Skip to content
Larnaca, Cyprus
BINA CYINNOVATION HUBLarnaca · est. 2026
AIAI4 September 20263 min read

Robo-boss ban, DSA ruling, and a $1B cyber pledge

California shields workers from AI-only firing decisions, the EU reclassifies ChatGPT under the DSA's toughest rules, and frontier labs pledge $1B for cyber defence.

By BINA Editorial

Three regulatory milestones and two major cybersecurity commitments arrived on the same day, signalling that AI governance has moved from deliberation to enforcement — and that frontier labs are starting to align explicitly with public-sector security needs.

Meta's Muse Spark 1.3 Brings a 1M-Token Window and an Open-Weights Signal

Meta released Muse Spark 1.3, a frontier multimodal model with a native context window of one million tokens — large enough to process feature-length films, thick legal documents, or full corporate archives in a single pass. The model handles video, images, and documents natively and scores 62 on the Artificial Analysis intelligence index, placing it among the most capable benchmarked systems currently available. CEO Mark Zuckerberg has signalled that an open-weights release is imminent, continuing Meta's strategy of making capable models freely available to challenge closed competitors.

California Passes 30 AI Bills, Including a Ban on AI-Only Firing Decisions

California's legislature ended its session by passing 30 AI-related bills — the broadest package any US state has produced — and forwarded them to Governor Gavin Newsom, who faces a 30 September deadline to sign or veto. The headline measure, widely called the "No Robo Bosses Act," prohibits employers from using automated systems as the sole basis for terminating a worker. Companion bills require clinical AI tools with known demographic biases to carry explicit warnings and mandate independent compliance audits across sectors. If Newsom signs the full package, California would set a US floor for AI accountability in both the workplace and in healthcare.

EU Classifies ChatGPT as a Very Large Online Search Engine Under the DSA

The European Commission designated ChatGPT as a "very large online search engine" under the Digital Services Act — the first time that category has been applied to a generative AI chatbot. The designation triggers the DSA's most demanding compliance obligations: algorithmic-transparency audits, annual systemic-risk assessments, and emergency-response protocols normally reserved for platforms such as Google Search and Bing. OpenAI will now need to document and justify how ChatGPT surfaces, ranks, and presents information, requirements that were written with traditional search in mind but that regulators have explicitly extended to conversational AI.

OpenAI Pledges $1 Billion to Shield Critical Infrastructure Under 'Daybreak'

OpenAI's new Daybreak for Frontline Defenders initiative commits one billion dollars to subsidised access to frontier AI models, structured training programmes, and dedicated technical support for operators of critical national infrastructure — water utilities, electric-grid operators, state and local governments, and nonprofits. The pledge represents a deliberate repositioning: a commercial frontier lab publicly aligning its resources with essential public services rather than exclusively with enterprise clients. The programme also includes a cybersecurity research component aimed at making AI tools harder to weaponise against the very infrastructure they will now help defend.

Google Releases Gemini 3.8 Flash Cyber for Vetted Defenders

Google introduced Gemini 3.8 Flash Cyber, a model built explicitly for defensive cybersecurity work and released exclusively through the new Fairwind Program, which vets eligible government agencies, academic researchers, and critical-infrastructure operators before granting access. Internal testing shows the model correctly identifies vulnerabilities in more than 70 percent of cases across 20 programming languages and produces 2.6 times as many correct security patches for Chrome as the best available commercial alternative. The restricted-access approach reflects a deliberate choice to keep a high-capability security tool out of general circulation while directing it toward organisations best positioned to use it responsibly.