Technology & Digital Competition — August 2026 Edition | Indo-Pacific Studies Center
Indo-Pacific Studies Center
Strategic Brief · Issue #001
Indo-Pacific Strategic Dynamics

Technology & Digital Competition

August 2026 Edition

From Episodic Pressure to Durable Presence

RC01 ChinaRC05 Cross-StraitRC09 Cyber & Technology

Bottom Line Assessment

Aggregate indicators are elevated — magnitude-4–5 share above its normal range and magnitude-5 share above its normal range — yet the dominant character of this period is structural accumulation rather than acute escalation, whose share is below its normal range. Against that backdrop, the reported founding of a global AI governance body oriented toward the Global South, a reported Chinese DRAM IPO described as Asia's largest of 2026 and the largest semiconductor listing ever on the STAR Market, and a coordinated multi-state PLC cyberattack stand as the standout developments of this period.

Technology and digital competition has become the primary arena through which Indo-Pacific states contest economic resilience, military advantage, and rules-setting authority; the parallel hardening of semiconductor supply chains and AI governance institutions means that standard-setting choices made now will constrain strategic options for a decade. Control over submarine cable routes, satellite spectrum, and critical-infrastructure security is simultaneously an economic and a deterrence question for every regional actor.

What Changed This Period — and What Did Not

What did not change
  • Grey-zone share: 5.9% against a mean of 7.6% — inside its normal range
Computed: measures inside their normal range (25th–75th percentile) against every observed month on the same filters. Stability is a finding, not an empty result.
What moved — and what may be changing
  • Measured: Magnitude 4–5 share: 33.3% against a mean of 26.2% — above its normal range
  • Measured: Magnitude-5 share: 7.8% against a mean of 4.9% — above its normal range
  • Measured: Escalation share: 9.8% against a mean of 21.0% — below its normal range
  • Measured: Signal volume: 51 against a mean of 40 (1.27×)
  • China may be transitioning from reactive standard-participation to proactive institution-founding in AI governance: WAICO's reported launch (S29) and the APEC Chengdu Statement (S8) in the same month suggest a coordinated offensive rather than episodic engagement. This hypothesis would be confirmed if WAICO convenes a technical working group or publishes binding governance principles within twelve months; it would be killed if founding-state participation drops below a quorum before a first plenary.
  • The US equipment-exclusion framework may be migrating from device-level to component-level enforcement as the primary mode: the FCC component-ban order (S9, low confidence, media report) represents a reported deepening to the chipset layer. This pattern would be confirmed if BIS or FCC extend component-traceability requirements to software or firmware provenance in a subsequent rulemaking; it would be killed if courts suspend the component-ban order on First Amendment or APA grounds before it takes effect.
  • Southeast Asian states may be moving from AI-ethics frameworks to legally binding data-governance regimes as the dominant regulatory form: Vietnam's cybersecurity law entry into force (S50), its draft Law on Data Security with a four-tier classification system (S31), and Indonesia's draft AI Presidential Regulation (S2) all appeared within a thirty-day window. Singapore's Generative AI advisory guidelines (S20) also appeared in this window, though S20 explicitly describes those guidelines as non-binding. Confirmation would be a second ASEAN state enacting legislation — rather than guidelines — within six months; a reversion to advisory instruments would weaken the inference.
  • Semiconductor capital timelines on both sides of the US-China competition may be accelerating beyond previously reported schedules: TSMC Taichung A14 construction is reported as significantly ahead of schedule (S1), Micron Clay New York reported as more than one quarter ahead of original schedule (S34), and CXMT's STAR Market IPO reported as raising funds explicitly for DRAM expansion (S5). Confirmation would be an official government or company announcement revising completion dates earlier than any previously published figure; reversal would be supply-chain delays or export-control complications that push timelines back.
“Measured” items are computed movements against the baseline. The remainder are analyst hypotheses this period’s signals raise but cannot yet establish — one observation does not establish a new practice; each names the observation that would confirm or kill it.
Percentages describe the composition of the IPSC signal register and should not be interpreted as the frequency distribution of all real-world military activity. Rates are robust to duplicate collection of the same event, but not to changes in collection tasking or centre mix — the denominator is IPSC-collected signals, not a complete universe of activity.

Key Judgements

Evidentiary base — computed: 51 signals · 45 unique sources · 63% official documents · confidence Medium 27 · Low 18 · High 6
  1. This period's severity distribution — magnitude-4–5 share above its normal range and magnitude-5 share above its normal range — reflects a genuine intensification in the structural stakes of digital competition, not merely a reporting spike, because the high-magnitude signals cluster across independent sub-domains rather than a single sensationalised event.7 signals cited · magnitude 4×3, 5×4 · RC01, RC09 · 3/7 official documents
    ConfidenceModerateBasisMultiple official-document and high-confidence signals at magnitude-4 and magnitude-5 across semiconductor, infrastructure, and governance sub-domains, with cross-centre corroboration from RC01 and RC09; escalation share simultaneously below its normal range, which is inconsistent with a simple alarm cycle.Would strengthenIf a subsequent month maintains an elevated magnitude-4–5 share across at least two sub-domains, that would confirm a sustained structural shift rather than a single-month cluster.Would weakenIf editorial review revealed that several high-magnitude assessments derived from a common wire-service report rather than independent sources, the corroboration basis would collapse.
  2. The reported founding of the World Artificial Intelligence Cooperation Organization (WAICO) constitutes the most consequential governance manoeuvre of this period because it attempts to institutionalise a rival AI norm-setting framework oriented toward the Global South before Western-led multilateral consensus has consolidated.3 signals cited · magnitude 3×1, 4×1, 5×1 · RC01 · 2/3 official documents
    ConfidenceModerateBasisSingle media-report signal, low confidence, but corroborated in kind by the APEC Chengdu Statement on digital technologies chaired by China and by CAC regulatory measures entering force, together suggesting a coordinated governance offensive rather than an isolated announcement.Would strengthenIf WAICO publishes founding statutes, a secretariat appointment, or a work programme within six months, confirming operational rather than declaratory ambition.Would weakenIf fewer than half of the reported founding states ratify or operationally engage with WAICO by end-2026, indicating the launch was primarily symbolic.
  3. The coordinated PLC cyberattack on water and wastewater systems across more than thirty Minnesota communities and utilities in at least seven US states, combined with the CISA advisory expanding confirmed Iranian-affiliated PLC exploitation, indicates that internet-exposed operational technology in civilian critical infrastructure remains a reliable attack surface despite years of remediation guidance.2 signals cited · magnitude 3×1, 4×1 · RC09 · 1/2 official documents
    ConfidenceHighBasisHigh-confidence official-document signal for the US attack and medium-confidence advisory for the CISA expansion; the CVE cited in S6 predates this period, suggesting that known, unpatched vulnerabilities — not novel tradecraft — likely drove the intrusion.Would strengthenAttribution of the US water-system attack to a named state or state-affiliated actor by a competent authority, linking it to the Iranian PLC exploitation pattern already documented in the CISA advisory.Would weakenIf post-incident forensics showed the attack was opportunistic criminal ransomware rather than a deliberate disruption campaign, the critical-infrastructure-targeting inference would not hold.
  4. The US is consolidating a layered semiconductor and digital-infrastructure exclusion architecture — spanning export controls, submarine cable licensing, and component-level equipment bans — that targets multiple choke-points simultaneously.5 signals cited · magnitude 2×1, 4×3, 5×1 · RC01, RC09 · 3/5 official documents
    ConfidenceModerateBasisCorroborated across official-document signals at magnitude-4 and magnitude-5 covering BIS chip reclassification, FCC submarine cable licensing, and the component-part equipment ban; all are formal regulatory instruments rather than executive statements, reducing reversal risk.Would strengthenAllied adoption of equivalent component-level equipment bans or cable licensing frameworks, which would close the circumvention pathways that US-only measures leave open.Would weakenSuccessful legal challenge to FCC 26-42 or the component-ban order that suspends their operation pending judicial review.
  5. China's reported CXMT DRAM IPO and accelerated domestic semiconductor investment, taken alongside the TSMC Taichung A14 fab construction milestone, suggest that both sides of the semiconductor competition are simultaneously pulling forward capacity timelines — making supply-chain decoupling faster and more costly to reverse than policy frameworks currently assume.3 signals cited · magnitude 2×1, 4×2 · RC01, RC09 · 0/3 official documents
    ConfidenceLowBasisBoth anchor signals are low-confidence media reports; the IPO valuation, market-share figures, and CXMT's reported ranking of fourth globally in DRAM production capacity are attributed rather than independently verified, and construction schedules can slip; the directional reading is plausible but the pace inference is uncertain.Would strengthenIndependent verification of CXMT's reported market-share trajectory and actual production ramp dates, or an official TSMC milestone announcement confirming the reported construction advance.Would weakenEvidence that CXMT's reported debut surge reflected speculative retail trading rather than institutional confidence in its production roadmap, or that TSMC Taichung timelines have since been revised.
Judgements are assessments, not events. Each is contestable; the italic note is computed from the signals the judgement cites, not written by the analyst. The evidentiary line above is computed from the whole signal set the same way.

Historical Indicators & Dashboard

Situation Assessment — each dimension computed separately, not collapsed into one score
Coercive pressureGrey-zone (sub-threshold) share is inside its normal range (10% escalation, 6% grey-zone/sub-threshold this period)
Domain concentrationTechnologyDigital: 51 of 51 signals (100%), 17 rated magnitude 4–5
Immediate kinetic warningNot assessed. This register does not track military mobilisation or force posture, so it cannot say whether conflict is imminent. A magnitude 4–5 rating is not a substitute for that — it means the signal is strategically significant, not that an attack is coming.
Quarantine or interdiction riskNot assessed. This register does not track naval deployments, legal declarations or shipping disruptions, so it cannot estimate the likelihood of an actual quarantine or interdiction. That call requires a separate, dedicated analysis this document does not provide.
Assessment confidence35% rate Low or Unstated confidence, below its normal range. 6 of 51 reach High confidence (top-tier source, independently corroborated).
Magnitude measures a signal's strategic significance (reversibility, scope, novelty), not the probability of imminent conflict. “Not assessed” rows are outside what this register codes and need a separate analyst judgement, not a guess.

This Period Against Its Own History

19 months · 2025-01 to 2026-07 · 51 signals this period against a mean of 40 (range 25–54)
Magnitude 4–5
33.3%
mean 26.2%
above its normal range
share of signals rated High or Critical impact
Magnitude 5
7.8%
mean 4.9%
above its normal range
share rated Critical impact only, the register's top tier
Escalation
9.8%
mean 21.0%
below its normal range
share coded as raising tension or crossing a threshold, as opposed to deterrence, de-escalation or signalling
Sub-threshold
5.9%
mean 7.6%
inside its normal range
grey-zone activity: signals coded SubThreshold (attributable, deliberately calibrated to stay below armed conflict — e.g. coast guard patrols, cyber operations, economic coercion) or Deniable (attribution contested or refused by the acting state) combined, as opposed to Overt action openly acknowledged and conducted
Bar spans this cluster's full observed range; the tick is its mean. The label is this period's standing against 19 months of the same cluster on the same filters. Placement rule: this period's value is ranked against every observed month — at or above the 90th percentile reads “among the highest months on record” (“the highest” only when it exceeds every month), 75th–90th “above its normal range”, 25th–75th “inside its normal range”, 10th–25th “below”, at or below the 10th “among the lowest”. Magnitude-based measures exclude Jan–Mar 2025 from mean and percentile (coding discontinuity — the same exclusion the charts apply), so this panel and the charts print the same historical means. Most months sit inside the normal range — that is the expected result, and it is information.

This Period in Context

Magnitude-5 share by month
Magnitude-5 share by monthShare of signals at magnitude 5, by month, against the panel mean coding discontinuityexcluded from mean0%6%12%10.57.8mean 4.88%25-0125-0425-0725-1026-0126-0426-0719 months · this period 1.61× the mean

Share of each month's signals assessed at the top of the magnitude scale. A within-month rate, not a count — counts rise when a research centre is ingested, rates do not. January–March 2025 are shaded: magnitude 4–5 sits at 13.7–14.8% there against 22–27% for every month after, which is an instrument change rather than a quiet quarter, so those months are excluded from the mean.

