<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.itpro.com/feeds/tag/eu" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro in Eu ]]></title>
                <link>https://www.itpro.com/tag/eu</link>
        <description><![CDATA[ All the latest eu content from the ITPro team ]]></description>
                                    <lastBuildDate>Wed, 01 Jul 2026 09:41:31 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Startup founders lament 'regulatory friction' despite EU simplification efforts ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/startup-founders-lament-regulatory-friction-despite-eu-simplification-efforts</link>
                                                                            <description>
                            <![CDATA[ Entrepreneurs are spending a fortune on compliance, and it’s forcing some to consider relocating ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">af7qTFWabwrvev3mxoG6L3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YfH4YfBJwqGBq5tCEPQ77n-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 01 Jul 2026 09:41:31 +0000</pubDate>                                                                                                                                <updated>Thu, 02 Jul 2026 12:44:12 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YfH4YfBJwqGBq5tCEPQ77n-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Digital sovereignty concept image showing digitized flag of the European Union (EU) imposed over a blue background with binary code. ]]></media:description>                                                            <media:text><![CDATA[Digital sovereignty concept image showing digitized flag of the European Union (EU) imposed over a blue background with binary code. ]]></media:text>
                                <media:title type="plain"><![CDATA[Digital sovereignty concept image showing digitized flag of the European Union (EU) imposed over a blue background with binary code. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YfH4YfBJwqGBq5tCEPQ77n-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Europe’s complex network of overlapping regulations is hitting startup founders hard and holding back business, according to a new research by startup support organization DutchBasecamp. </p><p>Some 79% of tech founders claim they've been hit by regulatory friction over the last year, according to the <a href="https://dutchbasecamp.org/eu-regulations-founders-perspective" target="_blank"><u><em>The Realities of Scaling in Europe</em></u></a> report, which was launched in partnership with the Computer & Communications Industry Association (CCIA).</p><p>More than half (58%) said they'd delayed entering another EU market, 45% have paused or canceled features, and 44% have experienced delayed or lost deals.</p><p>As negotiations on the Digital Omnibus continue, the CCIA warned that many meaningful simplification measures could fall by the wayside, which has the potential to further compound challenges faced by startups. </p><p>Some member states are resisting a proposal allowing businesses to report a <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>incident once, rather than separately under seven overlapping frameworks. </p><p>Meanwhile, a fix that would establish legitimate interest as a legal basis for <a href="https://www.itpro.com/technology/artificial-intelligence/meta-ditching-its-responsible-ai-team-doesnt-bode-well">responsible AI training</a> has been stripped out. </p><p>While postponing certain deadlines has provided some breathing room, many simplifications have been rejected, leaving developers with limited implementation time while essential codes, guidance, and standards are still missing. </p><p>“We warned from the start that the Commission’s proposals to simplify the patchwork of EU tech and digital rules were only the bare minimum. Instead of going further, Parliament and Council are now weakening, rejecting, or delaying even the most basic fixes," said Daniel Friedlaender, senior vice president and head of CCIA Europe. </p><p>“Europe’s innovators have shown remarkable patience in navigating today’s regulatory maze, but that patience is running out. EU institutions and member states need to wake up: 2026 must bring real improvements for tech companies. Europe knows the problems. If we refuse to fix them, we can’t be surprised if our founders look outside the EU for success.”</p><h2 id="growing-regulatory-friction">Growing regulatory friction</h2><p>Nearly a quarter of survey respondents said they'd spent more than 30% of their budgets on compliance costs, while 24% are considering or have already relocated their headquarters due to regulation. </p><p>In January, the European Investment Bank, with the European Commission, found that roughly one-in-ten EU scale-ups have relocated abroad, with around 85% of those moving to the United States.</p><p>The Commission’s Joint Research Center put the headquarters-relocation rate for venture-backed startups at between 3.3% and 4.3%, ten times the rate for comparable non-VC-backed firms.</p><p>More than half of founders said they'd steered clear of an EU country because of regulatory concerns, and only 21% said they'd seen no material impact from EU or national rules. </p><p>"Europe is already losing tech founders, products, and growth," said Masha Moisseyeva, managing director of DutchBasecamp. </p><p>"When 45% of those surveyed have paused or cancelled features, 58% have delayed entering another EU market, and 44% have lost or delayed deals in a single year, the urgent need for regulatory simplification is no longer a theoretical debate about EU competitiveness. The damage is happening now.” </p><h2 id="regulatory-confusion-is-rife">Regulatory confusion is rife</h2><p>Much of the cost, the researchers found, comes not from compliance itself but from not knowing what compliance will require. </p><p>Indeed, founders often cite uncertainty surrounding future EU AI Act obligations before any requirement has formally bound them.</p><p>“Founders are not asking the EU to lower its standards. They are asking for clear, workable rules they can rely on across the Single Market," said Moisseyeva. </p><p>"Instead, uncertainty and overlapping obligations are dictating what they build, who they serve, and how fast they grow.” </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AWS says cloud market gatekeeper designation risks ‘deterring European investment and innovation’ as EU regulators plot competition crackdown ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/aws-says-cloud-market-gatekeeper-designation-risks-deterring-european-investment-and-innovation-as-eu-regulators-plot-competition-crackdown</link>
                                                                            <description>
                            <![CDATA[ Gatekeeper designation under the legislation would force AWS and Microsoft to make concessions ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">CddusqTAFnsE38t8Co9iUW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/i2VUb2oLPjFFkMn6CA4Huj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 26 Jun 2026 16:06:44 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/i2VUb2oLPjFFkMn6CA4Huj-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Amazon Web Services (AWS) logo and branding pictured at the Hannover Messe industrial trade fair for mechanical and electrical engineering and digital industries.]]></media:description>                                                            <media:text><![CDATA[Amazon Web Services (AWS) logo and branding pictured at the Hannover Messe industrial trade fair for mechanical and electrical engineering and digital industries.]]></media:text>
                                <media:title type="plain"><![CDATA[Amazon Web Services (AWS) logo and branding pictured at the Hannover Messe industrial trade fair for mechanical and electrical engineering and digital industries.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/i2VUb2oLPjFFkMn6CA4Huj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Amazon has hit back at EU lawmakers after the European Commission signalled its intent to designate the hyperscaler as a “gatekeeper” under the Digital Markets Act (DMA). </p><p>In a statement on 25 June, the Commission noted that <a href="https://www.itpro.com/amazon-web-services">Amazon Web Services (AWS) </a>and Microsoft “hold an entrenched and durable position” in the EU cloud computing sector, with both potentially harming competition across the region. </p><p>AWS and Microsoft have already been designated as gatekeepers in other business areas, and with cloud computing, lawmakers are equally concerned the duo could stifle competition. </p><p>“Their <a href="https://www.itpro.com/627952/what-is-cloud-computing">cloud computing</a> services AWS and Azure have achieved significant turnover, and their operational capacity and investments seem to have significantly outpaced those of competitors,” the Commission said. </p><p>“They both have vast and entrenched user bases and appear to benefit from lock-in effects and high switching costs, in addition to a large ecosystem.”</p><p>The Commission also highlighted competition concerns regarding the influence of AI services on the broader market, noting that both firms’ <a href="https://www.itpro.com/technology/artificial-intelligence/amazing-ai-tools-to-try-today">AI tools</a> have “become a decisive factor in cloud procurement”. </p><p>“Whilst AI is significantly increasing the demand for cloud-related services, AWS and Azure appear to retain a large proportion of this increased demand within their respective ecosystems.”</p><p>While the Commission noted that this is a “preliminary view”, the statement follows a seven month investigation into the influence of both companies. </p><p>If designated under the legislation, lawmakers could impose a series of obligations on both companies, such as the introduction of new interoperability and data portability features. </p><p>Teresa Ribera, the EU’s executive vice president for Clean, Just, and Competitive Transition, said both companies will have the opportunity to respond before “final decisions are taken”. </p><h2 id="aws-hits-back-at-eu-claims">AWS hits back at EU claims</h2><p>AWS has contested the claims made by the European Commission, with a spokesperson suggesting the preliminary findings “disregard the breadth of cloud services available to European customers”. </p><p>The spokesperson added that designation under the legislation could risk “deterring future European investment and innovation”. </p><p>“AWS faces healthy competition and customers across Europe have more choice, lower prices, and greater flexibility than ever before,” the spokesperson said. </p><p>“The EU already has comprehensive cloud regulation through the Data Act, and adding another heavy layer of overlapping regulation under the DMA undermines European competitiveness and access to cutting-edge information technology.”