LIVE · cybersecurity feed
Live wire
CVE-2026-66066 · KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)Rails patches critical Active Storage flaw with RCE potentialCVE-2026-48449 · Adobe fixed a maximum-severity vulnerability flaw in Campaign ClassicRuby on Rails Patches Critical VulnerabilityHackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer SitesHijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance MalwareCaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theftHollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law FirmCVE-2026-33017 · Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability ExploitsThis month in security with Tony Anscombe – July 2026 edition
nation-state

EU begins enforcing AI Act, putting AI models under the microscope

Europe’s fight to regulate AI models moved from paper to practice on 2 August 2026, when the European Commission’s AI Office and national authorities began enforcing the AI Act. On the same date, new transparency rules took effect, requiring certain AI systems to tell users when they’re interacting with AI and when content has been generated or altered by it. Under these rules, chatbots have to id

zeroday.news · 3h ago

The European Union has begun enforcing its AI Act, with new transparency rules taking effect on August 2, 2026. These regulations mandate that certain AI systems must disclose to users when they are interacting with an AI or when content has been generated or altered by artificial intelligence. This includes requirements for chatbots to identify themselves as automated systems, for deepfakes to be labeled, and for machine-made or edited content to carry machine-readable marks for automatic detection.

Companies failing to comply with these obligations face significant penalties, including fines up to €15 million or 3% of their worldwide annual turnover, whichever amount is higher. The European Commission stated that the objective of these measures is to reduce deception and manipulation, enabling individuals to make more informed decisions, while also providing businesses with clearer compliance requirements.

The enforcement powers primarily target providers of general-purpose AI (GPAI) models, which are the foundational systems supporting numerous AI tools and services, including AI agents. The Commission highlighted that providers of the most advanced GPAI models must address risks of large-scale harm, such as chemical, biological, radiological, and nuclear incidents, loss of control, cyber offenses, harmful manipulation, and threats to fundamental rights.

All GPAI model providers are now required to document specific information and make it available to competent authorities or downstream providers. They must also establish a copyright policy and publish a sufficiently detailed summary of the content used to train their models.

Alongside the new enforcement, the Commission released an initial list of over 180 organizations that have signed the Code of Practice on transparency of AI-generated content. This voluntary framework offers companies a structured method to demonstrate adherence to the labeling and marking requirements, which are legal obligations under Article 50 of the AI Act.

While some aspects of the AI Act are now in force, others are being implemented on a staggered schedule. The AI Omnibus, a package of amendments to the Act, has postponed the rules for high-risk AI systems until December 2, 2027, and those for high-risk systems integrated into regulated products until August 2, 2028. Conversely, the Omnibus accelerates measures against harmful AI applications, banning AI systems that generate non-consensual sexually explicit content or child sexual abuse material starting December 2, 2026.

The European Commission has previously utilized other EU digital laws to scrutinize risks associated with generative AI. For instance, in January 2026, the Commission initiated a formal investigation into X under the Digital Services Act following the appearance of manipulated sexually explicit images and potential child sexual abuse material on the platform, involving its Grok tool.

Enforcement responsibilities are distributed among several bodies. The AI Office directly oversees general-purpose AI models, with authority to request technical documentation, conduct evaluations, demand corrective actions, and issue fines. National competent authorities are responsible for other AI systems operating within their respective borders, while the European Data Protection Supervisor ensures compliance among EU institutions themselves.

Henna Virkkunen, Executive Vice-President for Tech Sovereignty, Security and Democracy, emphasized that the Act provides legal certainty for innovators while safeguarding public interest, viewing enforcement as a crucial step toward fostering AI that is understandable and trustworthy for both individuals and businesses. However, some observers remain unconvinced that the AI Act will bring about substantial change, suggesting that user awareness of how AI tools handle data might be more impactful than the regulations themselves.

nation-stateai
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts

Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. [...]

security

WhatsApp account takeover scam asks you to “vote for my friend”

Scammers are trying to take over WhatsApp accounts by sending messages asking people to vote for a friend in a fake online contest.

malware

Digital executive protection is a strategic imperative for CEOs

In this interview with Help Net Security, Brian Hill, Field CISO, Client Advisory for BlackCloak, explains how attackers reach companies through the personal lives of executives. He describes a case where a draft report sat in an executive’s personal email with no multifactor authentication, and traders acted on it before the news went public. He also covers a home network left open after an AV te

security

New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems

The grants will help local governments assess and improve cyber defenses amid a multistate campaign targeting water and wastewater infrastructure. The post New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems appeared first on SecurityWeek.

ai

Public interest coalition urges Congress to investigate OpenAI, Hugging Face hack

The post Public interest coalition urges Congress to investigate OpenAI, Hugging Face hack appeared first on CyberScoop.

security

“Adult TikTok” searches lead to scams

That "free" adult TikTok site could leave you with spam, unwanted apps, or fake verification fees.