Grey-zone tempo
SubThresholdDeniable
Grey-zone tempoSub-threshold and deniable share of signals by month 0%10%20%mean 7.6%25-0125-0425-0725-1026-0126-0426-0719 months · 762 signals

Share of each month's signals coded SubThreshold or Deniable. The remainder — around 92% — is Overt and is not drawn. Mode records how an action was conducted, not what it was about, so this is a measure of grey-zone tempo rather than of any one domain.

What drives magnitude here
this clusterwhole corpus
What drives magnitude hereMean reversibility, scope and novelty for this cluster against the corpus reversibility1 – 31.86cluster n=511.52corpus n=8,424scope1 – 42.02cluster n=511.99corpus n=8,424novelty1 – 31.80cluster n=511.70corpus n=8,424bar length = position between 1 and the component ceiling

Magnitude is computed from these three components, not coded directly. Reading them separately shows whether a cluster scores high because its signals are hard to undo (reversibility), because they touch many parties (scope), or because they are without precedent (novelty). Bars are normalised to each component's ceiling so their lengths compare; the printed figure is the raw mean.

Strategic Synthesis

Governance architecture, not just capability, contested

The period's most structurally significant development is not a weapons test or a sanctions list but the reported founding of WAICO in Shanghai on 16 July 2026, with a reported twenty-nine founding states including Russia, Brazil, Pakistan, and others listed in S29 as including Indonesia, Kazakhstan, Laos, Belarus, Serbia, Cuba, Venezuela, and ten African and twelve Asian countries. Read alongside China chairing the APEC Digital and AI Ministerial in Chengdu that produced the 'Chengdu Statement' (S8), and the CAC's Interim Measures for AI Anthropomorphic Interactive Services entering force (S30), this constitutes a tripartite move: a multilateral body to contest Western norm-setting, a minilateral communiqué to shape APEC vocabulary, and domestic regulation that can be exported as a template. The West's comparative position is one of fragmented bilateral instruments — Japan's amended APPI (S25), Singapore's Generative AI advisory guidelines (S20), India's RBI model-risk guidance (S7), Vietnam's new cybersecurity law (S50) — rather than a consolidated institutional counter. Whether WAICO becomes operationally significant or remains declaratory depends on secretariat funding and member ratification that this period's signals do not yet confirm.

Exclusion architecture deepens at component level

The FCC's 22 July order prohibiting equipment authorisation for any device incorporating logic-bearing hardware components produced by Huawei, ZTE, Hikvision, Dahua, Hytera, DJI, or Autel (S9, low confidence, media report) — described in the signal as moving the ban from the assembled-device to the chipset level — combined with the submarine cable blanket-licensing regime excluding foreign-adversary-linked entities (S4, S36), represents a reported qualitative deepening of the US exclusion framework. According to S9, the order effectively bars devices incorporating components from these named entities from the US market regardless of the assembling brand. BIS simultaneously reclassified the UAE into Country Group A:5, extending licence-free access to Nvidia Blackwell and AMD Instinct AI chips for approved entities including G42 and Core42 (S33) — illustrating that the exclusion architecture is not simply protectionist but is being used to extend the trusted-vendor perimeter to aligned Gulf partners. The combined effect, as reported, is a more granular technological boundary whose enforcement burden now falls on component traceability rather than country-of-origin labelling.

OT security gap is operational, not theoretical

The coordinated attack on water and wastewater systems across reported thirty-plus communities and at least seven US states on 26–27 July (S6), exploiting what S6 assesses as likely CVE-2021-22681 in Rockwell Automation PLCs, and the simultaneous CISA advisory expanding confirmed Iranian-affiliated exploitation to Schneider Electric Modicon and Siemens S7-1200 PLCs (S16), establish that the operational technology attack surface is being actively exploited — not merely probed — across multiple adversary sets. The CVE in question predates this period by years; to the extent S6's assessment of the likely exploitation vector is correct, the attack succeeded through persistent non-remediation rather than novel capability. The Unit 42 reporting of CL-STA-1062 deploying a reported novel backdoor against Southeast Asian electricity and water utilities (S40) and the KDDI zero-day email-platform breach in Japan (S37) add regional texture: critical-infrastructure intrusions are occurring across the Pacific theatre concurrently, with differing attributed actors, suggesting the operational tempo is not driven by a single campaign but by the convergence of widely available exploitation tooling against consistently under-patched targets.

Allied digital-infrastructure diplomacy accelerating in Pacific

Pacific Cyber Week in Port Moresby (S22) and the associated Australian confirmation of the Pukpuk Digital Connectivity Initiative with PNG (S23), combined with the India-Southeast Asia I-2SEA submarine cable contract signed by a consortium reported to include Microsoft, Singtel, and Tata Communications (S42), and PNG's formal 5G spectrum release (S24), indicate that the contest for digital-infrastructure presence in the Pacific and Southeast Asia is entering a capital-commitment phase rather than a planning phase. China Mobile's SEA-H2X cable completing system acceptance and launching commercially on 22 July (S11) — reported as spanning approximately 5,746 km and connecting Hainan, China, Hong Kong, the Philippines, Thailand, and Singapore — means that competing cable architectures are now simultaneously operational and under construction. Singapore's Digital Infrastructure Bill consultation (S49) and the Quad joint statement on critical and emerging technologies issued from Manila (S10) add a regulatory and diplomatic layer: the infrastructure contest is being simultaneously fought in the ground and in the rulemaking arena.

Implications for the Regional Balance

Taiwan

Taiwan's position this period is defined by two simultaneous pressures. Construction of TSMC's Taichung Phase II A14 fab is reported by the Central Taiwan Science Park Administration Director as significantly ahead of schedule, with foundation piling largely complete and the first two fabs in the steel-structure phase (S1, low confidence) — suggesting that Taiwan's leading-edge fabrication advantage is being reinforced domestically even as it is replicated abroad. Against this, a Taiwan investigation into reported illegal AI-server exports containing Nvidia chips to China (S44, low confidence) and a Taipei City Investigation Office deferred prosecution for renting LINE accounts to a Xiamen-linked entity (S38, medium confidence) illustrate persistent export-control enforcement gaps and ongoing PRC influence operations. Taiwan's opening of a Phoenix office to anchor the Arizona semiconductor corridor (S41) reflects efforts to institutionalise supply-chain ties with the US, though the strategic significance depends on operationalisation not yet visible in this period's signals.

Japan

Japan's digital posture this period is primarily legislative and bilateral. The amended Act on the Protection of Personal Information was promulgated on 17 July 2026 (S25, medium confidence), aligning Japan more closely with international data-transfer standards. The India-Japan joint declaration on economic security targeting semiconductors and ICT (S45, medium confidence) and the elevation of AI cooperation to a strategic R&D partnership (S46, medium confidence) represent Japan expanding its trusted-partner architecture southward. On the vulnerability side, KDDI confirmed on 7 July that attackers exploited a reported zero-day in a third-party email platform to breach a shared email infrastructure platform serving six Japanese ISPs (S37, low confidence) — the vendor and CVE remain unnamed, limiting damage assessment. South Korea's ETRI led the development and approval of an ITU-R spectrum management methodology (S19, low confidence), reflecting Northeast Asian participation in standards-setting; that effort was led by South Korea rather than Japan.

Philippines

The Philippines featured as host of the Quad Foreign Ministers' meeting on 22 July 2026, which produced the first reported dedicated Quad joint statement on ASEAN cooperation, including on critical and emerging technologies and cyber coordination (S10, high confidence) — a meaningful diplomatic signal of Manila's role as a Quad-ASEAN bridge. On infrastructure, Cebu Pacific's reported partnership with SpaceX Starlink for LEO in-flight connectivity from 2027 (S32, high confidence) would make it the first low-cost carrier in Southeast Asia to adopt Starlink, according to the signal, deepening Philippines-US technology alignment. China Mobile's SEA-H2X cable is reported as connecting to the Philippines among other destinations (S11, low confidence), introducing a competing infrastructure presence whose security implications are not yet assessed in the available signals. The Unit 42 reporting of CL-STA-1062 targeting Southeast Asian utilities (S40, low confidence) did not name the Philippines specifically, but the regional exposure is noted.

India

India's technology diplomacy this period is notably outward-facing. The India-Japan economic security declaration (S45), AI strategic R&D partnership (S46), and IndiaAI–METI compute cooperation agreement (S47) — all medium-confidence official documents dated 2 July — collectively extend India's trusted-technology partner network into Northeast Asia. India also anchors the I-2SEA submarine cable consortium, with contracts signed on 2 July in a group reported to include Microsoft, Singtel, and Tata Communications (S42, medium confidence), positioning Indian entities in regional digital-infrastructure architecture. The Reserve Bank of India's draft model-risk management guidance for AI (S7, medium confidence) reflects domestic regulatory maturation. No India-specific intrusion or threat signal appears in this period's set, though the regional OT threat environment documented in S40 is relevant context. India's aggregate posture is one of institutional expansion rather than defensive consolidation.

US and Allied Force Planning

US and allied force planners face a dual signal this period: the US regulatory architecture is hardening and expanding — FCC component-ban (S9, low confidence, media report), BIS UAE reclassification (S33), submarine cable licensing (S4, S36) — but the OT attack on water utilities in multiple states (S6, high confidence) demonstrates that domestic critical infrastructure remains exploitable through known, unpatched vulnerabilities. The Australia-Singapore SAJMC cyber MoU renewal (S3) and Pacific Cyber Week coordination across PNG, Australia, and the US (S22, S23) reflect allied capacity-building momentum in the South Pacific. The Quad Manila statement (S10) and ASEAN cyber-norms suite announced by Singapore (S21) extend the normative framework. For planners, the key gap is the mismatch between the sophistication of the exclusion architecture being built at the supply-chain level and the persistent failure to remediate CVEs in legacy OT systems that adversaries are actively exploiting.

Watch Items & Signposts

  • WAICO secretariat appointment or first technical working-group convening: if this occurs before end-2026, it would confirm that the organisation is operationally rather than declaratorily oriented, materially upgrading the AI governance rivalry assessment.
  • FCC component-ban order legal challenge outcome: any federal court grant of a stay or preliminary injunction against the component-level equipment ban reported in S9 would reopen the component-traceability enforcement gap that the July order was designed to close.
  • US attribution of the 26–27 July multi-state water-utility PLC attack to a named state or state-affiliated actor: attribution would determine whether the incident represents a shift in adversary targeting doctrine toward civilian infrastructure and would trigger allied policy responses.
  • CXMT production ramp verification: independent industry reporting confirming or revising the company's reported DRAM market-share trajectory and actual wafer-output volumes in Q4 2026 would allow an evidence-based assessment of whether China's memory-chip self-sufficiency timeline has genuinely accelerated.

Collection Methodology, Coverage & Limitations

TechnologyDigital.AIGovernanceAndDataSovereigntyTechnologyDigital.CriticalInfrastructureTechnologyDigital.CyberOperationsAndCapacityTechnologyDigital.DigitalInfrastructureTechnologyDigital.SemiconductorAndCompute
RC01 China
14
signals · max mag 5
AIGovernanceAndDataSovereignty · DigitalInfrastructure · SemiconductorAndCompute
RC05 Cross-Strait
1
signal · max mag 3
CyberOperationsAndCapacity
RC09 Cyber & Technology
36
signals · max mag 5
AIGovernanceAndDataSovereignty · CriticalInfrastructure · CyberOperationsAndCapacity

Domain Breakdown

TechnologyDigital 51 100%
Share of this brief's 51 signals by top-level domain.