</p><p>AWS said it intends to work closely with the Commission to “reach the right outcome for customers”. </p><h2 id="long-running-competition-concerns">Long-running competition concerns</h2><p>The move by the Commission comes as relations between US-based tech giants and the EU grow increasingly tense. </p><p>European regulators have made repeated attempts to limit the influence of US firms across the region, having been locked in a series of battles with Microsoft over its dominance in the productivity software market. </p><p>Geopolitical tensions, however, are adding fuel to the fire on this front, particularly with regard to <a href="https://www.itpro.com/security/data-protection/what-businesses-need-to-know-about-data-sovereignty">data sovereignty</a>. </p><p>Critics argue that European organizations have become over reliant on US technology services, prompting calls to seek alternative, home-grown options. </p><p>Earlier this month, the Commission unveiled the <a href="https://www.itpro.com/business/policy-and-legislation/the-eu-is-charting-a-course-to-digital-independence-with-the-technological-sovereignty-package-heres-what-you-need-to-know">technological sovereignty package</a>, a series of measures aimed at strengthening digital sovereignty capabilities across the EU - spanning areas such as AI, cloud computing, and semiconductor manufacturing.</p><p>Speaking at the time, Ursula von der Leyen, president of the European Commission, said the package comes in direct response to concerns about overreliance on foreign technology services.</p><p>“We cannot afford to depend on others for the technologies that keep our hospitals running, our energy grids stable, and our services secure,” she said.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘This closes a gap that has caused real uncertainty in the market’: Changes to EU AI Act implementation deadlines welcomed by industry ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/this-closes-a-gap-that-has-caused-real-uncertainty-in-the-market-changes-to-eu-ai-act-implementation-deadlines-welcomed-by-industry</link>
                                                                            <description>
                            <![CDATA[ New implementation deadlines for the EU AI Act could help remove “genuine friction” for European companies ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wTrcGJSwGQ4XAiubLrguKi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YPLAJxoRSrPttgxeZWQkeG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 11 May 2026 14:23:01 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YPLAJxoRSrPttgxeZWQkeG-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[European Union (EU) concept image showing flag on a digitized background with ripples flowing out from 12 stars.]]></media:description>                                                            <media:text><![CDATA[European Union (EU) concept image showing flag on a digitized background with ripples flowing out from 12 stars.]]></media:text>
                                <media:title type="plain"><![CDATA[European Union (EU) concept image showing flag on a digitized background with ripples flowing out from 12 stars.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YPLAJxoRSrPttgxeZWQkeG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Changes made to the <a href="https://www.itpro.com/business/policy-and-legislation/how-the-eu-ai-act-compares-to-other-international-regulatory-approaches">EU AI Act</a> last week have been welcomed by industry stakeholders, but the move doesn’t mean enterprises can take their eye off the ball on AI governance. </p><p>Last week, a <a href="https://www.consilium.europa.eu/en/press/press-releases/2026/05/07/artificial-intelligence-council-and-parliament-agree-to-simplify-and-streamline-rules/" target="_blank">provisional agreement</a> was reached between the European Parliament and EU Council on the Omnibus VII legislative package. This includes proposals which aim to simplify the union’s legislative landscape. </p><p>Under the deal, significant changes to the EU AI Act will be implemented, including a revised compliance timeline for AI systems deemed “high-risk” under the legislation, as well as extended exemptions for small-to-medium sized enterprises. </p><p>As part of the delayed high-risk rules, new application dates will be 2 December 2027 for stand-alone AI systems, and 2 August 2028 for high-risk AI systems embedded in products, according to the EU Council. </p><p>Similarly, agreement reinstates provider obligations to register AI systems in the EU database for high-risk systems. </p><p>Elsewhere, the provisional agreement also postpones the deadline for the implementation of AI regulatory sandboxes at a national level until 2 August 2027.</p><p>Henna Virkkunen, executive vice president for tech sovereignty, security, and democracy at the European Commission, said the changes will help streamline implementation of the legislation. </p><p>“Our businesses and citizens want two things from <a href="https://www.itpro.com/business/policy-and-legislation/the-second-enforcement-deadline-for-the-eu-ai-act-is-approaching-heres-what-businesses-need-to-know-about-the-general-purpose-ai-code-of-practice">AI rules</a>. They want to be able to innovate and feel safe,” she said. </p><p>“Today’s agreement does both. With simpler and innovation-friendly rules, we make it easier to innovate without lowering the bar on safety. We are also making sure the tools supporting EU companies for a smooth implementation of the AI Act are ready. </p><h2 id="meaningful-changes-to-the-eu-ai-act">“Meaningful changes” to the EU AI Act</h2><p>The changes made to the legislation have been welcomed by industry stakeholders as a positive step toward streamlined implementation. </p><p>Mark Weir, regional director for the UK & Ireland at Check Point Software, said the alterations represent a “meaningful evolution in EU <a href="https://www.itpro.com/technology/artificial-intelligence/organizations-face-ticking-timebomb-over-ai-governance">AI governance</a>” that balances stronger protections alongside a practical approach to compliance. </p><p>“By harmonizing implementation across member states and reducing overlapping administrative obligations, the legislation removes genuine friction for organizations operating across Europe,” he said. </p><p>“Without clear guidance, even well-intentioned organisations struggle to translate broad principles into consistent practice,” Weir added. </p><p>“This closes a gap that has caused real uncertainty in the market. Taken together, these changes point toward a regulatory framework that is not just ambitious, but workable."</p><p>Weir noted that provider registration requirements are also a welcome move, and one that will give European legislators “real enforceability” over the EU’s digital sovereignty plans. </p><p>Levent Ergin, chief strategist for <a href="https://www.itpro.com/security/five-eyes-agencies-sound-alarm-over-risky-agentic-ai-deployments">agentic AI</a>, regulatory compliance, and sustainability at Informatica, echoed Weir’s comments but noted that the changes “shouldn’t detract from the need for better AI governance”. </p><p>“Businesses still need to ensure the data feeding their AI systems is governed, explainable, and built on trusted data foundations,” he said. </p><p>“Compliance is only part of the enabler of safe AI. Stronger governance, human oversight, and trusted context will ultimately determine which businesses can scale AI confidently and which struggle to move beyond experimentation.”</p><p>Looking ahead, the European Parliament and EU Council must not formally adopt the agreement. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Reducing reliance on foreign tech infrastructure is key’ to European tech success – and its survival ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-protection/reducing-reliance-on-foreign-tech-infrastructure-is-key-to-european-tech-success-and-its-long-term-survival</link>
                                                                            <description>
                            <![CDATA[ MEPs have once again called for decreased reliance on foreign tech infrastructure ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vfsFwuMro5QuNLntNz24mX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/aeA7CQhtNtuCimyeEWxL7m-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 17 Mar 2026 15:00:00 +0000</pubDate>                                                                                                                                <updated>Wed, 18 Mar 2026 08:35:56 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/aeA7CQhtNtuCimyeEWxL7m-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The 12 stars of the flag of the European Union (EU) imposed over a map of Europe.]]></media:description>                                                            <media:text><![CDATA[The 12 stars of the flag of the European Union (EU) imposed over a map of Europe.]]></media:text>
