The past week has seen near-autonomous AI agents deployed in real nation-state cyberattacks, the US Senate hardening legislative limits on autonomous weapons, and the EU AI Act entering its first live enforcement phase — all converging to signal that AI in defence and security has shifted from experimentation to consequential, regulated deployment. UK and European actors are central to this shift, from NATO’s drone funding engine to a UK university winning a flagship autonomous systems competition.
Top story: Suspected Chinese operatives used ‘near-autonomous’ AI agents to compromise Taiwan’s nuclear safety agency and seven energy companies — the first publicly documented AI-driven nation-state cyberattack at scale.
AI Agents Mount Near-Autonomous Attack on Taiwan’s Nuclear Agency
The Register · Risk
Suspected Chinese cyber operatives used publicly available AI tools in a coordinated campaign that compromised Taiwan’s nuclear safety agency, supply-chain vendors, and at least seven energy companies. Over four days, AI agents autonomously compromised 85 government accounts and extracted over 2,500 personnel records — what Israeli cybersecurity firm Dream called a ‘near-autonomous attack.’ This is the first publicly documented case of AI-driven agents conducting a sustained, multi-target government intrusion, raising urgent questions for critical national infrastructure defenders worldwide.
US Senate NDAA Bans AI From Launching Nuclear Weapons Autonomously
Arms Control Association · Regulation
The US Senate Armed Services Committee advanced its FY2026 NDAA draft requiring humans to retain ultimate responsibility over all lethal force and nuclear weapons deployment by AI systems. The bill also mandates Pentagon review of military AI models, privacy impact assessments, and an incident repository to track AI system failures. For defence practitioners globally, this marks the transition of ‘human-in-the-loop’ from a policy aspiration to enforceable US federal law — the most concrete legislative restriction on military AI in American history.
https://www.armscontrol.org/act/2026-07/news/us-senate-panel-approves-ai-autonomous-weapons-rules
NATO’s $40bn ‘Drone Edge’ Initiative Opens Procurement to AI Startups
Army Recognition · Strategy
At the July 2026 NATO Summit in Ankara, Allied leaders endorsed the NATO Innovation Scale-Up Package and launched the ‘Drone Edge’ initiative, committing over $40 billion across five years to counter-drone capabilities, autonomous systems, and operator training. The package includes the first-ever public demand signal to industry across the Alliance and the launch of the NATO Engine to accelerate deep-tech adoption. For European defence contractors and AI startups, it opens a structured procurement pathway into NATO’s expanding autonomous systems ecosystem.
UK University Wins NATO Autonomous Search-and-Rescue AI Contest
RepresentAI · Generative AI
At NATO’s Science for Peace and Security Programme demonstrations in the Netherlands, a team from City St. George’s, University of London won the third SAPIENCE competition — challenging researchers to develop autonomous aircraft capable of search-and-rescue without satellite positioning. The victory underlines the UK’s active role in shaping NATO’s autonomous systems research agenda and the growing operational maturity of GPS-denied AI navigation. Defence organisations should note this signals real-world readiness for AI-piloted platforms in contested environments where GPS jamming is standard.
https://representai.co.uk/2026/08/03/ai-in-defense-security-todays-top-stories-03-august-2026/
EU AI Act Enforcement Goes Live: GPAI Penalties Now Active
European Commission · Regulation
From 2 August 2026, the EU AI Act’s transparency obligations, GPAI penalty powers, and full national market surveillance authority came into force — with fines of up to €15 million or 3% of global annual turnover now enforceable. Defence and security technology providers deploying AI systems in Europe must now ensure AI-generated content is labelled, chatbots disclose their nature, and incident reporting obligations are met. High-risk AI system obligations were deferred to December 2027 under the Digital Omnibus deal, but organisations should treat that as implementation time, not a regulatory holiday.
https://commission.europa.eu/news-and-media/news/safer-and-more-transparent-ai-2026-08-02_en
