United Kingdom
Auror rolls out controlled facial recognition in UK stores
- Auror has launched its Subject Recognition facial recognition tool in UK stores to protect staff from rising violent crime by alerting them to known high-harm repeat offenders.
- Built strictly on individual retail crime data, watchlists cannot be merged or accessed by police. Non-matches are deleted instantly, no biometric templates are stored in the cloud, and human oversight is required for key decisions.
- Tesco trailed the platform across 40 stores, joining a competitive UK market alongside rivals like Facewatch.
United States
Autonomous OpenAI agent goes rogue in unprecedented breach
- OpenAI revealed that one of its autonomous AI agents broke out of an insecure test environment and accessed internal systems at model hub Hugging Face.
- Cyber-security experts criticised OpenAI for failing to build a secure sandbox, warning that the incident proves autonomous AI attack capabilities are no longer theoretical.
- Industry analysts suggested OpenAI may be highlighting the incident to demonstrate the power of its systems amidst intense market competition from rivals like Anthropic.
- The UK AI Security Institute and cyber-security specialists urged organisations to urgently strengthen their defences to keep pace with AI-driven threats.
Craneware investigates cyberattack impacting customer data
- Craneware, a UK-based provider of healthcare billing software serving thousands of US hospitals and clinics, has suffered a cyberattack involving data exfiltration.
- Hackers stole employee, customer, and partner records, though Craneware noted much of the stolen data was non-sensitive or public. Operations and customer services were not disrupted, and the intruders have been ejected.
- The UK Information Commissioner’s Office and the US FBI have been notified. Craneware is still determining the full scope of the breach, including whether patient data was exposed.
- No cybercrime group has claimed responsibility, and it remains unclear if a ransom was demanded.
Europe
France enacts strict age-verification rules to block teens from social media
- France has become the first European nation to pass a law banning social media for children under 15, introducing mandatory age verification across platforms, Following Australia’s pioneering ban and UK’s planned social media ban.
- The ban begins in September 2026 for new accounts, extending to all existing accounts by January 2027, requiring every user in France to verify their age to retain access.
- Platform compliance will rely on regulator-approved age-verification tools. Critics have raised concerns over data privacy, efficacy, and the risk of driving teenagers to unmonitored online spaces.
EU Commission finds TikTok failed to safeguard children’s privacy
- The European Commission has issued preliminary findings against TikTok under the Digital Services Act (DSA), concluding that the platform’s default settings failed to protect minors by allowing adult users to view children’s accounts.
- Regulators determined that accessible privacy settings exposed young users to risks including cyberbullying, unwanted contact, and predatory behaviour.
- The preliminary finding is part of a broader formal DSA investigation launched in February 2024, which previously called out TikTok’s addictive design features that harm minors’ mental and physical health.
- This adds to significant regulatory pressure in Europe, following previous Irish Data Protection Commission fines of €345 million for child data breaches and €530 million over illegal data transfers to China.
Samsung considers major investment to fuel Mistral’s European AI ambitions
- Samsung is reportedly in talks to invest up to €1 billion in French AI startup Mistral as part of a major fundraising round that could value the firm at roughly €20 billion.
- The capital will help fund Mistral’s expanding European data centre footprint, securing compute capacity and memory chips amidst global hardware shortages while providing Samsung with a key software partner.
- The investment negotiations coincide with a recent multibillion-dollar infrastructure deal with Microsoft to host Mistral models on Azure, supporting annual recurring revenues projected to exceed $1 billion this year.
International
Major South African tech distributor shutdown following suspected cyber breach
- Major South African tech distributor Rectron was forced to close offices nationwide following a major network outage.
- Industry sources indicate the disruption was caused by a network breach, prompting the company to deploy cybersecurity experts to investigate the incident.
- Phone lines went unanswered and Rectron issued brief notices citing an unexpected technical disruption, refusing to confirm or deny whether a cyber incident took place.
- The target of the suspected attack is a primary South African provider of enterprise cybersecurity and ransomware protection solutions.
Real-time facial recognition set to be Australia’s newest law enforcement tool
- Western Australia Police have launched an Australian-first, five-month mobile trial using a van equipped with real-time facial recognition technology, scanning over 130,000 faces and making 19 arrests in its first week.
- Authorities claim the technology enhances public safety by targeting wanted individuals without conducting mass surveillance or retaining data on ordinary citizens.
- The Western Australian privacy watchdog and experts warn of “collective privacy harms”, algorithmic bias against minority groups, accuracy issues in crowded environments, and potential covert monitoring or protest surveillance.
- The trial was implemented without prior consultation with the State Privacy Commissioner, and police are now under scrutiny to ensure compliance with privacy laws requiring formal risk assessments for automated decision-making.
For the latest updates on facial recognition technology news including Auror’s UK rollout, Australia’s facial recognition trial, OpenAI’s AI security incident, France’s social media restrictions, TikTok’s privacy investigation, and recent cyberattacks, visit out Data Protection News Hub.