                                <media:title type="plain"><![CDATA[The 12 stars of the flag of the European Union (EU) imposed over a map of Europe.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/aeA7CQhtNtuCimyeEWxL7m-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>European policymakers are increasingly concerned about digital sovereignty, calling for the development of a technology ecosystem that's less dependent on big US tech firms.</p><p>At workspace platform Wire’s recent <em>European Digital Sovereignty Summit</em> in Brussels, MEPs, industry leaders, and digital experts called for the creation of a digital ecosystem reflecting what they described as European – rather than US – business values: democracy, transparency, and interoperability.</p><p>“Reducing reliance on foreign tech infrastructure is key to protecting democratic stability and data sovereignty, particularly given geopolitical risks," said Wire CEO Benjamin Schilz.</p><p>"<a href="https://www.itpro.com/software/28109/what-is-open-source">Open source</a>, interoperability and transparent standards are essential to build trust, avoid vendor lock-in, and strengthen resilience.” </p><p>Participants highlighted the risks of concentrated browser ownership, reliance on foreign cloud providers, and governance vulnerabilities within major platforms. </p><p>Notably, however, sovereignty must not mean isolation: Europe should remain open and globally engaged but anchored in its own standards and safeguards. </p><p>Jean-Phillipe Scherer, head of EU/NATO Public Affairs for Defence and Space at Airbus, called for a broader mindset shift through more European leadership and education.</p><p>“Individual priorities, rather than national sovereignty, are the greater barrier to European cooperation,” he said.</p><p>There were calls for practical reforms, stronger alignment across AI, semiconductor and <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>policy, and for simplification within a deeper single market. </p><h2 id="strained-relations-create-uncertainty">Strained relations create uncertainty</h2><p>The unpredictability of the Trump administration in the US has intensified calls for European digital sovereignty, with figures including European Commission President Ursula von der Leyen and former head of the European Central Bank Mario Draghi, calling for action. </p><p>Just last week, the European Council proposed <a href="https://www.consilium.europa.eu/en/press/press-releases/2026/03/13/council-agrees-position-to-streamline-rules-on-artificial-intelligence/" target="_blank"><u>new regulations</u></a> aiming to reduce dependence on US firms. This includes new proposals to “simplify the EU’s digital legislative framework and the implementation of harmonized rules on AI”.</p><p>“Streamlining the AI rules is essential for ensuring the EU’s digital sovereignty," said Marilena Raouna, deputy minister for European affairs of the Republic of Cyprus. </p><p>"The proposal will bring greater legal certainty, make the rules more proportionate and ensure more harmonised implementation across member states."</p><p>In the UK, calls are growing for a stronger focus on digital sovereignty, with industry stakeholders harboring significant concerns on transatlantic overreliance. </p><p>A survey of over 1,000 UK IT leaders from Civo last year found that more than 60% <a href="https://www.itpro.com/cloud/cloud-computing/reliance-on-us-tech-providers-is-making-it-leaders-skittish"><u>believed the UK government should cut its use of US cloud services</u></a>. </p><p>Key concerns included exposing the country’s digital economy to significant risks with regard to data security, and the impact providers have on the domestic cloud industry.</p><p>The Atlantic Council recently <a href="https://www.atlanticcouncil.org/in-depth-research-reports/report/digital-sovereignty-europes-declaration-of-independence/" target="_blank"><u>warned</u></a> that Trump’s close connections with leading tech executives means that the US administration’s combative posture toward European tech regulation is likely to continue causing friction. </p><p>"Whether a continued focus by the Trump administration on Europe’s digital rules will create an even stronger push in Europe for an exclusive form of digital sovereignty is not yet evident," commented fellows Frances Burwell and Kenneth Propp. </p><p>"What is clear is that without some guidelines, such as those offered in the conclusions to this report, the European Union and United States might find that their differences regarding digital sovereignty and digital rules make creating and maintaining an open transatlantic digital marketplace much more challenging."</p><h2 id="big-tech-is-acting">Big tech is acting</h2><p>Aware of the issue, US tech firms are making efforts to calm European business concerns, particularly with the launch of dedicated sovereign cloud services, </p><p><a href="https://www.itpro.com/cloud/cloud-computing/aws-european-sovereign-cloud-explained">Amazon Web Services (AWS)</a>, <a href="https://www.itpro.com/cloud/cloud-computing/microsoft-ceo-satya-nadella-talks-up-sovereign-cloud-credentials-as-firm-announces-general-availability-for-azure-local-disconnected-new-capabilities-for-foundry-local">Microsoft</a>, and <a href="https://www.itpro.com/cloud/cloud-computing/google-is-getting-serious-on-cloud-sovereignty">Google Cloud</a> have all made moves on this front. Yet despite proactive efforts, lingering doubts still persist. </p><p>As these companies are subject to the US Cloud Act, which allows US law enforcement to demand access to data – even when that’s stored outside the US – European industry stakeholders continue to voice concerns. </p><p>Last year, Microsoft president Brad Smith <a href="https://www.itpro.com/cloud/cloud-computing/microsoft-says-itll-protect-eu-cloud-customers-from-shutdown-demands">claimed the tech giant would take the US government to court</a> if forced to comply with data requests by the US administration. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sumo Logic expands European footprint with AWS Sovereign Cloud deal ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-computing/sumo-logic-expands-european-footprint-with-aws-sovereign-cloud-deal</link>
                                                                            <description>
                            <![CDATA[ The vendor is extending its AI-powered security platform to the AWS European Sovereign Cloud and Swiss Data Center ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">25RLZZTx9rBreFguu6KuSQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/c2ioK8BSh37gJhJw7diMgP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 20 Feb 2026 14:00:26 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Computing]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/c2ioK8BSh37gJhJw7diMgP-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Sumo Logic logo pictured on the side of the company&#039;s headquarters in Redwood City, California, U.S, with grey skies in background.]]></media:description>                                                            <media:text><![CDATA[Sumo Logic logo pictured on the side of the company&#039;s headquarters in Redwood City, California, U.S, with grey skies in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Sumo Logic logo pictured on the side of the company&#039;s headquarters in Redwood City, California, U.S, with grey skies in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/c2ioK8BSh37gJhJw7diMgP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Sumo Logic is expanding its EMEA footprint with planned availability of its AI-powered security solutions on the <a href="https://www.itpro.com/cloud/cloud-computing/aws-european-sovereign-cloud-explained">AWS European Sovereign Cloud</a> and Swiss Data Center region.</p><p>The move aims to bolster support for European organizations' data privacy, sovereignty, resiliency, and security needs as they push ahead with digital and <a href="https://www.itpro.com/business/leadership/ai-employees-overload">AI strategies</a>.</p><p>Sumo Logic said the expansion will enable businesses to deploy its security analytics and SIEM capabilities while keeping data in-country or within designated time zones as demand for sovereign cloud services grows.</p><p>According to <a href="https://www.idc.com/resource-center/blog/the-high-cost-of-sovereignty-in-the-age-of-ai/" target="_blank">research from <em>IDC</em></a>, 63% of organizations are now more likely to adopt <a href="https://www.itpro.com/cloud/cloud-computing/what-is-a-sovereign-cloud">sovereign cloud</a> services due to recent geopolitical events, with spending tipped to reach more than $400 million by 2029.</p><p>Despite the growing market, Eric Avery, global head of infrastructure and data at Sumo Logic, said strict data sovereignty regulations are creating barriers for many organizations – particularly across regulated sectors such as healthcare, finance, and the public sector.</p><p>“Previously, enterprises in highly regulated industries have been limited in their choice of cloud security solutions while meeting compliance requirements like Switzerland’s FADP,” he explained. </p><p>“Sumo Logic's innovations around SIEM and agentic AI, combined with <a href="https://www.itpro.com/cloud/cloud-computing/aws-says-only-europeans-will-run-its-european-sovereign-cloud-service">AWS' European Sovereign Cloud </a>infrastructure, provides the ideal response.”</p><h2 id="aws-sovereign-cloud-and-swiss-expansion">AWS sovereign cloud and Swiss expansion</h2><p>Under the expansion, Sumo Logic’s Intelligent Security Operations platform will be made available for deployments on the AWS European Sovereign Cloud to help customers operate cloud workloads in an independently governed environment while using Sumo Logic to log, track, and secure deployments.</p><p>The security vendor also confirmed plans to roll out its platform in Switzerland in an effort to better support customers that require faster in-country data processing in line with the Swiss Federal Act on Data Protection (FADP), as well as GDPR obligations.</p><p>By expanding its footprint to the AWS Swiss Data Center, Sumo Logic said organizations operating within Swiss borders will be able to leverage its agentic AI-driven log analytics and advanced SIEM capabilities to boost compliance, while benefitting from a faster, low-latency environment.</p><p>“We deliver reliable security operations that help organizations stay secure and compliant while running services locally with the performance and scale they need,” Avery added.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ EU inaugurates NanoIC facility for next-generation chips ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/hardware/eu-inaugurates-nanoic-facility-for-next-generation-chips</link>
                                                                            <description>
                            <![CDATA[ The project forms part of efforts to reduce reliance on US and Asian supply chains ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">HEQsG6qQywy2GuKXqkx7JP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/d5ftRe88HMZW8wcJtCZDsJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 10 Feb 2026 13:58:35 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hardware]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/d5ftRe88HMZW8wcJtCZDsJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Quantum cybersecurity concept image showing a quantum chip with glowing lights connected to a digital interface and circuit board. ]]></media:description>                                                            <media:text><![CDATA[Quantum cybersecurity concept image showing a quantum chip with glowing lights connected to a digital interface and circuit board. ]]></media:text>
