

The plan prioritises the wellbeing, privacy, safety and legal rights of people affected by personal data breaches. It also introduces mandatory central reporting to help identify systemic weaknesses, analyse incident trends and share lessons across government.

A breach may be considered significant if it creates a risk of serious harm to large numbers of people, affects vulnerable or high-profile individuals, threatens national security or critical infrastructure, involves multiple organisations, or could cause major financial, operational or reputational damage.

The framework is organised into four response phases, beginning with preparation before an incident occurs. Organisations are expected to maintain response plans, clear escalation procedures, information asset registers and defined responsibilities, while ensuring suppliers report suspected breaches within 12 to 24 hours. Departments should also prepare alternative communication channels, notification templates and evidence preservation procedures.

The government recommends regular testing of response plans, including annual tabletop exercises, to ensure organisations can make timely decisions and meet the statutory 72-hour reporting deadline.

During the first 24 hours after identifying a significant breach, organisations should contain the incident, assess its severity and escalate it internally. Where the significance threshold is met, departments must activate crisis response arrangements and appoint a senior incident manager.

Breaches meeting the statutory threshold must be reported to the Information Commissioner’s Office within 72 hours, with the government stressing that an incomplete report submitted on time is preferable to a complete report filed late.

Departments must also notify relevant government bodies, including the Government Security Group, the Government Data Protection team and, where appropriate, the Government Cyber Coordination Centre and National Cyber Security Centre.

Significant incidents reported to the ICO must also be reported centrally to support government-wide analysis and annual public reporting.

Where a breach poses a high risk to individuals, affected people should generally be informed directly and told what happened, the likely consequences and available support. The guidance stresses that protecting affected individuals should take priority over limiting reputational damage and notes that organisations may need to provide helplines, identity monitoring or welfare support.

After an incident, organisations must conduct a comprehensive review, update their breach registers and report lessons and mitigation progress quarterly. The aim is to ensure that findings lead to practical reforms rather than being recorded without further action.

Why does it matter?

The action plan reflects a shift from treating data breaches primarily as compliance incidents towards managing them as coordinated public-sector resilience challenges. Standardised reporting, preparedness exercises and shared lessons could help government organisations respond more consistently while reducing the impact on affected individuals.

The framework also reinforces the principle that effective breach management extends beyond regulatory reporting. By prioritising support for affected people and requiring continuous organisational learning, the government is encouraging departments to treat data protection as an ongoing governance responsibility rather than a one-off compliance exercise.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

Claude for Teachers released for verified US educators

Anthropic has launched Claude for Teachers, offering verified K-12 educators in the US free access to premium Claude features, teaching skills and curriculum-aligned resources.

The product is designed to help teachers plan lessons, adapt materials, differentiate instruction and manage classroom workflows.

Claude for Teachers connects to Learning Commons, giving it access to academic standards across all 50 US states and related learning competencies.

Anthropic says the tool can use those standards to draft scaffolded lesson plans and student-facing materials based on widely used curricula, including OpenSciEd and Illustrative Mathematics.

Educators can also connect Claude with K-12 tools such as ASSISTments, Brisk Teaching, Canva Education, Coteach, Diffit, Eedi, MagicSchool, Snorkl and TeachFX.

The platform includes tailored teaching skills grounded in learning science, with use cases including standards-aligned lesson planning, differentiated materials and analysis of class data for instructional planning.

Anthropic says that Claude for Teachers is for educators only and complies with K-12 privacy requirements.

Data from the product will not be used for model training, and student information is covered by a K-12 Data Processing Addendum designed to comply with FERPA.

The company is also working with the American Federation of Teachers on safety and privacy principles for AI in education.

Verified educators can access Claude for Teachers free of charge if they sign up by 30 June 2027, with a dedicated version for schools and districts planned later.

Why does it matter?

Claude for Teachers shows how major AI companies are moving from general-purpose chatbots into specialised education tools with curriculum alignment, workflow integrations and sector-specific privacy commitments. The launch could support lesson planning and differentiated instruction. Still, it also raises familiar questions about student data, vendor dependence, AI quality, teacher autonomy and how schools evaluate the educational impact of AI tools before scaling them.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

Ofcom says age checks expand but more action needed

Ofcom has published its 2026 Use of Age Assurance Report, finding that age-assurance measures have expanded rapidly over the past year while calling for further action to strengthen online protections for children under the UK’s Online Safety Act.

The report examines the first six months after child protection duties took effect in July 2025, covering pornography, social media and online dating services. Ofcom said highly effective age assurance can significantly improve child safety, although no single method can completely prevent circumvention.

Ofcom said social media platforms have not consistently enforced their existing minimum age requirements and urged services relying on age inference to combine it with other highly effective methods. It also called on pornography services that have yet to introduce age checks to do so without delay, stressing that regulated services remain responsible for ensuring their age-assurance measures are effective.

The regulator also confirmed it will provide Parliament with an assessment by the end of October on how age checks for users over 16 could operate in practice, ahead of proposed social media restrictions expected in 2027.

Why does it matter?

The report provides one of the first comprehensive assessments of how age-assurance requirements are being implemented under the Online Safety Act. Its findings are likely to shape future enforcement priorities and inform policy discussions on additional age-based restrictions for social media services.

The report also suggests that age assurance is evolving into a broader ecosystem responsibility rather than a platform-only obligation. By highlighting the roles of search engines, app stores and device manufacturers alongside online services, Ofcom signals that effective child protection will increasingly depend on coordinated action across the digital ecosystem.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot