Skip to content
category — world

ls ./category/world

World

Regulation, policy and global stories with the context you need.

31 articles

Europe's 24-hour exploit-reporting clock reaches products sold years ago. Its security rules do not

2026-09-15

Since 11 September, manufacturers selling connected products in the EU must warn authorities within 24 hours of learning that a flaw in one is being exploited. The Cyber Resilience Act applies that duty to products already on the market, while its security requirements reach only those placed on the market from December 2027. For a device already on sale, the Act now requires the report, but not the patch.

OpenAI asked Congress whether slowing down is legal. The bill on the table says yes, if almost nothing else is the reason

2026-09-11

Sam Altman told staff OpenAI could pace frontier development alongside other labs, and OpenAI asked lawmakers whether that would breach antitrust law. The bipartisan bill that would answer it permits coordinated delays for loss-of-control risks — if not more than an insubstantial part of the reason is anything else. That week, OpenAI stopped selling its top tier for lack of compute.

He ran the monitoring that catches leakers, so he copied the documents out by hand

2026-08-31

Nathan Vilas Laatsch worked in the Defense Intelligence Agency's Insider Threat Division, enabling user activity monitoring on people with access to DIA systems. When he decided to pass secrets to a foreign government, he transcribed them at his desk on paper. He has pleaded guilty, and the plea recommends 11 to 18 years.

The US has sanctioned the same Iranian hacking institute twice in eight years — and it still does not tell you who stopped a British power plant

2026-08-29

Treasury designated nearly 60 Iran-linked entities, individuals and vessels under Operation Economic Outcast, including six people tied to the Mabna Institute — the outfit sanctioned in 2018 for stealing 31 terabytes from 320 universities. The designations concern US infrastructure. They do not name the UK attack, and the attribution there remains unconfirmed.

India's banking regulator issued seven cybersecurity directions at once, and they were already in force when you read about them

2026-08-27

On 31 July the RBI published parallel Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions for commercial banks, small finance banks, payments banks, urban co-operative banks, financial institutions, NBFCs and credit information companies. They took effect immediately, they repeal what came before, and incidents must reach the RBI within six hours.