                                <media:title type="plain"><![CDATA[Quantum cybersecurity concept image showing a quantum chip with glowing lights connected to a digital interface and circuit board. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/d5ftRe88HMZW8wcJtCZDsJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The European Union (EU) has put €700 million into NanoIC, the largest of five pilot lines designated under the <a href="https://www.itpro.com/business/policy-legislation/362185/european-commission-proposes-eu43-billion-chips-act">EU Chips Act</a>.</p><p>The Act includes five lines – Fames, Apecs, WBG, PixEurope and NanoIC - aimed at bringing chip technology "from the lab to the fab". The aim is to strengthen the position of European players in the global semiconductor market, reducing the current reliance on Asian and US supply chains. </p><p>NanoIC has now pulled in a total of €2.5 billion in investment, with €700 million from national and regional governments and the rest from ASML and other industry partners. </p><p>In a statement confirming the move, the European Commission said NanoIC will accelerate the development of next-generation semiconductor technology for use in <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a>, autonomous vehicles, healthcare, and 6G mobile technology.</p><p>It's the first European facility to deploy the most advanced Extreme Ultraviolet lithography machine. This allows the design and manufacture of chips using technology beyond two nanometers – a big step forward for the European semiconductor manufacturing industry.</p><p>NanoIC is built on the principle of open access, with startups, researchers, SMBs and large organizations all able to use the facilities. </p><p>The project is based at the Interuniversity Centre for Microelectronics in Leuven, Belgium, and is supported by partners including Tyndall National Institute in Ireland, French research organization CEA-Leti, and Germany's Fraunhofer-Gesellschaft.</p><p>The site includes a new 2,000 square meters expansion of the existing cleanroom, bringing it up to more than 12,000 square meters. Construction will begin soon to create an extra 4,000 square meter cleanroom.</p><p>It will house a best-in-class toolset, including ASML’s next-generation High NA EUV scanner, which is scheduled to arrive in the middle of next month.  Over the next five years, the NanoIC pilot line will integrate more than a hundred new tools, distributed across imec and its partner sites. </p><p>"By providing access to cutting-edge semiconductor technologies, the NanoIC pilot line will play a crucial role in strengthening Europe’s industrial fabric in the AI era, and ensuring a climate of economic growth, security, and prosperity for decades to come,” said Luc Van den hove, CEO of imec, which is hosting the project. </p><p>The pilot lines come four years after the Chips Act was first announced in 2022. Last month, EU member states officially endorsed a Semiconductor Declaration calling for the Act to be strengthened though a Chips Act 2.0. </p><p>“We don't have the luxury of being the biggest or the strongest, but we do have the choice to be the best,” said Matthias Diependaele, Flemish minister-president. “With the NanoIC pilot line, Europe is making that choice a reality: for technological excellence and strategic independence." </p><p>Fames, a pilot line aimed at advancing ultra-low-power semiconductors in Europe, launched late last month, covering advanced FD-SOI nodes, embedded non-volatile memories, RF passives, 3D integration and power management.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Trade groups claim EU’s Digital Networks Act risks “favoring the interests of outdated telecom monopolies” ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/infrastructure/networking/eu-digital-networks-act-opposition-ccia-gsma</link>
                                                                            <description>
                            <![CDATA[ The European Commission has set out its proposals to boost the EU's connectivity, to some criticism from industry associations ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">UwStv2UD2PqP7Zz9R57XkG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5vg5Sdyrhq9higntJj6kzg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 22 Jan 2026 10:56:14 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Networking]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5vg5Sdyrhq9higntJj6kzg-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Five European Union (EU) flags rustling in the wind outside the EU headquarters in Brussels, Belgium.]]></media:description>                                                            <media:text><![CDATA[Five European Union (EU) flags rustling in the wind outside the EU headquarters in Brussels, Belgium.]]></media:text>
                                <media:title type="plain"><![CDATA[Five European Union (EU) flags rustling in the wind outside the EU headquarters in Brussels, Belgium.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5vg5Sdyrhq9higntJj6kzg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>European Trade groups have hit out at the EU’s proposed <a href="https://digital-strategy.ec.europa.eu/en/policies/digital-networks-act" target="_blank">Digital Networks Act (DNA)</a> amid concerns the legislation could favor “outdated telecom monopolies”. </p><p>The European Commission (EC) set out its proposals for the legislation this week, which aims to modernize, simplify, and harmonize regional rules on connectivity networks. </p><p>The Act introduces mandatory national transition plans to <a href="https://www.itpro.com/infrastructure/networking/can-ai-deliver-better-broadband">phase out copper networks</a> and transition to advanced networks between 2030 and 2035. </p><p>Meanwhile, the hope is that by cutting red tape, it will encourage operators to invest in rolling out advanced fiber and <a href="https://www.itpro.com/infrastructure/mobile-networks">mobile networks</a>, and that this will in turn attract investment in <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>and the <a href="https://www.itpro.com/627952/what-is-cloud-computing">cloud</a>. </p><p>"High-performance resilient <a href="https://www.itpro.com/infrastructure/data-centres/data-centers-finally-get-critical-national-infrastructure-designation-in-the-uk">digital infrastructure</a> is essential in strengthening Europe’s leadership in innovation, competitiveness and digital sovereignty," sad Henna Virkkunen, executive vice-president for tech sovereignty, security and democracy.</p><p>"Advanced and accessible connectivity will allow start-ups to harness the potential of AI, enable doctors to care for patients remotely, quickly and safely. Our goal is a digital environment where new technologies are readily available, affordable, and grounded in fair trustworthy rules that benefit people."</p><h2 id="key-rules-under-the-digital-networks-act">Key rules under the Digital Networks Act</h2><p>Under the proposals, companies will only have to register in one EU country to provide services across the union. There will be incentives for pan-European satellite communication services through an EU-level, as opposed to national level.</p><p>The Act will also make national spectrum authorization more consistent by giving operators longer spectrum licenses and by making licenses renewable by default. </p><p>This, lawmakers said, will ensure that all available spectrum is being used by imposing a "use it or share it" rule on operators. </p><p>Similarly, this will also see the introduction of a voluntary cooperation mechanism between connectivity providers and other players, such as content application and cloud providers.</p><h2 id="opposition-is-mounting">Opposition is mounting</h2><p>The proposals have drawn fire from the Computer & Communications Industry Association (CCIA Europe). The Act's voluntary cooperation and dispute management scheme, it said, are unnecessary, as online service providers and telecom operators already cooperate. </p><p>The new mechanism would leave the door open for legislative amendments or rulings by national regulatory authorities that could turn it into a binding IP dispute-resolution system, the trade group warned. </p><p>That would effectively resurrect widely-rejected network fees, allowing dominant telecoms operators to extract unjustified revenues from popular online services.</p><p>“This is not a ‘voluntary conciliation’ procedure, but one that will create new disputes. It risks harming every part of Europe’s connectivity ecosystem," said CCIA Europe’s senior policy manager, connectivity and competition, Maria Teresa Stecher.</p><p>“The DNA could have been a real opportunity to simplify EU rules and boost competitiveness. Instead, the Commission now risks doing the opposite – favoring the interests of outdated telecom monopolies over European consumers, innovative online services, and better connectivity. This is not simplification, it is a step backwards.” </p><p>The GSM Association (GSMA), a lobby group for the mobile communications industry, echoed the CCIA's concerns over the conciliation process, airing a few additional concerns of its own.</p><p>Chief among these are concerns that this will add a new layer of complexity for providers and that aspects of the legislation stem from the "largely outdated" ePrivacy Directive.</p><p>"A key priority for the Commission over the past 12 months has been ‘simplification’," it said.</p><p>"But we now face the prospect of even more sector-specific rules, additional administrative bodies and reporting obligations, and the retention of unnecessary, redundant or duplicative elements including consumer protection and rules stemming from a largely outdated <a href="https://www.itpro.com/privacy/32712/eprivacy-regulation-what-is-it-and-how-does-it-affect-me">ePrivacy Directive</a>. This is not simplification, it is complexification."</p><p>The proposal will now be presented to the European Parliament and Council for approval.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ European Commission approves data flows with UK for another six years ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/european-commission-approves-data-flows-with-uk-for-another-six-years</link>
                                                                            <description>
                            <![CDATA[ The European Commission says the UK can have seamless data flows for another six years despite recent rule changes ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Dg2XD2EjDvXVebwCQorX26</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YPLAJxoRSrPttgxeZWQkeG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 24 Dec 2025 08:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YPLAJxoRSrPttgxeZWQkeG-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[European Union (EU) concept image showing flag on a digitized background with ripples flowing out from 12 stars.]]></media:description>                                                            <media:text><![CDATA[European Union (EU) concept image showing flag on a digitized background with ripples flowing out from 12 stars.]]></media:text>
                                <media:title type="plain"><![CDATA[European Union (EU) concept image showing flag on a digitized background with ripples flowing out from 12 stars.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YPLAJxoRSrPttgxeZWQkeG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The European Commission (EC) has renewed a pair of rules that will allow data to continue flowing between the European Economic Area and the UK. </p><p>The adequacy decisions were agreed after the UK left the EU via "Brexit" in 2020 on the grounds that the UK legal framework for data protections were as good as those in Europe. </p><p>While that was welcome news for British companies dependent on the flow of data, the former government still complained that the decision should have been <a href="https://www.itpro.com/policy-legislation/data-protection/358674/eu-grants-the-uk-provisional-data-adequacy-status"><u>taken before the official Brexit withdrawal date.</u></a></p><p>That agreement ran out in June 2025, but was given a technical extension of six months to give the EC time to consider the impact of changes brought in via <a href="https://www.itpro.com/security/data-protection/data-use-and-access-act-comes-into-force"><u>Labour's Data (Use and Access) Act</u></a>. </p><p>This loosened up some data controls for research and charitable fundraising, while requiring companies to have a data protection complaints procedure. </p><p>The aim, said then technology secretary Peter Kyle, was to enable the government to make use of the "goldmine of data" it holds for policing, admin and more. </p><p>In particular, the EC was considering the impact of those changes on the General Data Protection Regulation (GDPR) and the Law Enforcement Directive. </p><h2 id="six-year-renewal">Six-year renewal </h2><p>Now, the EC has announced that the adequacy decisions have been given another six years until 2031, with the possibility of renewal again, with the Commission and European Data Protection Board reviewing the system and any changes in four years.</p><p>"The decisions ensure that personal data can continue flowing freely and safely between the European Economic Area (EEA) and the United Kingdom, as the UK legal framework contains data protection safeguards that are essentially equivalent to those provided by the EU," the EC said in a statement.</p><p>The renewal means data will be able to continue to flow between the UK and Europe, avoiding serious disruption for businesses if that were to stop. </p><h2 id="adequacy-agreements">Adequacy agreements</h2><p>The EC's first adequacy decision with a non-EU country following the introduction of GDPR was with Japan, coming into force in 2019, though the European body had similar agreements in place for other countries including Canada before the regulation was introduced. </p><p>Other countries with adequacy decisions in place include the US, Switzerland, Argentina, and Korea. </p><p>"The European Commission has the competence to determine, on the basis of the General Data Protection Regulation, whether a country or international organisation outside the EU ensures an adequate level of data protection," the EC explained. </p><p>"Following this, the Commission might initiate the process for the adoption of an adequacy decision, which allows the free flow of personal data from the EU and the European Economic Area (EEA) to a third country or international organisation without further obstacles."</p><p>For the UK renewal, a wide range of opinions were sought. "The adoption of the renewal decisions follows the European Data Protection Board's opinion and the Member States' green light in the so-called comitology procedure," the EC said in a statement, referring to a system that enables the EC to implement rules under the review of national representatives from member states.</p><p>The UK adequacy agreement was approved despite the changes introduced by the Data (Use and Access) Act introduced by the Labour government – which were <a href="https://www.theregister.com/2025/12/22/eu_uk_data_adequacy/"><u>more limited than a data overhaul</u></a> initially <a href="https://www.itpro.com/policy-legislation/368448/government-replace-gdpr-with-data-reform-bill"><u>planned by the last Conservative government</u></a> that may not have been seen in such a positive light by the EC and member states. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ EU lawmakers want to limit the use of ‘algorithmic management’ systems at work ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/privacy/eu-lawmakers-want-to-limit-the-use-of-algorithmic-management-systems-at-work</link>
                                                                            <description>
                            <![CDATA[ All workplace decisions should have human oversight and be transparent, fair, and safe, MEPs insist ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wmC5cfiUeRywWwRyUaNThT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ChVns2sZRm8ohNECYxRrPh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 18 Dec 2025 10:32:17 +0000</pubDate>                                                                                                                                <updated>Thu, 18 Dec 2025 10:33:07 +0000</updated>
                                                                                                                                            <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ChVns2sZRm8ohNECYxRrPh-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data privacy concept image showing digitized human eyeball surrounded by data platforms and statistical interface panels.]]></media:description>                                                            <media:text><![CDATA[Data privacy concept image showing digitized human eyeball surrounded by data platforms and statistical interface panels.]]></media:text>
                                <media:title type="plain"><![CDATA[Data privacy concept image showing digitized human eyeball surrounded by data platforms and statistical interface panels.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ChVns2sZRm8ohNECYxRrPh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>MEPs are calling on the European Commission to establish more robust rules on the use of algorithms in recruitment and staff management amidst concerns over privacy and discrimination.</p><p>According to recent <a href="https://www.europarl.europa.eu/RegData/etudes/STUD/2025/774670/EPRS_STU(2025)774670_EN.pdf" target="_blank"><u>EU research</u></a>, 42% of EU workers are currently subject to algorithmic management in the workplace, a figure expected to rise to 55.5% within the next five years.</p><p>There's already legislation on artificial intelligence and data protection at EU level, including the <a href="https://www.itpro.com/business/policy-and-legislation/the-second-enforcement-deadline-for-the-eu-ai-act-is-approaching-heres-what-businesses-need-to-know-about-the-general-purpose-ai-code-of-practice">EU AI Act</a> and <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR</a>, while rules focusing more specifically on the use of AI at work are laid out in the Platform Work Directive.</p><p>However, the EU lawmakers believe that more specific legislation is required. It has now proposed a series of recommendations aimed at ensuring that the use of automated monitoring and decision-making systems in the workplace is transparent, fair, and safe.</p><p>The main thrust of the proposals is that there must be human oversight of all decisions taken or supported by algorithmic management systems.</p><p>Workers should have the right to request explanations of any decisions taken or supported by such systems - and, if a worker believes his or her rights to have been infringed, they should have the right to ask for a review. </p><p>If successful, the system in question could be modified or discontinued.</p><p>Decisions on the offer or termination of employment, the renewal or non-renewal of a contract, changes in pay, or disciplinary action should always be taken by a human and be subject to human review.</p><p>"This topic affects both employers and 200 million workers in the EU. A human-centered approach is key, and the rights, safety, and dignity of employers and employees must be strictly respected," said MEP Andrzej Buła. </p><p>"This sends a strong signal: Europe can combine competitiveness with social responsibility. It can support innovative enterprises without sacrificing high standards and employee protection."</p><h2 id="cracking-down-on-algorithmic-management">Cracking down on ‘algorithmic management’</h2><p>A key focus of the crackdown centers on the fact that workers should be informed about how algorithmic management systems impact working conditions, when they're used to take automated decisions, what type of data they collect or process, and how human oversight is ensured. </p><p>MEPs believe workers should be consulted when these systems are used to make decisions affecting pay, evaluation, task allocation or working time. </p><p>Similarly, the use of these systems should respect wellbeing and not put workers' safety or physical or mental health at risk.</p><p>To protect workers’ privacy and data, the proposed rules would ban the processing of data relating to the emotional, psychological or neurological states of employees, as well as their private communications or geolocation outside working hours. </p><p>Elsewhere, the guidelines aim to limit the use of employee data while off-duty, as well as the use of data relating to freedom of association and collective bargaining. </p><p>There were 451 votes in favour of the recommendations and 45 against, with 153 abstentions. The European Commission now has three months to respond, by either informing Parliament on the steps it plans to take, or by giving reasons for a refusal.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Will the future of AI be made in Europe? The EU thinks so ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence/will-the-future-of-ai-be-made-in-europe-the-eu-thinks-so</link>
                                                                            <description>
                            <![CDATA[ European Commission unveils two plans backed by €1 billion to help homegrown AI ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xPr7VJJw2ffQaLFnhBFt2d</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/y6tegU6S8qaKFmtHCKZp5Y-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 09 Oct 2025 10:33:27 +0000</pubDate>                                                                                                                                <updated>Thu, 09 Oct 2025 10:35:33 +0000</updated>
                                                                                                                                            <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/y6tegU6S8qaKFmtHCKZp5Y-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Flags of the European Union (EU) pictured on a still day with sunshine in background]]></media:description>                                                            <media:text><![CDATA[Flags of the European Union (EU) pictured on a still day with sunshine in background]]></media:text>
                                <media:title type="plain"><![CDATA[Flags of the European Union (EU) pictured on a still day with sunshine in background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/y6tegU6S8qaKFmtHCKZp5Y-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The European Union wants <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a> to be made in Europe – and it's chucking more than €1 billion into the pot to help make it happen. </p><p>The EU's European Commission unveiled two plans to boost homegrown AI innovation. The first is the Apply AI Strategy, which aims to speed up the use of AI in key industries as well as the public sector, and the AI in Science Strategy, which focuses on AI in research and science. </p><p>"I want the future of AI to be made in Europe," said Ursula von der Leyen, President of the European Commission, in a <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_25_2299">statement</a>. "Because when AI is used, we can find smarter, faster, and more affordable solutions."</p><p>She added, "AI adoption needs to be widespread, and with these strategies, we will help speed up the process. Putting AI first also means putting safety first. We will drive this '<a href="https://www.itpro.com/technology/artificial-intelligence/ai-first-partnerships-unlocking-scalable-growth-for-business">AI first</a>' mindset across all our key sectors, from robotics to healthcare, energy, and automotive."</p><p>The Apply AI and AI in Science strategies follow plans from earlier this year that aimed to reduce regulatory burdens and costs for AI companies. </p><h2 id="ai-for-europe">AI for Europe</h2><p>Such plans are seen as a way to balance the dominance of the US and China when it comes to AI and other future-looking technologies, and give Europe its own " digital sovereignty" in terms of infrastructure and R&D. </p><p>"Europe is well-positioned to become an AI continent," said Henna Virkkunen, Executive Vice-President for Tech Sovereignty, Security, and Democracy, in a statement. "With the Apply AI Strategy, we will help our companies and key sectors, from manufacturing to healthcare and the public sector, use AI to deliver real benefits for EU citizens, reinforce our competitiveness, and strengthen our technological sovereignty."</p><p>That follows efforts by US companies to build infrastructure in Europe, with a push towards <a href="https://www.itpro.com/policy-legislation/data-governance/368517/oracle-to-build-sovereign-cloud-regions-in-the-eu-for-2023">sovereign clouds</a> and the ability to keep <a href="https://www.itpro.com/cloud/cloud-computing/369720/microsofts-eu-data-boundary-rollout-january-2023">data in Europe</a>. </p><h2 id="what-is-the-apply-ai-strategy">What is the Apply AI Strategy?</h2><p>This aspect of the EU's plans looks to encourage adoption of AI, in particular among smaller and medium-sized companies across key industries, including healthcare, pharmaceuticals, energy, mobility, manufacturing, construction, agri-food, defence, communications, and culture, as well as the public sector. </p><p>"It encourages an AI-first policy, so more companies consider AI as a part of the solution to tackle challenges, while taking into careful consideration the benefits and the risks of the technology," the EC said in a statement. </p><p>To help, the EC is "mobilising" €1 billion for "concrete measures" including setting up AI-powered healthcare screen centres, building <a href="https://www.itpro.com/security/cyber-crime/agentic-ai-cybersecurity-risks">agentic AI</a> for manufacturing and other industries, and developing frontier models. </p><p>The aim isn't just to boost industry, however. "The strategy will help boost EU capabilities to unlock societal benefits, from enabling more accurate healthcare diagnoses to enhancing the efficiency and accessibility of public services," the EC added. </p><h2 id="what-is-the-ai-in-science-strategy">What is the AI in Science Strategy?</h2><p>The aim with this side of the EC's plan is to set up Europe as a centre for AI-driven scientific innovation. </p><p>At the core is a virtual institute to coordinate the use of AI in science, as well as AI resources, known as the Resource for AI Science in Europe (RAISE). </p><p>The EC is also investing €58 million to help train and retain AI talent, encouraging them to "Choose Europe", with a further €600 million from funding body Horizon Europe dedicated to infrastructure. The EC said it hopes to double Horizon Europe's annual spend on AI to €3 billion. </p><p>"But this is not only about money," said Ekaterina Zaharieva, Commissioner for Startups, Research and Innovation, in a <a href="https://ec.europa.eu/commission/presscorner/detail/en/statement_25_2324">statement</a>. "It is about building a European way for AI in science: open, collaborative, interdisciplinary, and responsible; where AI serves science, and science serves society."</p><p>She added: "With this strategy, Europe is making a purposeful choice to empower scientists, nurture talent and safeguard our sovereignty."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Three things you need to know about the EU Data Act ahead of this week's big compliance deadline ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/three-things-you-need-to-know-about-the-eu-data-act-ahead-of-this-weeks-big-compliance-deadline</link>
                                                                            <description>
                            <![CDATA[ A host of key provisions in the EU Data Act will come into effect on 12 September, and there’s a lot for businesses to unpack. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">RLXZuY9bCm8EwcWY4Xc4q5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YPLAJxoRSrPttgxeZWQkeG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 11 Sep 2025 12:02:00 +0000</pubDate>                                                                                                                                <updated>Thu, 11 Sep 2025 12:02:32 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YPLAJxoRSrPttgxeZWQkeG-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[European Union (EU) concept image showing flag on a digitized background with ripples flowing out from 12 stars.]]></media:description>                                                            <media:text><![CDATA[European Union (EU) concept image showing flag on a digitized background with ripples flowing out from 12 stars.]]></media:text>
                                <media:title type="plain"><![CDATA[European Union (EU) concept image showing flag on a digitized background with ripples flowing out from 12 stars.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YPLAJxoRSrPttgxeZWQkeG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A host of key provisions in the EU Data Act will come into effect on 12 September, and there’s a lot for businesses to unpack. </p><p>The regulation came into force on 11 January 2024 and while a grace period has been running to ensure implementation, rules under the legislation will be applicable across the European Union (EU) from here onward. </p><p>At its core, the EU Data Act will introduce sweeping changes with regard to how data from connected devices and cloud services is accessed, managed, and shared across the union. This includes new rules on data access, service portability for organizations, and contractual fairness. </p><p>The potential long-term impact of the legislation cannot be understated, according to Soniya Bopache, VP and general manager for data compliance at Arctera. </p><p>“The EU Data Act has the potential to foster a more competitive and equitable data economy – largely thanks to its provisions on data access, fair contractual terms, and cloud switching,” she said. </p><p>“For businesses governed by the Act, this isn’t just a matter of compliance, it’s an opportunity to build a more transparent, efficient, and innovative digital ecosystem.”</p><p>So what can businesses expect with the EU Data Act?</p><h2 id="what-industries-fall-under-the-eu-data-act">What industries fall under the EU Data Act?</h2><p>The legislation applies to a broad range of sectors, spanning areas such as manufacturing, <a href="https://www.itpro.com/627952/what-is-cloud-computing">cloud computing</a>, transport, and consumer goods. </p><p>Moreover, it’s not limited to the private sector, with public sector organizations also expected to benefit from the legislation, according to Peter Grimmond, VP and head of technology at <a href="https://www.itpro.com/cloud/cloud-security/cohesity-expands-partnership-with-google-cloud-to-drive-generative-ai-data-insights">Cohesity</a>.</p><p>“The EU Data Act has huge potential to deliver acceleration of both public and private sector innovation, through increased <a href="https://www.itpro.com/business/data-and-insights/what-is-data-democratization">data democratization</a> and access,” he said. </p><p>“For all enterprise and public sector organisations that have a robust, compliant, data classification processes already in place, the act will create an environment of collaboration and innovation where innovation can thrive without compromising corporate resilience or individual rights”</p><h2 id="data-access-and-transparency">Data Access and Transparency</h2><p>Data access and transparency is a key focus of the legislation, according to official EU <a href="https://digital-strategy.ec.europa.eu/en/factpages/data-act-explained" target="_blank"><u>materials </u></a>on the Act. </p><p>Fundamentally, the regulations are designed to “enhance the EU’s data economy and foster a competitive data market” by making data more accessible and usable. </p><p>The move comes in the wake of an explosion of connected devices across the union in recent years. These IoT products collect vast volumes of data, which the legislation aims to capitalize on for reuse across the region. </p><p>To achieve this, new rules under the act will give users of connected devices - including businesses and individuals - greater control over the data they produce. </p><p>Similarly, the Act also includes rules on how enterprises can share data with other businesses. According to Grimmond, this aspect of the legislation could deliver positive long-term benefits for both businesses and consumers alike. </p><p>“It will speed the ability for data to be shared from more devices across more organisations, and opens the door for the development of new products, services, and ways of doing business,” he explained. </p><p>“Crucially, it does this without undermining the robust privacy standards that are the EU’s hallmark regulatory framework: building on <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR’s </a>global standard for privacy and aligning with <a href="https://www.itpro.com/business/policy-legislation/368414/eu-digital-operational-resilience-act-dora">DORA’s </a>focus on digital operational resilience.”