
Ofcom Says Guessing a User's Age Is Not Enough
Ofcom opened a section 12 investigation into TikTok's age assurance on 16 July 2026. The real target is age inference as a method. What UK-facing operators should ask now.

Ofcom opened a section 12 investigation into TikTok's age assurance on 16 July 2026. The real target is age inference as a method. What UK-facing operators should ask now.

On 15 July 2026 CISA added CVE-2023-4346 to its KEV catalog. The KNX flaw has no patch. The fix is a commissioning setting, and the buildings are European.

xAI's complaint against a Grok user pleads exactly one cause of action: breach of its Terms of Service. It asks the user to indemnify xAI's legal costs. What European owners should read in their own vendor terms.

The Oversight Board tested 10 models from 6 providers across 10 jurisdictions. Refusal rates were 34% in restrictive countries versus 14% in permissive ones. The method is now a procurement instrument.

The Board for Digital Services found X's audit measures, and therefore its whole DSA action plan, insufficient on 15 June. On 16 July the Commission accepted the plan with clarifications and enhanced supervision. The first independent check is up to a year away.

On 15 July 2026 Sprout Social filed a 20% workforce cut and a high-end guidance beat in one 8-K. The vendor signal owners trusted for twenty years has stopped working.

Google and Epic withdrew their motion on 15 July. From 22 July, Google Play provides app listings to third-party US Android app stores by default unless a developer opts out in Play Console.

On 16 July 2026 FERC voted 5-0 to direct NERC to write mandatory Reliability Standards for data centres and to revise its registry criteria. Both are due 31 December 2026. What it means for owners with US compute.

Hugging Face says its responders could not analyse a 17,000-event attacker log on hosted models because safety guardrails blocked the requests. We read the three big providers' published policies. None of them forbid what Hugging Face was doing.

The EDPB found no abuse of rights and sent a 2021 cookie complaint against VRT back to the Belgian authority to be assessed on its merits. What owners should draw from it.

On 15 July 2026 the Commission sent letters of formal notice to all 27 Member States over the recast EPBD. The 2030 and 2033 building deadlines are unchanged.

CVE-2026-15409 and CVE-2026-15410 chain into root on SonicWall SMA1000. Stolen TOTP seeds survive the patch, which is why Germany's BSI orders Assume Breach.
Page 8 / 36
One considered note on infrastructure, governance, and measurement, most mornings. No theory.