Attribution — actor → target

Japan → India 4 15%
China (no stated target) 3 11%
Australia (no stated target) 3 11%
China → Taiwan 2 7%
SouthKorea (no stated target) 2 7%
China → Russia 1 4%
China → US 1 4%
Taiwan → US 1 4%
Japan (no stated target) 1 4%
US → Australia 1 4%
ASEAN (no stated target) 1 4%
Philippines → ASEAN 1 4%
Australia → ASEAN 1 4%
Philippines (no stated target) 1 4%
India → ASEAN 1 4%
China → Philippines 1 4%
Taiwan (no stated target) 1 4%
US (no stated target) 1 4%
27 of 51 signals carry a stated actor · who is directing activity at whom, among what this brief covers, not a claim about the theatre as a whole

How to Read This Brief

Magnitude — computed
Magnitude is not judged directly. It is the sum of three coded components, banded 1–5. Hover a magnitude pill to see its components.
Reversibility1 reversible · 2 costly · 3 irreversible
Scope1 bilateral · 2 sub-regional · 3 regional · 4 systemic
Novelty1 routine · 2 variation · 3 first observed
5sum 9–10
4sum 7–8
3sum 5–6
2sum 4
1sum 3
Strategic Effect
SignallingCommunicates intent or resolve
DeterrenceDesigned to prevent adversary action
CapacityDisplayDemonstration of existing or growing capability
EscalationRaises tension or crosses a threshold
DeEscalationReduces tension or creates off-ramps
MixedOrAmbiguousCross-cutting or unclear primary effect
NotAssessedEffect not assigned
Mode — how it was conducted
OvertAcknowledged, conducted openly
SubThresholdAttributable, calibrated below armed conflict
DeniableAttribution contested or refused
Mode is a property of conduct, not of subject matter. Only non-Overt modes are tagged in the timeline.
Capability · Intent · Leverage
CapabilityWhat an actor can do
IntentWhat an actor plans or seeks
LeverageWhat an actor uses to influence others
Confidence — computed
Derived from source reliability (A–E) and corroboration (number of independent sources on the same event), not judged directly. Most signals in this register are single-sourced and therefore sit at Medium or below.
Timeline entries show Obs (raw event) and Assessment (IPSC analysis) separately.

Citation & Licence

Cite as Indo-Pacific Studies Center. Technology & Digital Competition, Indo-Pacific Strategic Dynamics, August 2026 Edition, Strategic Brief Issue 001. Indo-Pacific Studies Center, 29 August 2026.
Plain text Indo-Pacific Studies Center. "Technology & Digital Competition," Indo-Pacific Strategic Dynamics, August 2026 Edition, Strategic Brief Issue 001. Indo-Pacific Studies Center, 29 August 2026.
Basis 51 signals across 5 subdomains of TechnologyDigital, contributed by 3 research centres.
Contributing centres RC01 China (14) · RC05 Cross-Strait (1) · RC09 Cyber & Technology (36). Centre attribution for each signal appears in the annex register.
Copyright © 2026 Indo-Pacific Studies Center (www.indo-pacificstudiescenter.org). Licensed under CC BY-NC-ND 4.0 — attribution required; no commercial use; no derivatives. This brief is produced for analytical and informational purposes and does not constitute official policy advice.

Annex — Assessed Evidence

1 Jul 2026
RC01
S51 XPHOR Silicon Photonics STAR Market IPO Filing Accepted
TechnologyDigital.SemiconductorAndCompute
ObsThe Shanghai Stock Exchange disclosed on 1 July 2026 that it had accepted the STAR Market IPO filing of XPHOR, a Shanghai-based silicon photonics company. XPHOR plans to raise 2.43 billion yuan (~USD 357.75 million) to fund capacity expansion for silicon photonic chips needed by AI computing and data centres, R&D for next-generation silicon photonic products, and construction of an in-house R&D hub. The filing is part of a broader 2026 IPO acceleration trend driven by AI computing demand and China's push for technological self-reliance.
AssessmentThe XPHOR IPO filing represents a specific instance of China's accelerating state-backed capital mobilisation into next-generation chip subsectors. Silicon photonics is a dual-use technology with significant implications for high-speed data centre interconnects and telecommunications infrastructure; its domestic industrialisation reduces China's dependency on foreign optical integration components and aligns with the 15th Five-Year Plan's equipment localisation goals.
Mag 2 CapacityDisplay Capability MediaReport
1 Jul 2026
RC09
S49 AID-CLOUD
TechnologyDigital.AIGovernanceAndDataSovereignty
SoutheastAsia
ObsSingapore Ministry of Digital Development and Information (MDDI) and IMDA opened public consultation on draft Digital Infrastructure Bill (DIB) on 1 July 2026; consultation closed 22 July 2026. Bill introduces two new licensing regimes: a Major Foundational Digital Infrastructure (FDI) licence mandatory for third-party co-location/cloud data centres ≥10 MW critical IT load and major IaaS/PaaS providers earning ≥S$100m/year in Singapore; and a DC Operator licence for data centres ≥3 MW with mandatory PUE requirements. Non-compliance penalties up to S$1 million or 10% of Singapore annual turnover. Draft bill has extraterritorial reach. This is the first time Singapore brings the compute layer under hard-law regulation. Date of consultation opening: 1/7/2026.
AssessmentStructurally significant: if enacted, the DIB is Singapore's first statutory instrument regulating the compute-infrastructure layer, pulling AI data centres and cloud hyperscalers (AWS, Azure, Google Cloud) into a licensing regime. Extraterritorial scope affects all major global cloud providers serving Singapore. Consultation stage only — magnitude capped at 4 pending enactment — but the draft text represents a qualitative escalation in Singapore's digital infrastructure governance and a direct capacity-display signal to regional digital dependency map.
Mag 2 CapacityDisplay Capability OfficialDocument
1 Jul 2026
RC09
S50 AID-LOCAL
TechnologyDigital.AIGovernanceAndDataSovereignty
SoutheastAsia
ObsVietnam's Law on Cybersecurity No. 116/2025/QH15 entered into force on 1 July 2026, replacing both the Law on Network Information Security 2015 and the Cybersecurity Law 2018. Enacted by the National Assembly on 10 December 2025, the law establishes a unified cybersecurity and network information security framework with strengthened obligations on platforms and AI-generated content, prohibits use of AI to forge images/voices/videos for illegal purposes, and requires covered service providers to provide user information to Ministry of Public Security (A05) within 24 hours on request (3 hours in urgent cases). Extraterritorial effect applies to foreign individuals and organisations involved in cybersecurity activities or products in Vietnam. Date in force: 1/7/2026.
AssessmentBinding instrument with extraterritorial reach and platform-level obligations — a structural shift that tightens the Ministry of Public Security's legal grip on foreign cloud and platform operators. Entry into force consolidates Vietnam's sequential layering of data governance statutes (Law on Data Jul 2025, PDPL Jan 2026, Cybersecurity Law Jul 2026) into an increasingly restrictive cross-border data regime. Represents a structural shift rather than symbolic positioning.
Mag 3 Escalation Capability OfficialDocument
2 Jul 2026
RC01
S45 India-Japan economic security declaration targets semiconductors and ICT
TechnologyDigital.SemiconductorAndCompute
NortheastAsia
Japan → India
ObsIndia and Japan adopted a joint declaration on economic security promoting project-based collaboration in semiconductors, critical minerals, ICT including AI, clean energy and pharmaceuticals.
AssessmentThe declaration elevates semiconductor and digital supply-chain resilience into bilateral economic-security strategy and reduces dependence on China-centred technology ecosystems.
Mag 3 NotAssessed Intent OfficialDocument
2 Jul 2026
RC01
S46 India-Japan AI cooperation elevated to strategic R&D partnership
TechnologyDigital.AIGovernanceAndDataSovereignty
NortheastAsia
Japan → India
ObsIndia and Japan issued a joint statement on AI cooperation to elevate the relationship into a strategic research and development partnership across the AI stack for safe, secure, trusted, inclusive and human-centric AI.
AssessmentThe statement builds an allied AI-development pathway outside the Chinese ecosystem and supports standards alignment between two major Indo-Pacific technology actors.
Mag 3 NotAssessed Capability OfficialDocument
2 Jul 2026
RC01
S47 IndiaAI and Japan METI link AI compute and project support
TechnologyDigital.SemiconductorAndCompute
NortheastAsia
Japan → India
ObsIndiaAI Mission and Japan METI agreed to cooperate through B2B matchmaking, webinars on AI policies and challenges, and support for joint projects through access to computing resources under IndiaAI and GENIAC.
AssessmentThe arrangement adds operational depth to India-Japan AI cooperation by linking firms, policy exchanges and compute access in a non-Chinese innovation channel.
Mag 3 NotAssessed Capability OfficialDocument
2 Jul 2026
RC01
S48 India-Japan internet registry cooperation advances IPv6 and security
TechnologyDigital.DigitalInfrastructure
NortheastAsia
Japan → India
ObsIndia's National Internet Exchange and Japan Network Information Center signed a memorandum to cooperate on national internet registry operations, IPv6 adoption, internet security improvements, capacity building and internet governance exchanges.
AssessmentThe memorandum strengthens trusted digital infrastructure cooperation between India and Japan and modestly diversifies technical governance away from China-centred platform and standards influence.
Mag 2 NotAssessed Capability OfficialDocument
2 Jul 2026
RC01
S44 Taiwan probe targets alleged AI server exports to China
TechnologyDigital.SemiconductorAndCompute
TaiwanStrait
China → Taiwan
ObsSuper Micro said two Taiwan employees were detained and two released on bail after Taiwanese prosecutors investigated alleged illegal exports of advanced AI servers containing Nvidia chips to China.
AssessmentThe investigation shows Taiwan enforcing controls around AI server supply chains and reducing pathways for restricted US-linked compute hardware to reach Chinese end users.
Mag 3 SubThreshold NotAssessed Leverage MediaReport
2 Jul 2026
RC01
S43 Chinese GLM-5.2 model gains global developer traction
TechnologyDigital.AIGovernanceAndDataSovereignty
ExtraRegional
China → US
ObsReuters reported that Z.ai's inexpensive GLM-5.2 model was gaining Western developer interest and approaching leading US model performance at lower cost. (using publication date as proxy)
AssessmentThe uptake indicates Chinese AI models can compete internationally despite chip controls, expanding China's influence over global developer ecosystems and open-model adoption pathways.
Mag 4 Deniable NotAssessed Capability MediaReport
2 Jul 2026
RC09
S42 CBL-BUILD
TechnologyDigital.DigitalInfrastructure
India → ASEAN
ObsOn 2 July 2026 in Hyderabad India a consortium comprising Lightstorm (majority owner) Microsoft Singtel and Tata Communications officially signed contracts to build the India-Southeast Asia (I-2SEA) submarine cable system. NEC Corporation was simultaneously announced as system supplier and ASEAN Cableship Pte Ltd as marine installation partner. The cable will extend approximately 3600 km connecting dual landings in India (Machilipatnam and South Chennai) with Malaysia (Kuala Lumpur) and Singapore. I-2SEA is explicitly designed for AI and hyperscaler workloads and is targeted for Ready-for-Service in Q4 2029. The corridor bypasses HMN Technologies (formerly Huawei Marine) entirely; NEC as vendor and ASEAN Cableship as installer constitute a trusted-vendor supply chain consistent with Quad Cable Connectivity and Resilience Program objectives. No landing permits or regulatory approvals were announced at contract signing — permit filings to DoT India IMDA Singapore and MCMC Malaysia are expected subsequently.
AssessmentVendor selection of NEC over HMN Technologies and majority control by Singapore/India/US-aligned consortium (Lightstorm/Singtel/Microsoft/Tata) represents a material de-risking of the India–Southeast Asia corridor. The Malacca/Singapore chokepoint interlock is directly addressed: both Singapore and Malaysia landings lie on or near the Malacca corridor. The system's AI-workload orientation signals a first-mover infrastructure posture linking India's GPU clusters to Singapore's cloud hub. Landing permit status is the critical outstanding variable — if Indian DoT or IMDA introduce delays this would constitute a separate CBL-PERMIT signal. Confidence High per official NEC press release and Lightstorm announcement.
Mag 3 CapacityDisplay Capability OfficialDocument
3 Jul 2026
RC01
S41 Taiwan opens Phoenix office to anchor semiconductor corridor
TechnologyDigital.SemiconductorAndCompute
TaiwanStrait
Taiwan → US
ObsTaiwan announced it would establish a Taipei Economic and Cultural Office in Phoenix to support Taiwanese businesses and promote cooperation in trade, technology, education and supply chains around Arizona's semiconductor cluster.
AssessmentThe office deepens Taiwan-US semiconductor ecosystem integration and supports resilient technology supply chains outside China's political and industrial orbit.
Mag 3 NotAssessed Capability OfficialDocument
5 Jul 2026
RC09
S40 CRI-INTRUDE
TechnologyDigital.CriticalInfrastructure
SoutheastAsia
China
ObsPalo Alto Networks Unit 42 reported on 5 July 2026 that China-linked threat actor CL-STA-1062 (also tracked as UAT-7237) has successfully targeted electricity and water utility providers in multiple Southeast Asian countries deploying a novel backdoor dubbed TinyRCT. Unit 42 investigated more than 10 attacks; at least three critical infrastructure entities including two state-owned energy organisations in one unnamed SEA country were compromised. The lightweight C# backdoor enables remote command execution, file exfiltration, screenshot capture, and self-deletion with anti-forensics. In some cases the actor stopped after gaining access and fingerprinting the environment; in others intrusion chains spanned from initial access to full exfiltration pivoting between government entities.
AssessmentUnit 42 assessed with high confidence that CL-STA-1062 shares overlaps with Cisco Talos-tracked UAT-7237; vendor confidence language: 'high confidence' overlap assessment. Campaign targeting state-owned energy and water entities across SEA indicates strategic pre-positioning consistent with PRC intelligence collection and disruption preparation. No CERT or operator confirmation of OT layer compromise published; confidence capped at Medium per corroboration rule.
Mag 4 Signalling Capability IndustryReport
7 Jul 2026
RC01
S39 FCC blocks Chinese-linked telecom services firm
TechnologyDigital.DigitalInfrastructure
ExtraRegional
China
ObsThe FCC denied Digitalsystem Technology permission to provide international telecom services and placed it on a national-security risk list, citing Chinese ownership links and partnerships with Chinese telecom operators.
AssessmentThe decision extends US technology decoupling into telecom-service authorisation and reduces Chinese-linked access to international communications infrastructure.
Mag 2 NotAssessed Leverage MediaReport
7 Jul 2026
RC05
S38 PRC Cyberespionage Social-Engineering Network Charged in Taiwan
TechnologyDigital.CyberOperationsAndCapacity
TaiwanStrait
China → Taiwan
ObsTaipei City Investigation Office issued deferred prosecution orders on 7 July against two executives of local firm Abigail — Li Hualun and Chen Mengsen — for renting Taiwan mobile-registered LINE accounts to Xiamen Empress Information Technology Co. Ltd. allegedly linked to China's cyber army. The accounts enabled Chinese operators to impersonate journalists and conduct social-engineering attacks against Taiwanese officials scholars and NGO workers. The ICIJ and Citizen Lab's Citizen Lab had previously documented the campaign as GLITTER CARP/SEQUIN CARP operations. Malware disguised as encrypted communications software was also deployed.
AssessmentThis case reveals a maturing hybrid model: PRC cyber operators sub-contracting to Taiwan-resident facilitators to launder attribution. Targeting politicians academics and NGO workers serves dual objectives — intelligence collection and suppression of pro-Taiwan civil society voices. The timing ahead of November 2026 local elections amplifies the influence-operation risk. Confidence is high given corroborating ICIJ and Citizen Lab technical attribution.
Mag 3 Deniable Signalling Intent OfficialDocument
7 Jul 2026
RC09
S37 CRI-INTRUDE
TechnologyDigital.CriticalInfrastructure
NortheastAsia
ObsOn 7 July 2026 KDDI Corporation confirmed that attackers exploited a zero-day vulnerability in third-party email platform software (vendor and CVE not yet publicly named) to breach a shared email infrastructure platform serving six Japanese ISPs — KDDI au one net, STNet, JCOM, Chubu Telecommunications, NIFTY, and BIGLOBE. Breach date was 16 May 2026; KDDI detected and blocked access on 17 June 2026. Forensic investigation confirmed exposure of 12.2 million email addresses and 7.6 million passwords. KDDI reported the incident to Japan's Ministry of Internal Affairs and Communications. No evidence of system access beyond the exploited vulnerability; no malware deployment confirmed. No attribution to known threat actor.
AssessmentDisclosure of a zero-day without a CVE number or named vendor is analytically unusual and limits defenders. KDDI's telecom infrastructure sits at the heart of Japanese digital connectivity; shared ISP platform architecture means a single exploit achieved multi-operator exposure. No threat actor attribution available at time of publication. Magnitude scored 4 (High) on the basis of scale — 12.2 million credentials exposed across national telecom infrastructure — though service availability was not degraded.
Mag 3 Signalling Capability MediaReport
8 Jul 2026
RC09
S36 CBL-PERMIT
TechnologyDigital.DigitalInfrastructure
ObsOn 8 July 2026 the FCC announced via Federal Register (DA 26-684 / 91 Fed. Reg. 42137) that the remaining provisions of its First Report and Order on Submarine Cable Landing License Rules — held pending OMB PRA approval — became effective. These provisions include mandatory prior-approval and notification requirements for cable landing licensees that become or propose to become foreign adversary-controlled (47 CFR 1.70009) as well as updated application and definitional requirements. The rules constitute the first comprehensive overhaul of US submarine cable licensing in over 25 years and presumptively preclude landing license grants to entities owned by or subject to the direction of a foreign adversary including China. Entities owning or operating SLTE on US-connected cables — including Indo-Pacific trans-Pacific systems — are now brought within this licensing framework.
AssessmentThis effective-date announcement operationalises the structural exclusion of Chinese entities from US-connected trans-Pacific cable infrastructure. For Indo-Pacific cable systems with US termini (e.g. Pacific Light Cable Network TGN-Pacific Unity FASTER HKA and others transiting the Luzon/Bashi and trans-Pacific corridors) the practical effect is that any Chinese-linked ownership or SLTE operation requires FCC pre-approval or faces presumptive denial. The 8 July effective date coincides with the ongoing SEA-H2X commercial launch (see RC09WSA-2026-07-006) and the I-2SEA build announcement creating a clear bifurcation of the Indo-Pacific cable market along trusted/non-trusted vendor lines. Confidence High per Federal Register official document.
Mag 4 Deterrence Intent OfficialDocument
9 Jul 2026
RC09
S34 CMP-CAPEX
TechnologyDigital.SemiconductorAndCompute
ObsMicron poured first concrete at its Clay New York $100B semiconductor megafab on 9 July 2026 — more than one quarter ahead of the original schedule. The milestone marks transition from site preparation to vertical construction on what will be the largest semiconductor facility in US history with up to four fabs planned. Simultaneously Micron raised its total planned US investment from $200B to more than $250B through 2035. The campus targets DRAM and HBM memory production. First wafer output at Micron's Idaho plants is expected mid-2027 and late 2028. Governor Hochul described it as the largest private investment in New York State history. CHIPS Act grants underpin the investment.
Assessment"Largest private investment in New York State history" per Governor Hochul. Provides a US-domiciled DRAM/HBM source that reduces dependence on Korean and Taiwanese memory supply transiting Taiwan Strait and Luzon chokepoints. HBM is the critical memory substrate for AI accelerators; domestic HBM capacity is directly relevant to US AI compute resilience in a Taiwan Strait contingency. Timeline risk exists given first Idaho fab output not until mid-2027.
Mag 5 Deterrence Capability MediaReport
9 Jul 2026
RC09
S35 CMP-INPUT
TechnologyDigital.SemiconductorAndCompute
ObsMicron announced on 9 July 2026 a $500M strategic financing package to GlobalWafers America and a 10-year supply agreement for 300mm raw silicon wafers from GlobalWafers' Sherman Texas facility — the only CHIPS-program-participating 300mm wafer supplier manufacturing on US soil. The deal is part of a broader $3B Micron US supply-chain investment. GlobalWafers' Texas facility will approximately double installed capacity to ~600K 12-inch wafers/month upon expansion completion. Binding contracts and regulatory approvals remain pending as of announcement date. GlobalWafers (Taiwan-headquartered) is the world's third-largest silicon wafer supplier.
AssessmentRaw 300mm silicon wafers are a critical upstream input for all advanced DRAM and logic fabrication. GlobalWafers' Sherman TX site is the sole US-domiciled advanced 12-inch wafer source; this deal reduces dependence on Taiwanese and Japanese wafer supply that would be disrupted by Taiwan Strait or western Pacific sea-lane interdiction. Wedbush analysts flag wafer supply as a potential chokepoint for the 2028–2030 AI memory ramp. Confidence Medium — binding contracts not yet finalised as of announcement.
Mag 4 Deterrence Capability IndustryReport
10 Jul 2026
RC09
S33 CMP-CTRL
TechnologyDigital.SemiconductorAndCompute
ObsBIS published a Final Rule effective 10 July 2026 (Federal Register 14 July 2026 2026-14132) reclassifying the UAE from EAR Country Groups D:3 and D:4 into Country Group A:5. The rule provides UAE Government entities and approved commercial entities — specifically G42 and Core42 — with licence-free access to advanced computing items including Nvidia Blackwell and AMD Instinct AI chips. US hyperscaler subsidiaries in the UAE are also approved under Supplement No. 8 to Part 740. The rule is effective immediately; G42 and Core42 STA eligibility expires 270 days from 10 July 2026 unless they become US companies. Rule text cites the May 2025 US-UAE AI Acceleration Partnership framework.
AssessmentDe-escalatory for US-UAE bilateral tech relationship but escalatory in the structural sense: institutionalises a non-Taiwan AI compute node of strategic scale. Stargate UAE Phase 1 (200MW ~100k GB300 chips) is confirmed for Q3 2026 go-live. Regulatory primary text available at Federal Register. Diversion risk from UAE to third parties (including PRC-connected entities) is non-trivial given UAE's role as a transit hub; BIS affiliate rule snaps back November 2026. Confidence High — primary source is Federal Register.
Mag 4 Signalling Intent OfficialDocument
14 Jul 2026
RC09
S31 AID-TRANSFER
TechnologyDigital.AIGovernanceAndDataSovereignty
SoutheastAsia
ObsOn 13–14 July 2026 the Vietnamese Ministry of Justice released a formal assessment of the draft Law on Data Security. The draft introduces a four-tier data classification system (ordinary, internal, important, core) and permanently bans cross-border transfer of core data. Important data and large-scale personal data may only be transferred abroad with prior Ministry of Public Security approval. Draft open for public comment 17 July–5 August 2026; government targeting October 2026 National Assembly session for passage. The draft constitutes the fourth statutory data governance layer in approximately 24 months, stacking atop the Law on Data (Jul 2025), PDPL (Jan 2026), and Cybersecurity Law (Jul 2026). No deconfliction mechanism between overlapping regimes specified. Raises potential CPTPP inconsistency flagged by analysts.
AssessmentPre-legislative at this stage (magnitude 4 reflects extraterritorial reach and structural rerouting potential if enacted). The hard ban on core data exports and prior-approval gate for important data would, if enacted, constitute a magnitude-5 severance/rerouting event. Classified as Intent/Escalatory now based on draft text; should be upgraded upon passage. CPTPP inconsistency risk adds a secondary escalation vector.
Mag 2 Escalation Capability OfficialDocument
14 Jul 2026
RC09
S32 SPC-SATCOM
TechnologyDigital.DigitalInfrastructure
SouthChinaSea
Philippines
ObsOn 14 July 2026 Philippines carrier Cebu Pacific announced a partnership with SpaceX Starlink to bring LEO satellite in-flight connectivity to its fleet from 2027, making it the first low-cost carrier in Southeast Asia to adopt Starlink. The deal is part of a coordinated deployment by investor Indigo Partners across more than 1,000 aircraft (also covering Frontier Airlines, Wizz Air, Volaris, and JetSMART). Starlink service will cover passenger broadband and operational crew connectivity. Financial terms were not disclosed. Cebu Pacific operates 101 aircraft on 35 domestic and 26 international routes including routes transiting the South China Sea and Luzon Strait corridor.
AssessmentAs the first SEA LCC Starlink agreement, this embeds SpaceX's LEO constellation as the connectivity backbone for Philippine aviation at operational and passenger levels. Flights crossing the Luzon Strait and SCS chokepoints will carry Starlink-dependent navigation and crew communications. This deepens Philippine aviation's dependency on a US-headquartered LEO operator, raising both resilience and geopolitical-dependency signals vis-à-vis Chinese alternative constellations (Qianfan/SpaceSail) seeking market entry across the region.
Mag 4 Signalling Capability MediaReport
15 Jul 2026
RC01
S30 CAC Anthropomorphic AI Interaction Measures Enter Force – Data Governance Expanded
TechnologyDigital.AIGovernanceAndDataSovereignty
ObsThe Interim Measures for the Administration of AI Anthropomorphic Interactive Services, jointly issued by the CAC and four co-regulators on 10 April 2026, entered force on 15 July 2026. The measures establish China's first dedicated regulatory regime for AI services that simulate human personality — covering virtual companions, emotional support bots, and AI chatbots. Obligations include mandatory CAC algorithm filing, security assessments, user disclosure, anti-addiction safeguards, and data localisation. ByteDance (Doubao) and Alibaba (Qwen) shut down personalized AI agent features that could not meet compliance requirements in time.
AssessmentThe entry into force of these measures extends China's AI governance architecture into the affective and social computing domain, imposing data localisation and security review requirements that create extraterritorial compliance burdens for non-Chinese platforms serving Chinese users. The forced shutdown of Alibaba and ByteDance agent features underscores the real enforcement weight behind the framework and sets a precedent likely studied by other Indo-Pacific regulators developing AI governance norms.
Mag 4 Signalling Intent OfficialDocument
16 Jul 2026
RC01
S29 WAICO Founded – China-Led Global AI Governance Body Established by 29 States
TechnologyDigital.AIGovernanceAndDataSovereignty
China → Russia
ObsOn 16 July 2026, representatives of 29 countries signed the founding agreement of the World Artificial Intelligence Cooperation Organization (WAICO) in Shanghai. WAICO is headquartered in Shanghai and oriented toward the Global South. China's Foreign Minister Wang Yi signed on behalf of Beijing; UN Secretary-General António Guterres attended. Founding members include Russia, Indonesia, Brazil, Pakistan, Kazakhstan, Laos, Belarus, Serbia, Cuba, Venezuela, and 10 African and 12 Asian countries. The G7 advanced economies — the US, Japan, UK, Germany, France, South Korea, Canada, and Australia — were not founding members. WAICO is viewed as rivalling the US-led Pax Silica initiative.
AssessmentWAICO is the most strategically significant digital governance development of the July 2026 window. Beijing has converted its WAIC platform advantage into a permanent intergovernmental institution headquartered on Chinese soil, with an Indo-Pacific-heavy founding membership that includes key Southeast Asian states. The exclusion of all G7 nations signals a deliberate bifurcation of global AI governance architecture. For the Indo-Pacific, WAICO creates a competing standard-setting locus that Beijing will use to advance Chinese AI norms, data governance frameworks, and infrastructure preferences in developing economies currently contested between US and Chinese digital ecosystems.
Mag 5 Escalation Intent MediaReport
16 Jul 2026
RC09
S27 AID-ENFORCE
TechnologyDigital.AIGovernanceAndDataSovereignty
Australia
ObsOn 16 July 2026 the OAIC published its report concluding preliminary inquiries into the 2025 Qantas data breach affecting approximately 5.12–5.67 million Australians. Breach occurred via social engineering (vishing) attack on an overseas third-party call centre provider in Manila. OAIC assessed compliance with APPs 1 (management), 8 (cross-border disclosure) and 11 (security). Commissioner Carly Kind found no evidence of breach of Privacy Act obligations; declined to commence a Commissioner-Initiated Investigation at this stage but retained discretion to re-open. No penalty imposed. Inquiry conducted between 11 July 2025 and 1 June 2026. The incident involved cross-border data processing via an overseas outsourced provider.
AssessmentThe no-further-action outcome is analytically significant as a precedent-setter: it clarifies that APP 8 cross-border disclosure obligations can be satisfied through third-party contractual compliance measures even when a breach occurs at an offshore provider. De-escalatory for regulated entities regarding cross-border outsourcing risk but does not reduce overall sector risk posture. Magnitude 2 given no penalty and no binding determination against the respondent.
Mag 1 DeEscalation Intent OfficialDocument
16 Jul 2026
RC09
S28 CAP-STD
TechnologyDigital.CyberOperationsAndCapacity
SoutheastAsia
SouthKorea
ObsSouth Korea's Telecommunications Technology Association (TTA) adopted the Joint Declaration for the Promotion of ICT Standards and Capacity Building in the Asia-Pacific Region with the ITU at the ITU Regional Development Forum for Asia and the Pacific (RDF-ASP) in Bangkok on 16 July 2026. The declaration focuses on ICT standardisation and human capacity building, expanded expert participation, stronger exchanges, and sharing of best practices to promote uptake of ITU standards in the region. The cooperation builds on TTA's information-security standards training conducted in February 2026 for 15 Asia-Pacific and CIS countries.
AssessmentKorea is positioning TTA as the lead standards-capacity-building partner for ITU in the Asia-Pacific, projecting K-standards internationally and building regulatory alignment with Seoul. This declaration directly expands Korean vendor and standards influence across the region, with implications for competition with Chinese standards-promotion efforts through ITU channels. The ITU's hosting of the RDF-ASP at Bangkok, co-located with APT's ADF-23, amplifies regional reach.
Mag 2 CapacityDisplay Capability OfficialDocument
17 Jul 2026
RC01
S26 WAIC 2026 – Xi Jinping Keynote and Huawei Atlas 950 SuperPoD Debut
TechnologyDigital.SemiconductorAndCompute