</p><h2 id="cloud-service-flexibility">Cloud service flexibility</h2><p>As mentioned, another core aspect of the legislation centers around data portability, particularly with regard to cloud services. The Act aims to provide enterprises more flexibility in how they engage with cloud providers and, crucially, switching or opting for multiple options. </p><p>This aspect of the legislation comes in direct response to growing calls for a more fluid and competitive cloud computing industry in the EU, with enterprises having contended with “<a href="https://www.itpro.com/cloud/362542/vendor-lock-in-is-it-worth-worrying-about-in-the-cloud">vendor lock-in</a>” for several years now. </p><p>Running parallel to this frustration has been the rise of <a href="https://www.itpro.com/cloud/34476/what-is-multi-cloud">multi-cloud</a> and <a href="https://www.itpro.com/hybrid-cloud/29668/what-is-hybrid-cloud">hybrid cloud</a> strategies, whereby enterprises host data on multiple providers, or through a combination of on-prem and cloud-based services. </p><p>Yet businesses with one particular cloud provider aiming to switch to another have faced significant costs transferring data. These “egress fees” have become a recurring point of contention and even prompted legal action against major industry providers. </p><p>With this in mind, the EU Data Act includes measures that ensure customers can switch from one data processing service to another in a more efficient manner. </p><p>Notably, the Act doesn’t specifically rule out vendors charging fees for data transfers. However, it obliges cloud providers to pass on these costs to the customer rather than charging excessive payments. </p><p>Some providers have taken steps to adhere to the new legislation. Google Cloud, for example, recently announced it would <a href="https://www.itpro.com/cloud/cloud-computing/google-cloud-introduces-no-cost-data-transfers-for-uk-eu-businesses">waive data transfer fees for customers switching to another provider</a>. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/business/policy-and-legislation/dora-and-why-resilience-once-again-matters-to-the-board">DORA and why resilience (once again) matters to the board</a></li><li><a href="https://www.itpro.com/business/policy-legislation/370403/what-is-the-network-and-information-security-2-nis2-directive">Everything you need to know about the NIS2 Directive</a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/the-second-enforcement-deadline-for-the-eu-ai-act-is-approaching-heres-what-businesses-need-to-know-about-the-general-purpose-ai-code-of-practice">What businesses need to know about the General-Purpose AI Code of Practice</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The second enforcement deadline for the EU AI Act is approaching – here’s what businesses need to know about the General-Purpose AI Code of Practice ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/the-second-enforcement-deadline-for-the-eu-ai-act-is-approaching-heres-what-businesses-need-to-know-about-the-general-purpose-ai-code-of-practice</link>
                                                                            <description>
                            <![CDATA[ General-purpose AI model providers will face heightened scrutiny ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">a8ZtL4J6csok6tvrb68aoh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YPLAJxoRSrPttgxeZWQkeG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 31 Jul 2025 09:26:10 +0000</pubDate>                                                                                                                                <updated>Thu, 31 Jul 2025 09:26:31 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YPLAJxoRSrPttgxeZWQkeG-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[European Union (EU) concept image showing flag on a digitized background with ripples flowing out from 12 stars.]]></media:description>                                                            <media:text><![CDATA[European Union (EU) concept image showing flag on a digitized background with ripples flowing out from 12 stars.]]></media:text>
                                <media:title type="plain"><![CDATA[European Union (EU) concept image showing flag on a digitized background with ripples flowing out from 12 stars.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YPLAJxoRSrPttgxeZWQkeG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The second major enforcement deadline for the EU AI Act is approaching, meaning big tech firms will face a greater degree of scrutiny over AI model safety. </p><p>From August 2nd, new governance rules for general-purpose AI (GPAI) models will be introduced through a <a href="https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai#:~:text=The%20General%2DPurpose%20AI%20(GPAI,drafting%20process%20of%20the%20code." target="_blank"><u>voluntary Code of Practice</u></a>. </p><p>The deadline represents the second major enforcement date for the landmark legislation this year, following on from a <a href="https://www.itpro.com/technology/artificial-intelligence/a-big-enforcement-deadline-for-the-eu-ai-act-is-just-around-the-corner">February deadline which focused primarily on prohibited use cases</a>. </p><p>Enza Iannopollo, VP principal analyst at Forrester, said that while the onus will be placed on providers, enterprise end-users will also likely feel the impact of the new rules. </p><p>“Whilst the first regulatory milestone on 2nd February focused on requirements, including those on prohibited use cases, this second deadline expands accountability and enforcement as it introduces critical provisions regarding general-purpose AI (GPAI) models,” she explained.</p><p>“Providers of <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai">generative AI</a> models are directly responsible for meeting these new rules, however it’s worth noting that any company using genAI models and systems — those directly purchased from genAI providers or embedded in other technologies — will feel the impact of these requirements on their value chain and on their third-party <a href="https://www.itpro.com/security/do-risk-awareness-and-risk-management-strategies-actually-make-a-difference">risk management</a> practices.”  </p><h2 id="what-the-gpai-code-of-practice-means-for-businesses">What the GPAI code of practice means for businesses</h2><p>The GPAI code of practice will enforce more robust guardrails for training AI models, according to EU lawmakers, and is based on three key pillars. </p><p>This includes greater transparency, meaning AI model providers are required to document and disclose training processes and share information on models with regulators. </p><p>Safety and security are a key focus of the code, again focusing on whether GPAI models pose risks to the public or enterprises. Under the new rules, providers are required to assess and document potential harms and take appropriate action to reduce any risks. </p><p>Dirk Schrader, resident CISO (EMEA) and VP of security research at Netwrix, said security considerations in the act are welcomed and help create a more aligned approach to AI-related security risks. </p><p>“One of the most significant anticipated successes of the Act is the standardization of AI security across the European Union, creating a harmonized, EU-wide security baseline,” he said. </p><p>“A key strength of the proposed regulations is their emphasis on a security-by-design ethos, mandating a lifecycle approach that integrates security considerations from the outset and throughout an <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>system's operational life.”</p><p>Security considerations do raise questions over compliance, however. Simply put, there isn’t a solid baseline for enterprises to work from with regard to <a href="https://www.itpro.com/technology/artificial-intelligence/majority-firms-using-generative-ai-related-security-incidents">AI-related security risks</a> at this stage. </p><p>“The Act is the first major law to call out protections against data poisoning, model poisoning, adversarial examples, confidentiality attacks, and model flaws,” he said. </p><p>“The real compliance burden will be determined by technical specifications that don't yet exist, as these will define the practical meaning of 'appropriate level of <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a>' and may evolve rapidly as AI threats mature.”</p><p>Elsewhere, rules pertaining to copyright are also outlined in the code of practice, and this has been a major point of contention in recent months. For example, under the code, signatories must ensure training data is sourced lawfully. </p><p>A host of major tech companies have agreed to the code of practice, most recently Google and OpenAI. Some, however, have taken a harder stance. </p><p>Earlier this month, <a href="https://www.itpro.com/business/policy-and-legislation/meta-isnt-playing-ball-with-the-eu-on-the-ai-act">Meta revealed it won’t sign up for the code of practice</a> amid what it described as concerns over “legal uncertainties”. </p><p>In a LinkedIn post clarifying the company’s stance on the code, Meta’s chief global affairs officer Joel Kaplan said the code will introduce measures which “go far beyond the scope of the AI Act”. </p><p>"Europe is heading down the wrong path on AI. We have carefully reviewed the European Commission’s Code of Practice for general-purpose AI (GPAI) models and Meta won’t be signing it," he said. </p><h2 id="the-risks-of-non-compliance">The risks of non-compliance</h2><p>Organizations that fail to comply with the EU AI Act face serious repercussions, and while the new code of practice is voluntary, Iannopollo said it’s crucial that enterprises operating in the region pay close attention to the enforcement deadline. </p><p>“Like it or not, the <a href="https://www.itpro.com/business/policy-and-legislation/unraveling-the-eu-ai-act">EU AI Act</a> will contribute to shape AI risk management and AI governance practices of most global companies,” she said. “Its requirements may not be perfect, but they are the only binding set of rules on AI with global reach, and it represents the only realistic option of <a href="https://www.itpro.com/technology/artificial-intelligence-ai/370342/inside-mozillas-mission-to-champion-trustworthy-ai">trustworthy AI</a> and responsible innovation. </p><p>“It’s crucial that companies operating AI technology in the EU, or using AI-generated insights within the EU market, pay attention to this enforcement milestone.”</p><p>The EU AI Act contains “significant fines” for non-compliance, including up to 7% of a company’s global turnover. Iannopollo noted that not all the authorities responsible for enforcement are up and running yet, but others are, including the <a href="https://www.itpro.com/business/policy-and-legislation/the-clock-is-ticking-for-firms-to-comply-with-the-eu-ai-act-heres-what-you-need-to-know">EU AI Office</a>. </p><p>“Companies, make no mistake: there will be action in the next few months,” she said. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/business/policy-and-legislation/the-eu-just-shelved-its-ai-liability-directive">The EU just shelved its AI liability directive</a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/how-the-eu-ai-act-compares-to-other-international-regulatory-approaches">How the EU AI Act compares to other international regulatory approaches</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/eu-ai-act-everything-you-need-to-know-about-the-legislation-including-rules-requirements-and-who-will-be-forced-to-comply">Everything you need to know about the EU AI Act</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Meta isn’t playing ball with the EU on the AI Act ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/meta-isnt-playing-ball-with-the-eu-on-the-ai-act</link>
