Habr•September 26, 2026•🇷🇺Translated from Russian

Bill Gates Calls for Stronger External Oversight and Regulation of AI

Bill Gates has called for stronger external oversight of artificial intelligence, arguing that reliance on the goodwill of AI creators is no longer viable.

In an interview with NBC News, Gates stated that self-regulation by the industry is insufficient. He urged Congress to enact specific laws governing AI and recommended that law enforcement and policymakers become actively involved in defining guarantees and controls. While acknowledging that this approach would introduce additional bureaucracy, Gates believes it would not significantly slow down development.

Why stronger controls are needed now

Gates noted that AI has become powerful enough to cause large-scale harm if misused. He warned that AI could trigger events resulting in up to a billion deaths and described the combination of malicious actors with advanced AI tools as more dangerous than any previous weapon.

He did not advocate halting progress. Instead, he called for mandatory rules, independent checks, and ongoing monitoring, especially in high-risk areas such as medicine, finance, government systems, and other critical infrastructure.

Reactions from industry and government

Executives from Anthropic and OpenAI have also suggested slowing the pace of AI development. Former Anthropic employee Jacob Coxon publicly accused companies of acting irresponsibly and gambling with lives by racing toward self-improving superintelligence.

House Speaker Mike Johnson has indicated he prefers to wait for concrete proposals from the companies themselves. In contrast, Mark Zuckerberg opposes industry-wide coordination and maintains that individual laboratories should decide when to slow down.

Meanwhile, states including California, Maryland, and New York have started their own regulatory initiatives and are forming expert councils to address AI governance.

Practical recommendations for organizations

Organizations using AI should maintain a registry of AI tools and connected services, review prompts and data-handling scenarios, restrict access to models and internal databases, test outputs for errors and bias, log user and system actions, and prepare incident-response plans for erroneous recommendations.

Related articles

Securitylab•Policy & Regulation

Implementing DevSecOps in Unprepared Teams: A Practical Three-Month Roadmap

Many development teams face resistance when security tools are introduced without proper process changes, leading to bypassed checks and unresolved findings. The article outlines a structured approach for small teams of five to eight developers without a dedicated security specialist, focusing on one service as a pilot. It emphasizes assigning clear roles including a Security Champion, selecting initial checks such as secret scanning with Gitleaks and dependency analysis, and converting scanner reports into actionable tasks with owners and deadlines. The plan covers the first eight weeks of setup, including baseline handling for legacy issues, automated blocking rules, and incident rehearsal exercises. Metrics recommended include time to first triage, age of open critical defects, and false positive rates, aligned with DORA indicators for release performance. The guidance draws on OWASP SAMM practices and stresses that security requirements must be integrated into daily workflows rather than added as extra gates.

Habr•Policy & Regulation

Why Technically Strong CISOs Lose to Weaker Peers: The Hidden Role of Internal Politics

A new analysis from independent expert Andrey Biryukov explains why technically proficient CISOs frequently fail to secure budgets and executive support while less technical peers succeed. The core issue lies not in technical knowledge but in the ability to translate security risks into business language that resonates with CFOs, CEOs, and boards. Biryukov details how influence, rather than formal authority, determines whether security initiatives gain traction or stall in endless approvals. He emphasizes building coalitions in advance, crafting compelling narratives, and preparing concrete business cases that quantify revenue impact and regulatory exposure. The article also highlights common pitfalls such as relying on fear-based arguments or ignoring stakeholder KPIs. Ultimately, the piece argues that selling security internally is essential for any CISO who wants both resources and long-term survival in the role.

AntiMalware•Policy & Regulation

Bybit Restricts Transfers to Sanctioned Entities Including Lazarus Group and CryptoPro

Cryptocurrency exchange Bybit has notified users that transfers to or from entities on its Restricted Counterparties list are prohibited, regardless of amount or whether conducted directly or through intermediaries. The list includes the North Korean state-sponsored Lazarus group and Russian cryptographic software developer CryptoPro due to their presence on sanctions lists from the United States, European Union, and United Kingdom. Bybit will automatically reject outgoing transfers to listed counterparties and may freeze incoming funds from them or related addresses, with potential account suspension or closure for users involved. The exchange emphasizes that blockchain transparency allows tracing of funds without user confessions and reserves the right to block transactions even with counterparties not yet explicitly listed. These measures are embedded in Bybit's terms of service to ensure compliance with international sanctions regimes.

AntiMalware•Policy & Regulation

Russia's MinTsifry Flags Google Android Developer Verification Rules as Risk to Domestic Apps

Russia's Ministry of Digital Development is assessing new Google policies that will require developer registration for Android apps distributed outside Google Play. The changes, starting in select countries in 2026 and expanding globally in 2027, could block sideloading of Russian applications previously removed from official stores due to sanctions. Minister Maksut Shadaev described the scenario as a potential barrier where users may no longer freely install APK files from third-party sources. Google plans to retain advanced modes and ADB installation options with extra warnings for unverified apps. Custom firmware projects such as LineageOS have stated their devices will remain unaffected by the verification system. Russian banks, marketplaces, and other services that rely on direct APK distribution are viewed as the most exposed.