ObsThe 2026 World Artificial Intelligence Conference (WAIC) opened in Shanghai on 17 July 2026 with Xi Jinping delivering his first-ever WAIC keynote. Huawei debuted the Atlas 950 SuperPoD — the industry's largest super-node architecture enabling 1,024 Ascend NPU cards to operate as a single compute unit (the physical unit features 8,192 Ascend cards per cluster). Over 300 AI products made their global debut; more than 1,100 enterprises participated across an exhibition exceeding 100,000 sq metres. Xi announced China would provide 5,000 exchange-programme quotas and establish AI cooperation centres with ASEAN, the Arab League, the African Union, CELAC, BRICS, and SCO partners over five years.
AssessmentWAIC 2026 served as China's primary technology diplomacy platform for July, combining hardware capability demonstration with institutional and normative outreach. The Huawei Atlas 950 debut is a direct Capability signal: it demonstrates that China is assembling frontier-class AI compute infrastructure from domestic components despite US chip controls. Xi's 5,000 scholarship pledge and ASEAN/Global South cooperation centre announcements are concrete instruments for embedding Chinese AI platforms and training norms in Indo-Pacific institutions.
Mag 3 CapacityDisplay Capability OfficialDocument
17 Jul 2026
RC09
S25 AID-TRANSFER
TechnologyDigital.AIGovernanceAndDataSovereignty
NortheastAsia
Japan
ObsJapan's amended Act on the Protection of Personal Information (APPI) was promulgated on 17 July 2026 as Law No. 56 following Diet passage on 10 July 2026. Cabinet approved the amendment bill on 7 April 2026 for submission to the Diet. Key AI-relevant changes: introduces administrative monetary fines for the first time (replacing criminal-penalty-only regime); creates a new consent exemption for statistical analysis and AI model training allowing use of publicly available sensitive personal data without consent subject to transparency measures and contractual safeguards; strengthens protections for children's data and biometric data. Effective date to be set by Cabinet order within two years of promulgation (i.e. by July 2028). Extraterritorial reach applies to foreign companies handling personal information of individuals in Japan.
AssessmentStructural shift: Japan's APPI amendment is enacted law even though not yet in force. The consent exemption for AI training data responds directly to domestic AI development imperatives and signals a deliberate 'data-free-flow with trust' deregulatory posture that diverges from the EU AI Act trajectory. The introduction of administrative fines represents the most significant enforcement upgrade to the APPI since the 2017 revision. Affects all Indo-Pacific operators running AI workloads involving Japanese personal data.
Mag 3 DeEscalation Capability OfficialDocument
20 Jul 2026
RC09
S20 AID-REG
TechnologyDigital.AIGovernanceAndDataSovereignty
SoutheastAsia
ObsSingapore Personal Data Protection Commission published final Advisory Guidelines on Use of Personal Data in Generative AI on 20 July 2026 at the inaugural Singapore Data Festival; guidelines took effect immediately from 20 July. Guidelines are non-binding but introduce first-of-kind AI-specific notification requirement across the AI supply chain covering development, testing, deployment and procurement stages; PDPC consultation closed 1 July 2026 and final text incorporates accountability and data-minimisation obligations. Date in force: 20/7/2026.
AssessmentNon-binding advisory guidance that nonetheless sets PDPC regulatory expectations and signals Singapore is hardening its AI accountability posture ahead of any standalone AI law; the AI-specific notification requirement is a structural first for PDPC and will inform industry practice regionally. Represents Signalling rather than structural binding shift at this stage.
Mag 3 Signalling Intent MediaReport
20 Jul 2026
RC09
S22 CAP-TRAIN
TechnologyDigital.CyberOperationsAndCapacity
SouthPacific
US → Australia
ObsPacific Cyber Week 2026 opened in Port Moresby on 20 July co-convened by Papua New Guinea, Australia and the United States with Pacific partners, running alongside the PNG Digital Transformation Summit 20-22 July. The week-long programme covered cybersecurity, AI, digital public infrastructure, online safety and cybercrime, and culminated in a Pacific ICT Ministers Meeting. Australian Ambassador for Cyber Affairs and Critical Technology Jessica Hunter and Australian High Commissioner Ewen McDonald attended the opening alongside PNG PM Marape and ICT Minister Naguri.
AssessmentPattern confirms deepening AUS-US bilateral delivery architecture for Pacific cyber capacity. Joint convening with PNG government signals host-country co-ownership model; the pairing with the Pacific ICT Ministers Meeting and Lagatoi Declaration implementation elevates the event above a routine workshop to a structurally significant annual platform. Repeated co-delivery with the US reinforces a complementary donor bloc competing with Chinese digital-infrastructure financing in the Pacific.
Mag 2 CapacityDisplay Capability OfficialDocument
20 Jul 2026
RC09
S23 CAP-FUND
TechnologyDigital.CyberOperationsAndCapacity
SouthPacific
Australia
ObsAt the opening of Pacific Cyber Week on 20 July 2026, Australia confirmed two key capital-infrastructure initiatives with PNG: the Pukpuk Digital Connectivity Initiative to expand PNG's international submarine cable connectivity, and the PNG Telecommunications Blueprint, an independent assessment to guide future investment and reform priorities. Both were presented as joint AUS-PNG partnership deliverables.
AssessmentThis pair of initiatives signals Australia's intent to anchor PNG's digital-infrastructure investment pipeline within a trusted-partner framework. The Pukpuk cable initiative directly competes with Chinese cable-financing offers in the Pacific and provides a concrete capacity signal beyond diplomatic rhetoric. Committed programme and named deliverables place this at magnitude 4.
Mag 3 CapacityDisplay Capability OfficialDocument
20 Jul 2026
RC09
S21 CAP-NORM
TechnologyDigital.CyberOperationsAndCapacity
SoutheastAsia
ASEAN
ObsAt the official dinner of the 4th Digital Defence Symposium on 20 July 2026, Singapore's Permanent Secretary (Defence) Joseph Leong announced a suite of ASEAN cyber-norms initiatives to be advanced under Singapore's ADMM Chairmanship in 2027: (1) working with ASEAN defence establishments toward collective implementation of the 11 UN GGE cyber norms; (2) expanding ACICE-UNIDIR cyber norms workshops for ASEAN member states (first completed April 2026, next in August 2026); (3) hosting the inaugural ASEAN Regional Cyber Exercise co-organised with Singapore's Digital and Intelligence Service; and (4) building on the inaugural ACICE-US Cyber Capacity Building Course. Singapore also identified the ADMM-Plus EWG on Cybersecurity as co-chaired by Cambodia and Australia.
AssessmentThis announcement constitutes the most significant ASEAN cyber-norms initiative for the period. Singapore is leveraging upcoming ADMM chairmanship to set the normative agenda for ASEAN defence cyber cooperation — specifically anchoring regional norms to the UN GGE framework rather than alternative frameworks. The inaugural ASEAN Regional Cyber Exercise is a standing-institution-level commitment. The explicit naming of the ACICE-US course and the Cambodia-Australia EWG co-chair identifies the network of complementary Western-aligned mechanisms.
Mag 3 Signalling Intent OfficialDocument
20 Jul 2026
RC09
S24 SPC-SPEC
TechnologyDigital.DigitalInfrastructure
SouthPacific
ObsOn 20 July 2026 — the opening day of the Digital Transformation Summit 2026 in Port Moresby — PNG's National Information and Communications Technology Authority (NICTA) formally announced the release of 5G spectrum in Papua New Guinea, with NICTA chairman Brian Riches confirming its regulatory review ahead of deployment is nearing completion. The summit (20–22 July) was co-convened with Australia and the United States as part of Pacific Cyber Week and culminated in the first-ever Pacific Islands Forum ICT Ministerial Meeting. Digicel PNG had already declared 5G readiness in a prior consultation period; NICTA's July 2026 announcement represents the formal regulator confirmation triggering the commercial licensing pathway. The 2300 MHz and 3500 MHz bands are under consideration for 5G assignment.
AssessmentPNG's formal 5G release creates an immediate vendor-selection moment for a Pacific state that sits astride key maritime and aerial corridors between Australia and the broader Indo-Pacific. The co-location of the announcement with Pacific Cyber Week — co-hosted by PNG, Australia, and the US — and the Pacific ICT Ministers Meeting signals that trusted-technology concerns are embedded in the decision context. The vendor chosen for PNG's 5G build will have strategic implications for the rest of the Pacific island arc given PNG's infrastructure leadership role.
Mag 3 Signalling Capability OfficialDocument
21 Jul 2026
RC09
S18 CAP-NORM
TechnologyDigital.CyberOperationsAndCapacity
SouthPacific
ObsThe Counter Ransomware Initiative held its Pacific Regional Meeting on 21 July 2026 at Pacific Cyber Week in Port Moresby. The meeting provided an opportunity for Pacific governments and practitioners to discuss ransomware threats and collective response options within the CRI framework. Financial assistance for Pacific delegates was provided by New Zealand, the United States and Australia.
AssessmentThe CRI Pacific Regional Meeting marks a deliberate effort to extend a Western-aligned multilateral ransomware-norms instrument into the Pacific Islands Forum space. Holding it as an embedded side-event of Pacific Cyber Week institutionalises CRI engagement with Pacific states whose cyber-incident response capacity remains nascent. The donor-funded attendance model reflects influence-building as well as capacity delivery.
Mag 2 Signalling Intent OfficialDocument
21 Jul 2026
RC09
S17 CAP-TRAIN
TechnologyDigital.CyberOperationsAndCapacity
SoutheastAsia
ObsThe ADMM Cybersecurity and Information Centre of Excellence (ACICE) and RSIS co-hosted the 4th Digital Defence Symposium (DDS) on 21-22 July 2026 at Raffles City Convention Centre, Singapore. The symposium convened ASEAN and partner-nation defence officials on the theme 'Building Digital and Information Resilience: Technology, Norms, and the Cyber Information Continuum', alongside the 4th ASEAN Roundtable on Navigating the Digital Space and the 5th ACICE Advisory Board Meeting. Partner nations attending included Australia, China, Estonia, Germany, Italy, Japan, Lithuania, the UK and the US.
AssessmentThe DDS is ACICE's flagship multilateral training-and-norms platform. The simultaneous inclusion of China and Western partners reflects ACICE's formal ASEAN centrality posture, but the deliberate listing of like-minded partners signals Singapore's management of dual-track engagement. The accompanying ACICE Advisory Board meeting adds institutional continuity beyond the symposium itself.
Mag 2 CapacityDisplay Capability OfficialDocument
21 Jul 2026
RC09
S19 SPC-ITU
TechnologyDigital.DigitalInfrastructure
Regionwide
SouthKorea
ObsSouth Korea's Electronics and Telecommunications Research Institute (ETRI) led the development and approval of an ITU-R Spectrum Management Study Group 1 report titled 'Methodologies for assessing or predicting spectrum availability' using machine learning techniques. The report was approved at the SG1 meeting in Geneva in the week ending 27 July 2026 and is undergoing final editorial procedures before formal publication. ETRI's leadership of this standardisation work positions South Korea as a proponent of AI-driven spectrum management norms within the ITU-R framework, with implications for how future spectrum assessments — including contested cross-border allocations — are conducted internationally. (Using publication date as proxy for approval date per Cenerva week-to-27-July-2026 report.)
AssessmentThis is a standards-layer signal rather than an allocation decision, but it is analytically significant: AI-based spectrum-availability assessments approved under ITU-R could reshape how Indo-Pacific states defend or contest spectrum filings in future WRC negotiations. South Korea's authorship gives it first-mover positioning in a methodology that may eventually be applied to contested NGSO coordination disputes between China and its neighbours — including over Ku/Ka satellite slots covering the SCS.
Mag 3 Signalling Capability MediaReport
22 Jul 2026
RC09
S10 CAP-NORM
TechnologyDigital.CyberOperationsAndCapacity
SoutheastAsia
Philippines → ASEAN
ObsThe Quad Foreign Ministers met in Manila on 22 July 2026 on the sidelines of the ASEAN Post-Ministerial Conference and issued the first-ever dedicated Quad joint statement on cooperation with ASEAN. The statement affirmed cooperation on shared priorities including critical and emerging technologies, maritime and transnational security, and pledged closer coordination against malicious cyber activity. Ministers also committed to action against North Korean cyber activities funding Pyongyang's weapons programmes.
AssessmentThe Quad's first dedicated joint statement with ASEAN is a structural milestone in Quad-ASEAN cyber-diplomacy. By framing Quad partners as 'ASEAN Comprehensive Strategic Partners', the document positions the grouping as an inside stakeholder in ASEAN's digital-governance agenda rather than an external counterweight. The explicit cyber reference is non-binding but politically significant given ASEAN's prior wariness of the Quad.
Mag 4 Signalling Intent OfficialDocument
22 Jul 2026
RC09
S9 SPC-VENDOR
TechnologyDigital.DigitalInfrastructure
ExtraRegional
ObsFCC voted 22 July 2026 to close the component-part loophole in its Covered List rules by prohibiting FCC equipment authorisation for any device incorporating logic-bearing hardware components produced by Huawei, ZTE, Hikvision, Dahua, Hytera, DJI, or Autel. The order moves the ban from the assembled-device level to the chipset level — the deepest expansion yet — and effectively bars HiSilicon-chipped devices from the US market regardless of the assembling brand. A Further NPRM proposes mandatory full bill-of-materials disclosure for all FCC applicants, which would create the first supply-chain transparency mechanism for consumer electronics in US regulatory history. This follows a June 2026 FCC action that already extended the import ban to pre-2022 legacy Covered List models effective July 2026.
