United Kingdom
- The Home Office has awarded a contract to Akhter Computers Ltd to develop and test AI software that estimates a migrant’s age from photographs.
- Officials state the technology will act as an additional tool for border officers to ensure that limited local council care and legal protections are reserved exclusively for children, deterring adults from lying about their age.
- Campaign groups, including Human Rights Watch, have condemned the scheme as a cruel and unproven experiment, warning that using facial estimation on vulnerable refugees undermines human rights and lacks ethical validation.
- The Scottish Government’s National Planning Framework (NPF4) claims datacentres will have a negligible climate impact based on a 2022 analysis that predates the AI boom.
- Over a dozen proposed Scottish datacentres collectively demand 6.2GW of power, which is 1.5 times more than the entire country’s peak winter electricity usage.
- Campaign group APRS warns that the lack of an official definition for “green datacentres” allows developers to exploit the label for favourable treatment from local authorities.
United States
California Attorney General sues 23andMe successor for 2023 data breach
- The 2023 breach exposed the genetic predispositions, ancestry, ethnicity, and health risk factors of nearly seven million users, as well as data belonging to their biological relatives.
- Hackers broke into accounts and later sold the stolen data on the dark web, specifically targeting information belonging to Jewish and Asian American Pacific Islander users.
- Attorney stated that 23andMe failed to implement basic security steps, such as proper login authentication, and subsequently lied to consumers about the true severity of the breach.
- Thisfollows a £2.31m fine from the UK’s Information Commissioner’s Office over the exposure of over 155,000 UK residents’ data, which preceded 23andMe’s bankruptcy filing and subsequent rebranding into Chrome Holding.
Major cruise line hack exposes sensitive data of nearly 6 million travelers
- The breach occurred after an unauthorised actor used a social engineering attack to deceive a single employee, exposing the personal details of 5,995,277 individuals across Carnival’s portfolio of cruise brands.
- While Carnival is still conducting a full analysis of the compromised data, it has confirmed that customer names, email addresses, phone numbers, dates of birth, driver’s licences, and passport numbers were accessed.
- Impacted customers expressed frustration over how long it took Carnival to notify them, with some users alleging that the stolen data has already been published on the dark web after the company refused to pay a ransom.
- Although the cybercrime extortion group ShinyHunters has claimed credit for the breach, Carnival Corporation has not publicly confirmed the identity of the hackers or where the stolen data has gone.
Europe
The European Central Bank tells banks to invest more to get a grip on AI security risks
- Advanced large language models are viewed by experts as significant threats due to their ability to automatically detect and exploit flaws in the banking industry software systems.
- It was emphasised that increased cybersecurity funding must become a structural priority for the financial sector rather than a temporary fix to patch current vulnerabilities.
- Highlighting that US banks currently have greater exposure to these advanced AI tools than European institutions, the ECB stressed that pervasive security investments are equally critical for both small and large banks.
Meta tool to track employee mouse clicks on collision course with EU privacy rules
- Meta’s Model Capability Initiative tracks mouse movements, clicks, and navigation across more than 200 apps and websites to train autonomous AI agents.
- Although Meta claims the tool is only installed on US devices, the company admitted it captures the contents of emails and chats sent by non-US colleagues to US staff, potentially violating GDPR provisions.
- An internal employee analysis revealed that MCI links into security software to harvest code changes, URLs, and unencrypted clipboard content, allowing Meta to build comprehensive behavioural models to automate corporate tasks.
International
Apple, Google push for judicial oversight in Canada online safety bill
- Representatives from Apple and Google testified before a House of Commons committee to demand explicit legal protections for end-to-end encryption and the introduction of strict judicial oversight for data requests.
- Apple privacy executives warned lawmakers that creating backdoors inevitably exposes everyday consumers to cybercriminals and hostile foreign actor.
- The friction follows an incident last year where Apple chose to withdraw its encrypted cloud backup features from the United Kingdom after receiving a similar decryption order from the UK government.
For the latest updates on UK AI border age verification, the 23andMe lawsuit, Meta privacy concerns and major data breaches, visit our Data Protection News hub.