AssessmentThe chipset-level ban reshapes global supply chains for consumer and commercial electronics exported through or to US-aligned Indo-Pacific partners. Vendors supplying 5G RAN or CPE equipment to Southeast Asian and Pacific operators who also seek US market access or US-funded connectivity programmes will face intensified vendor-selection pressure. This is the highest-impact vendor-restriction signal of the July window and directly amplifies existing Five Eyes exclusion pressure on regional operators still carrying Huawei/ZTE infrastructure.
Mag 5 Signalling Intent MediaReport
22 Jul 2026
RC09
S13 SPC-SATCOM
TechnologyDigital.DigitalInfrastructure
Regionwide
ObsOn 22 July 2026 the FCC adopted a landmark Report and Order titled 'Space Modernization for the 21st Century' that replaces the legacy Part 25 satellite-licensing framework with a new Part 100. Key changes: processing rounds for NGSO constellations revised; most space station and earth station licence terms extended to 20 years; a new Variable Trajectory Space Station licence category created; red tape cut to reduce review timelines from years to months; and operators required to share space situational awareness data. The order was accompanied by a Further NPRM seeking comment on intersatellite links between US-licensed and non-US-licensed satellites, operational envelopes, and secondary market transactions.
AssessmentThe Part 100 overhaul materially lowers barriers for US-based LEO operators — primarily SpaceX/Starlink — to obtain and modify authorisations for Indo-Pacific gateway and earth-station siting. Faster licence processing directly accelerates Starlink's ability to expand ground infrastructure across the Pacific island arc and in Southeast Asian markets where regulatory approvals have been a bottleneck. The new requirement to share space situational awareness data also has implications for non-US operators seeking coordination agreements.
Mag 5 CapacityDisplay Capability OfficialDocument
22 Jul 2026
RC09
S14 SPC-SPEC
TechnologyDigital.DigitalInfrastructure
ExtraRegional
ObsFCC voted 22 July 2026 to auction 160 MHz of upper C-band spectrum (3.98–4.14 GHz) by July 2027 — the agency's first new commercial spectrum auction in five years. The order reallocates the band for terrestrial flexible-use (5G/6G), creates 3,248 new licences, and sets a 30 December 2030 deadline for incumbent Fixed Satellite Service operators to vacate. Combined with lower C-band already auctioned, this creates a contiguous 440 MHz 'super band' from 3.7–4.14 GHz. The FCC authorised gross incentive payments of approximately USD 5.6 billion for SES and USD 504 million for Eutelsat contingent on clearing deadlines. Eligible space station operators must file initial transition plans by 5 November 2026.
AssessmentClearing incumbent FSS operators from the upper C-band displaces satellite capacity currently used for broadcast distribution and enterprise connectivity in the Asia-Pacific, as both SES and Eutelsat operate fleets that serve the region. The transition will require new satellites and significant re-engineering of downlink infrastructure. For Indo-Pacific states dependent on C-band for rural connectivity or broadcast contribution, this is a structural supply signal that warrants tracking against regional gateway investment timelines.
Mag 4 CapacityDisplay Capability OfficialDocument
22 Jul 2026
RC09
S11 CBL-BUILD
TechnologyDigital.DigitalInfrastructure
China → Philippines
ObsOn 22 July 2026 China Mobile announced that the Southeast Asia-Hainan-Hong Kong (SEA-H2X) international submarine cable had completed its system acceptance test and launched commercially. SEA-H2X spans approximately 5746 km with eight fibre pairs and a design capacity exceeding 200 Tbps connecting Hainan China Hong Kong the Philippines Thailand and Singapore. China Mobile is the project's largest investor and holds key management responsibilities including operating the network operations centre. The cable integrates with China Mobile's existing Asia-Pacific systems (APG SJC SJC2 SEA-ME-WE 5 PEACE). The system employs Open Cable technology with spectrum sharing and is positioned to provide low-latency computing power interconnection between China and Southeast Asia. The commercial launch was announced via PRNewswire from Hong Kong and characterised by China Mobile as advancing its Belt and Road digital infrastructure objectives.
AssessmentChina Mobile's entry into commercial service on SEA-H2X represents a significant expansion of Chinese state-owned carrier control over submarine cable infrastructure transiting or terminating in Southeast Asian partner states (Philippines Thailand Singapore). The Philippines landing is of particular chokepoint significance — SEA-H2X likely crosses or runs proximate to the Luzon/Bashi corridor alongside AAG FASTER and other systems. China Mobile's role as network operations centre operator means it controls fault diagnosis performance monitoring and potentially traffic routing on a 200+ Tbps system. Simultaneous with FCC SLTE exclusion rules (RC09WSA-2026-07-004 and -005) this creates a structural divergence: the US is excluding Chinese entities from US-connected infrastructure while China Mobile is consolidating operational control on Southeast Asian routes. No independent security review of SEA-H2X by Philippine NTC or Singapore IMDA was publicly announced as of reporting date. Confidence High per China Mobile PRNewswire official press release.
Mag 3 CapacityDisplay Capability MediaReport
22 Jul 2026
RC09
S16 CRI-VULN
TechnologyDigital.CriticalInfrastructure
Regionwide
ObsOn 22 July 2026 CISA updated joint advisory AA26-097A expanding confirmed Iranian-affiliated exploitation of internet-facing PLCs to include Schneider Electric (Modicon M340 / BMX P34) and Siemens S7-1200 series in addition to previously confirmed Rockwell Automation/Allen-Bradley MicroLogix and CompactLogix controllers. The update added new MITRE ATT&CK Exfiltration Technique T1041 documenting theft of PLC project files using vendor configuration software on leased overseas infrastructure, and added detection guidance for malicious tampering with reusable code modules embedded in PLC programs. CVE-2021-22681 (CVSS 9.8) — an authentication bypass in Rockwell Logix controllers with no vendor patch available — remains the primary exploitation vector. Approximately 5,000-6,000 internet-exposed Rockwell devices identified via Shodan. Indo-Pacific operators of these platforms carrying equivalent exposure.
AssessmentAA26-097A update represents material capability escalation: vendor scope expanded from one to three OEM families; first confirmed PLC project-file exfiltration documented (operational reconnaissance for future tailored attack); reusable code module tampering guidance added. Rockwell has confirmed no patch exists for CVE-2021-22681. Indo-Pacific water, energy, and government ICS operators using these platforms face equivalent exposure to US victims confirmed in the advisory.
Mag 3 Escalation Capability Advisory
22 Jul 2026
RC09
S15 CRI-REG
TechnologyDigital.CriticalInfrastructure
SoutheastAsia
ObsOn 22 July 2026 CSA announced at the Operational Technology Cybersecurity Expert Panel Forum 2026 that it will release an updated Cybersecurity Code of Practice (CCoP) for Critical Information Infrastructure and a first-ever CCoP for Cloud Services in H2 2026. The updated CCoP introduces mandatory board-level cyber resilience frameworks requiring documented risk tolerance, mitigation, and recovery strategies reviewed annually. The regulatory driver cited by CSA is the emergence of APTs and AI-enabled threats that allow adversaries to discover vulnerabilities faster and launch attacks at greater scale since the previous CCoP revision in 2022. Compliance certification deadlines require CII auditors to achieve certification by 31 December 2026 and CII owners by 31 December 2027.
AssessmentThis is the most sweeping overhaul of Singapore's CII cybersecurity standards since 2022 and is explicitly framed as a response to APT activity including confirmed UNC3886 targeting of Singapore telecom operators. The CCoP Cloud extension is a first-of-kind regulatory instrument for cloud-hosted critical infrastructure in Singapore. Board accountability mandate creates legal exposure for directors of CII operators under Singapore Cybersecurity Act 2018. Instrument coded Legal; OfficialDocument source is the CSA official press release.
Mag 2 DeEscalation Intent OfficialDocument
22 Jul 2026
RC09
S12 CRI-INTRUDE
TechnologyDigital.CriticalInfrastructure
Australia
ObsOn 22 July 2026 Origin Energy Limited identified a potential cybersecurity incident involving unauthorised access to customer data and immediately notified the Australian Cyber Security Centre (ACSC) and Australian Federal Police. By 28 July Origin confirmed approximately 900,000 current and former customer records were accessed including names, addresses, dates of birth, phone numbers, account information, and partial payment card or bank account numbers. Origin's CEO publicly acknowledged the breach. ACSC, National Office of Cyber Security, AFP, and the Office of the Australian Information Commissioner are all engaged. Core energy operational systems and customer credit card / bank details were stated not to be affected.
AssessmentOrigin Energy is one of Australia's largest electricity and gas retailers and power generators. No technical indicators of compromise published as of date of source; attack vector not disclosed. Attribution low-confidence: one researcher suggested TripleX group but this is unconfirmed. Operator and ACSC engagement confirmed; incident classified as criminal matter under AFP investigation. OT / generation systems stated unaffected; magnitude scored 3 (essential service IT-side breach; service maintained).
Mag 3 Signalling Capability MediaReport
23 Jul 2026
RC01
S8 APEC Chengdu Statement on Digital Technologies and AI Adopted
TechnologyDigital.AIGovernanceAndDataSovereignty
China
ObsThe 2026 APEC Digital and AI Ministerial Meeting, held in Chengdu on 23 July 2026 and chaired by China's Minister of Industry and Information Technology Li Lecheng, adopted the 'Chengdu Statement' — a ministerial-level action framework for deepening digital and AI cooperation across Asia-Pacific economies. China's Vice Premier Zhang Guoqing opened the meeting, pledging to advance joint formulation of standards and rules, promote open-source cooperation, and lead digital transformation in the region. The statement endorsed accelerating communication and computing infrastructure development and supporting digital transformation of MSMEs. The US delegation raised concerns over 'AI distillation' in closed sessions while adopting a restrained public tone.
AssessmentChina has successfully chaired an APEC-level ministerial that enshrines an action framework for Asia-Pacific digital cooperation on terms favourable to Beijing's open-source and infrastructure-led approach. The Chengdu Statement provides a multilateral imprimatur for China's AI and digital ecosystem outreach in the region, complementing WAICO. The US-China tension over AI distillation — surfaced in closed-door sessions — indicates that despite consensus language, the statement masks significant divergence on IP protection and model governance norms that will shape Indo-Pacific tech alignment choices.
Mag 3 Signalling Intent OfficialDocument
24 Jul 2026
RC09
S7 AID-REG
TechnologyDigital.AIGovernanceAndDataSovereignty
ObsRBI released draft Guidance on Regulatory Principles for Model Risk Management 2026 on 24 June 2026 (Press Release No. 2026–2027/528); public consultation open until 24 July 2026. Guidance applies to all models used by regulated entities including third-party AI/ML models. Requires Board-approved Model Risk Management Framework (MRMF) covering entire model lifecycle; introduces AI-specific chapter with explainability thresholds, hallucination and bias controls, red-teaming requirements, mandatory kill-switch arrangements, and human oversight obligations; applies three-lines-of-defence governance. Once finalised, will replace the RBI's 2002 Credit Risk Model guidance. Scope covers commercially deployed AI models from any vendor. Consultation window was actively open throughout July 2026.
AssessmentConsultation stage only (magnitude 3); however, this is India's first dedicated AI/ML model governance framework for the financial sector and represents a significant expansion of sectoral AI regulation with cross-border supply-chain implications for any foreign AI vendor selling models to Indian banks. Once finalised, it will constitute a binding instrument affecting one sector with de facto extraterritorial reach over model providers. The kill-switch and explainability requirements are structurally more prescriptive than most regional peers.
Mag 1 Signalling Intent OfficialDocument
26 Jul 2026
RC09
S6 CRI-DISRUPT
TechnologyDigital.CriticalInfrastructure
Regionwide
US
ObsOn 26–27 July 2026 a coordinated cyberattack targeted water and wastewater systems across more than 30 Minnesota communities and utilities in at least seven US states. Attackers exploited internet-exposed Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs — likely using CVE-2021-22681 — to remotely access OT networks, change IP addresses and passwords locking operators out of their own systems, and degrade water operations. At least one plant was shut down; others forced to manual operation. The FBI and EPA issued a public service announcement on 31 July 2026 confirming incidents reported to FBI since 27 July and that 'some activity degraded water operations.' CISA noted a 'significant escalation' in PLC attacks.
AssessmentFBI/EPA official PSA corroborates operational degradation across multiple states meeting the CRI-DISRUPT corroboration rule at magnitude 3+. Timing — four days after CISA updated AA26-097A on 22 July — is assessed by Tenable researchers as 'significant' and aligns with escalating Iranian-affiliated PLC campaign. Federal investigators examining Iran link; attribution assessed probable but unproven as of 31 July per MNIT statewide response statements. These same PLC models are widely deployed in Indo-Pacific water and energy infrastructure; tactical precedent directly transferable.
Mag 4 Escalation Intent OfficialDocument
27 Jul 2026
RC01
S5 CXMT Lists on STAR Market – Asia's Largest 2026 IPO Raises USD 8.6bn for DRAM Expansion
TechnologyDigital.SemiconductorAndCompute
ObsChangXin Memory Technologies (CXMT) listed on the SSE STAR Market on 27 July 2026, raising RMB 57.92 billion (USD 8.6 billion) — Asia's largest IPO of 2026 and the largest semiconductor listing ever on the STAR Market. CXMT shares surged 466% on debut, making it the most valuable China-listed company with a market cap of approximately RMB 3.31 trillion. CXMT held a 7.67% share of the global DRAM market in 2025 and ranked fourth globally in DRAM production capacity. IPO proceeds are earmarked for memory wafer mass production, DRAM technology R&D and capacity expansion. Global competitors fell sharply on the news: Micron –5%, SK Hynix ADRs –6%, SanDisk –12%. Analysts flagged potential expansion into HBM memory as a next step.
AssessmentCXMT's listing is the most consequential single capital-formation event in China's semiconductor self-reliance drive during the window. The USD 8.6bn war chest materially accelerates China's domestic DRAM capacity ahead of potential US regulatory responses and signals investor confidence in state-backed chip champions. The market impact on Samsung, Micron, and SK Hynix — all critical technology partners for Indo-Pacific allies — demonstrates that China's memory chip sector is now competitive enough to move global markets. HBM expansion ambitions directly threaten the supply-chain leverage that underpins allied chip control strategies.
Mag 4 CapacityDisplay Capability MediaReport
27 Jul 2026
RC09
S3 CAP-NORM
TechnologyDigital.CyberOperationsAndCapacity
Australia → ASEAN
ObsAt the 15th Singapore-Australia Joint Ministerial Committee (SAJMC) in Adelaide on 27 July 2026, ministers welcomed the renewal of the bilateral MoU on Cyber Security Cooperation (signed 24 February 2026) and confirmed its operationalisation through a senior officials' meeting. The MoU covers information sharing, training and best-practice exchange, joint cyber exercises, innovation, trade and investment promotion, regional confidence-building measures, and regional capacity building including at the ASEAN-Singapore Cybersecurity Centre of Excellence. Ministers also announced the inaugural bilateral Cyber and Digital Dialogue to be held on 30 July 2026 in Australia under the MoU on AI cooperation.
AssessmentThe SAJMC outcome bundles a renewed bilateral MoU, an inaugural Cyber and Digital Dialogue, and explicit ASEAN-Singapore CCoE regional capacity-building commitments into a single diplomatic instrument. The simultaneous activation of three institutional mechanisms — MoU, Dialogue, and CCoE — in one communiqué signals depth of digital alignment well beyond a routine reaffirmation. The CCoE commitment embeds Australia into Singapore's ASEAN-facing cyber training infrastructure.
Mag 2 Signalling Intent OfficialDocument
27 Jul 2026
RC09
S4 CBL-PERMIT
TechnologyDigital.DigitalInfrastructure
ObsOn 27 July 2026 the FCC published its Second Report and Order (FCC 26-42 adopted 25 June 2026) in the Federal Register Vol. 91 No. 142 (pages 46844–46866). The order establishes a blanket licensing regime for all owners and operators of Submarine Line Terminal Equipment (SLTE) on cables landing in the US. It explicitly excludes from the blanket licence any entity meeting foreign adversary presumptive disqualification criteria — directly targeting China Telecom China Unicom and China Mobile. Entities already owning or operating SLTE linked to Chinese adversary-controlled entities are required to remediate. SLTE owners/operators must file annual Foreign Adversary Annual Reports cybersecurity and physical security risk management plans and circuit capacity reports. The order's Federal Register publication starts the 30-day comment clock for the accompanying Further Notice and initiates compliance obligations for approximately 3136 current SLTE owners/operators globally including those on Indo-Pacific trans-Pacific routes.
AssessmentFederal Register publication locks in the effective dates and compliance timeline for the broadest expansion of US submarine cable security regulation in decades. The specific exclusion of Chinese adversary-linked entities from SLTE operation extends the security perimeter from cable landing points into inland data-centre SLTE infrastructure — a structural change to the digital chokepoint architecture on US-connected trans-Pacific routes. The companion Q2 2026 Windward data showing China-flagged high-IUU events near Pacific cable-landing hubs rising 130% QoQ reinforces the policy rationale. Confidence High per Federal Register official document.
Mag 4 Deterrence Intent OfficialDocument
29 Jul 2026
RC09
S2 AID-REG
TechnologyDigital.AIGovernanceAndDataSovereignty
SoutheastAsia
ObsOn 29 July 2026 Indonesia's Deputy Minister of Communication and Digital Affairs Nezar Patria confirmed via official statement that the draft Presidential Regulation on the National AI Roadmap and AI Ethics has completed inter-ministerial review and is awaiting presidential signature. Statement also confirmed Indonesia's intent to pursue dedicated AI legislation following the Presidential Regulation. Once signed, ministerial derivative regulations will follow including mandatory AI content labelling/watermarking for digital platforms. The draft Presidential Regulation establishes risk categories, labelling requirements and ethics framework. No penalties included in the Presidential Regulation itself — enforcement relies on existing ITE Law and PDP Law. Using publication date as proxy for event date.
AssessmentAn announcement without instrument text — magnitude capped at 2 per scoring anchors; however, inter-ministerial completion is the final administrative step before presidential signature, making this a verifiable pre-enactment milestone that alters the near-term regulatory trajectory for Indonesia's digital economy. Raises to 3 upon confirmation of presidential signature. Once enacted, the Presidential Regulation will be the first comprehensive national AI framework for the world's fourth most populous nation, with significant downstream dependency implications for regional AI compute and platform flows.
Mag 1 Signalling Intent MediaReport
29 Jul 2026
RC09
S1 CMP-CAPEX
TechnologyDigital.SemiconductorAndCompute
TaiwanStrait
Taiwan
ObsCentral Taiwan Science Park Administration Director Hsu Mao-hsin confirmed on 29 July 2026 that construction of TSMC's $49B 1.4nm (A14) fab at Taichung Phase II Park is significantly ahead of schedule. Foundation piling is largely complete; the first two of four planned fabs have entered the steel structure phase; the central utility plant and office buildings are under construction. First fab building completion is now expected before April 2027. Supply-chain sources indicate pilot production could begin Q3 2027 and mass production by mid-2028 — at least one quarter earlier than the prior 2H28 target. The node uses second-generation GAAFET (NanoFlex Pro) with current EUV. Notably 1.4nm is not included in TSMC's US fab plans; it remains exclusively Taiwan-sited.
AssessmentThe 1.4nm node being Taiwan-only deepens Taiwan's irreplaceable role in sub-2nm AI chip production for at least the 2028–2032 window. Any Taiwan Strait contingency that disrupts the Taichung Science Park — located on Taiwan's west coast facing the strait — would eliminate the world's only planned mass-production source of 1.4nm-class chips. Accelerated schedule modestly increases the period of Taiwan-dependent leading-edge concentration. Confidence High on construction progress per official park administration statement.
Mag 4 CapacityDisplay Capability MediaReport
S#DateRCIndicatorDomainTheatreModeMagEffectConfSource
S342026-07-09RC09CMP-CAPEXTechnologyDigital.SemiconductorAndComputeOvert5DeterrenceLowMediaReport
S292026-07-16RC01WAICO Founded – China-Led Global AI Governance Body Established by 29 StatesTechnologyDigital.AIGovernanceAndDataSovereigntyOvert5EscalationLowMediaReport
S92026-07-22RC09SPC-VENDORTechnologyDigital.DigitalInfrastructureExtraRegionalOvert5SignallingLowMediaReport
S132026-07-22RC09SPC-SATCOMTechnologyDigital.DigitalInfrastructureRegionwideOvert5CapacityDisplayHighOfficialDocument
S432026-07-02RC01Chinese GLM-5.2 model gains global developer tractionTechnologyDigital.AIGovernanceAndDataSovereigntyExtraRegionalDeniable4NotAssessedLowMediaReport
S402026-07-05RC09CRI-INTRUDETechnologyDigital.CriticalInfrastructureSoutheastAsiaOvert4SignallingLowIndustryReport
S362026-07-08RC09CBL-PERMITTechnologyDigital.DigitalInfrastructureOvert4DeterrenceMediumOfficialDocument
S352026-07-09RC09CMP-INPUTTechnologyDigital.SemiconductorAndComputeOvert4DeterrenceLowIndustryReport
S332026-07-10RC09CMP-CTRLTechnologyDigital.SemiconductorAndComputeOvert4SignallingHighOfficialDocument
S322026-07-14RC09SPC-SATCOMTechnologyDigital.DigitalInfrastructureSouthChinaSeaOvert4SignallingLowMediaReport
S302026-07-15RC01CAC Anthropomorphic AI Interaction Measures Enter Force – Data Governance ExpandedTechnologyDigital.AIGovernanceAndDataSovereigntyOvert4SignallingHighOfficialDocument
S102026-07-22RC09CAP-NORMTechnologyDigital.CyberOperationsAndCapacitySoutheastAsiaOvert4SignallingHighOfficialDocument
S142026-07-22RC09SPC-SPECTechnologyDigital.DigitalInfrastructureExtraRegionalOvert4CapacityDisplayHighOfficialDocument
S62026-07-26RC09CRI-DISRUPTTechnologyDigital.CriticalInfrastructureRegionwideOvert4EscalationHighOfficialDocument
S52026-07-27RC01CXMT Lists on STAR Market – Asia's Largest 2026 IPO Raises USD 8.6bn for DRAM ExpansionTechnologyDigital.SemiconductorAndComputeOvert4CapacityDisplayLowMediaReport
S42026-07-27RC09CBL-PERMITTechnologyDigital.DigitalInfrastructureOvert4DeterrenceMediumOfficialDocument
S12026-07-29RC09CMP-CAPEXTechnologyDigital.SemiconductorAndComputeTaiwanStraitOvert4CapacityDisplayLowMediaReport
S502026-07-01RC09AID-LOCALTechnologyDigital.AIGovernanceAndDataSovereigntySoutheastAsiaOvert3EscalationMediumOfficialDocument
S452026-07-02RC01India-Japan economic security declaration targets semiconductors and ICTTechnologyDigital.SemiconductorAndComputeNortheastAsiaOvert3NotAssessedMediumOfficialDocument
S462026-07-02RC01India-Japan AI cooperation elevated to strategic R&D partnershipTechnologyDigital.AIGovernanceAndDataSovereigntyNortheastAsiaOvert3NotAssessedMediumOfficialDocument
S472026-07-02RC01IndiaAI and Japan METI link AI compute and project supportTechnologyDigital.SemiconductorAndComputeNortheastAsiaOvert3NotAssessedMediumOfficialDocument
S442026-07-02RC01Taiwan probe targets alleged AI server exports to ChinaTechnologyDigital.SemiconductorAndComputeTaiwanStraitSubThreshold3NotAssessedLowMediaReport
S422026-07-02RC09CBL-BUILDTechnologyDigital.DigitalInfrastructureOvert3CapacityDisplayMediumOfficialDocument
S412026-07-03RC01Taiwan opens Phoenix office to anchor semiconductor corridorTechnologyDigital.SemiconductorAndComputeTaiwanStraitOvert3NotAssessedMediumOfficialDocument
S382026-07-07RC05PRC Cyberespionage Social-Engineering Network Charged in TaiwanTechnologyDigital.CyberOperationsAndCapacityTaiwanStraitDeniable3SignallingMediumOfficialDocument
S372026-07-07RC09CRI-INTRUDETechnologyDigital.CriticalInfrastructureNortheastAsiaOvert3SignallingLowMediaReport
S262026-07-17RC01WAIC 2026 – Xi Jinping Keynote and Huawei Atlas 950 SuperPoD DebutTechnologyDigital.SemiconductorAndComputeOvert3CapacityDisplayMediumOfficialDocument
S252026-07-17RC09AID-TRANSFERTechnologyDigital.AIGovernanceAndDataSovereigntyNortheastAsiaOvert3DeEscalationMediumOfficialDocument
S202026-07-20RC09AID-REGTechnologyDigital.AIGovernanceAndDataSovereigntySoutheastAsiaOvert3SignallingLowMediaReport
S232026-07-20RC09CAP-FUNDTechnologyDigital.CyberOperationsAndCapacitySouthPacificOvert3CapacityDisplayMediumOfficialDocument
S212026-07-20RC09CAP-NORMTechnologyDigital.CyberOperationsAndCapacitySoutheastAsiaOvert3SignallingMediumOfficialDocument
S242026-07-20RC09SPC-SPECTechnologyDigital.DigitalInfrastructureSouthPacificOvert3SignallingMediumOfficialDocument
S192026-07-21RC09SPC-ITUTechnologyDigital.DigitalInfrastructureRegionwideOvert3SignallingLowMediaReport
S112026-07-22RC09CBL-BUILDTechnologyDigital.DigitalInfrastructureOvert3CapacityDisplayLowMediaReport
S162026-07-22RC09CRI-VULNTechnologyDigital.CriticalInfrastructureRegionwideOvert3EscalationMediumAdvisory
S122026-07-22RC09CRI-INTRUDETechnologyDigital.CriticalInfrastructureOvert3SignallingLowMediaReport
S82026-07-23RC01APEC Chengdu Statement on Digital Technologies and AI AdoptedTechnologyDigital.AIGovernanceAndDataSovereigntyOvert3SignallingMediumOfficialDocument
S512026-07-01RC01XPHOR Silicon Photonics STAR Market IPO Filing AcceptedTechnologyDigital.SemiconductorAndComputeOvert2CapacityDisplayLowMediaReport
S492026-07-01RC09AID-CLOUDTechnologyDigital.AIGovernanceAndDataSovereigntySoutheastAsiaOvert2CapacityDisplayMediumOfficialDocument
S482026-07-02RC01India-Japan internet registry cooperation advances IPv6 and securityTechnologyDigital.DigitalInfrastructureNortheastAsiaOvert2NotAssessedMediumOfficialDocument
S392026-07-07RC01FCC blocks Chinese-linked telecom services firmTechnologyDigital.DigitalInfrastructureExtraRegionalOvert2NotAssessedLowMediaReport
S312026-07-14RC09AID-TRANSFERTechnologyDigital.AIGovernanceAndDataSovereigntySoutheastAsiaOvert2EscalationMediumOfficialDocument
S282026-07-16RC09CAP-STDTechnologyDigital.CyberOperationsAndCapacitySoutheastAsiaOvert2CapacityDisplayMediumOfficialDocument
S222026-07-20RC09CAP-TRAINTechnologyDigital.CyberOperationsAndCapacitySouthPacificOvert2CapacityDisplayMediumOfficialDocument
S182026-07-21RC09CAP-NORMTechnologyDigital.CyberOperationsAndCapacitySouthPacificOvert2SignallingMediumOfficialDocument
S172026-07-21RC09CAP-TRAINTechnologyDigital.CyberOperationsAndCapacitySoutheastAsiaOvert2CapacityDisplayMediumOfficialDocument
S152026-07-22RC09CRI-REGTechnologyDigital.CriticalInfrastructureSoutheastAsiaOvert2DeEscalationMediumOfficialDocument
S32026-07-27RC09CAP-NORMTechnologyDigital.CyberOperationsAndCapacityOvert2SignallingMediumOfficialDocument
S272026-07-16RC09AID-ENFORCETechnologyDigital.AIGovernanceAndDataSovereigntyOvert1DeEscalationMediumOfficialDocument
S72026-07-24RC09AID-REGTechnologyDigital.AIGovernanceAndDataSovereigntyOvert1SignallingMediumOfficialDocument
S22026-07-29RC09AID-REGTechnologyDigital.AIGovernanceAndDataSovereigntySoutheastAsiaOvert1SignallingLowMediaReport
© 2026 Indo-Pacific Studies Center · CC BY-NC-ND 4.0 · www.indo-pacificstudiescenter.org Technology & Digital Competition · Strategic Brief · Issue #001