                                                                            <description>
                            <![CDATA[ Europe is 'heading down the wrong path on AI', according to Meta, with the company accusing the EU of overreach ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KhFr49uEw5Fx54P4VMjqo6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Kk6Qvhw6UhQGx3igACUs4E-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 21 Jul 2025 10:33:02 +0000</pubDate>                                                                                                                                <updated>Mon, 21 Jul 2025 10:33:24 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Kk6Qvhw6UhQGx3igACUs4E-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo and branding of Meta, developer of the Llama 4 AI model range, pictured at an event in Mumbai, India.]]></media:description>                                                            <media:text><![CDATA[Logo and branding of Meta, developer of the Llama 4 AI model range, pictured at an event in Mumbai, India.]]></media:text>
                                <media:title type="plain"><![CDATA[Logo and branding of Meta, developer of the Llama 4 AI model range, pictured at an event in Mumbai, India.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Kk6Qvhw6UhQGx3igACUs4E-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Meta has said it won't sign up for the EU's code of practice for providers of <a href="https://www.itpro.com/technology/artificial-intelligence/the-eu-just-launched-a-bold-new-initiative-to-support-regional-ai-startups-and-drive-innovation">general-purpose AI models</a>, citing concerns over "legal uncertainties".</p><p>The voluntary guidelines form part of the <a href="https://www.itpro.com/technology/artificial-intelligence/eu-ai-act-everything-you-need-to-know-about-the-legislation-including-rules-requirements-and-who-will-be-forced-to-comply">EU AI Act</a>, due to come into force next month. They ask companies to, amongst other things, refrain from <a href="https://www.itpro.com/technology/artificial-intelligence/dollar100-billion-to-build-an-ai-model-anthropic-ceo-dario-amodei-predicts-soaring-ai-training-costs-but-models-will-become-far-more-powerful">training AI</a> on pirated materials and comply with requests from content creators to omit their work from training data.</p><p>As part of the rules, providers are also required to issue regular updates on <a href="https://www.itpro.com/software/development/ai-tools-software-development-workforce-layoffs">AI tools</a> and services.</p><p>While the code is voluntary, the EU has said that AI providers who don't sign up will be expected to demonstrate compliance by other means, and might face more regulatory scrutiny.</p><p>Meta has hit back at lawmakers, however, accusing the EU of overreach. </p><p>"Europe is heading down the wrong path on AI. We have carefully reviewed the European Commission’s Code of Practice for general-purpose AI (GPAI) models and Meta won’t be signing it," wrote chief global affairs officer Joel Kaplan in a <a href="https://www.linkedin.com/posts/joel-kaplan-63905618_europe-is-heading-down-the-wrong-path-on-activity-7351928745668055042-XuF7/" target="_blank"><u>post on LinkedIn</u></a>. </p><p>"This Code introduces a number of legal uncertainties for model developers, as well as measures which go far beyond the scope of the AI Act."</p><h2 id="meta-has-history-with-the-eu">Meta has history with the EU</h2><p>Meta has been complaining about the AI Act for a while. Last summer, <a href="https://www.itpro.com/software/development/a-sign-of-things-to-come-in-software-development-mark-zuckerberg-says-ai-will-be-doing-the-work-of-mid-level-engineers-this-year-and-hes-not-the-only-big-tech-exec-predicting-the-end-of-the-profession">Mark Zuckerberg</a> and Spotify CEO Daniel Ek issued a <a href="https://about.fb.com/news/2024/08/why-europe-should-embrace-open-source-ai-zuckerberg-ek/" target="_blank"><u>joint statement</u></a> saying that "Europe’s risk-averse, complex regulation could prevent it from capitalizing on the big bets that can translate into big rewards."</p><p>The tech giant has support from US president Donald Trump on the issue, who has called for the AI Act to be paused - although the EU appears to be standing firm. </p><p>Henna Virkkunen, the European Commission vice-president responsible for tech sovereignty, recently said lawmakers are "very committed to our rules when it comes to the digital world". </p><p>Earlier this month, companies including Google, Meta, Airbus, BNP Paribas, and TotalEnergies called for a two-year delay in implementation, claiming that as it stands, the AI Act will stifle innovation.</p><p>"Businesses and policymakers across Europe have spoken out against this regulation. Earlier this month, over 40 of Europe’s largest businesses signed a letter calling for the Commission to ‘Stop the Clock’ in its implementation," said Kaplan. </p><p>"We share concerns raised by these businesses that this over-reach will throttle the development and deployment of frontier AI models in Europe, and stunt European companies looking to build businesses on top of them."</p><p>OpenAI and Mistral have already signed the code - although the latter has voiced concerns about the impact of the legislation.</p><p>"Compliance with the Code and the AI Act’s risk based framework must be as simple and streamlined as possible for the homegrown start-ups and smaller businesses that will be the future leaders of Europe’s AI-first economy," said OpenAI in a <a href="https://openai.com/global-affairs/eu-code-of-practice/"><u>statement</u></a>. </p><p>"We have advocated⁠ for greater simplification and harmonization to support these next generation companies and will continue to back their concerns, as they are key to AI of, by and for Europe." </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/technology/artificial-intelligence/the-uk-government-is-working-with-meta-to-create-an-ai-engineering-dream-team-to-drive-public-sector-adoption">The UK government is working with Meta to create an AI engineering dream team</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/meta-open-source-ai-linux-foundation">Meta faces new ‘open washing’ accusations with AI whitepaper</a></li><li><a href="https://www.itpro.com/infrastructure/data-centres/meta-working-on-a-5gw-data-center-to-supercharge-ai-infrastructure-and-mark-zuckerberg-says-one-cluster-alone-covers-a-significant-part-of-the-footprint-of-manhattan">Meta is working on a 5GW data center to supercharge AI infrastructure</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Oracle’s European investment drive continues in Germany and the Netherlands – here’s why it’s a key market for the cloud giant ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-computing/oracles-european-investment-drive-continues-in-germany-and-the-netherlands-heres-why-its-a-key-market-for-the-cloud-giant</link>
                                                                            <description>
                            <![CDATA[ Oracle is once again ramping up investment across Europe, this time targeting multi-billion-dollar deals in the Netherlands and Germany. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8FwRvSrNUZMpreqeeqyfcm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kYgyeHbGeSuHN5htYWgHcU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Jul 2025 10:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Computing]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kYgyeHbGeSuHN5htYWgHcU-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Man pictured walking in the entrance to the Oracle office in Hong Kong. ]]></media:description>                                                            <media:text><![CDATA[Man pictured walking in the entrance to the Oracle office in Hong Kong. ]]></media:text>
                                <media:title type="plain"><![CDATA[Man pictured walking in the entrance to the Oracle office in Hong Kong. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kYgyeHbGeSuHN5htYWgHcU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Oracle has announced plans to invest $3 billion in Germany and the Netherlands as the <a href="https://www.itpro.com/627952/what-is-cloud-computing">cloud computing</a> giant continues its European infrastructure push. </p><p>Over the next five years, the firm will invest $2 billion to expand its Oracle Cloud Infrastructure (OCI) footprint in Germany, with a big increase in AI infrastructure capacity in the Oracle Cloud Frankfurt region in particular.</p><p>In a statement outlining the plans, Thorsten Herrmann, senior vice president and Germany country leader at Oracle, said the move is aimed at helping organizations across the country “accelerate their AI and cloud journeys”. </p><p>“In addition, we’re supporting the federal government’s objective of strengthening Germany as a hub for <a href="https://www.itpro.com/software/open-source/open-source-AI-return-on-investment">AI investment</a> and innovation in Europe,” Herrmann added.</p><p>The investment will also help Oracle meet demand for <a href="https://www.itpro.com/cloud/cloud-computing/what-is-a-sovereign-cloud">sovereign cloud</a> and AI services in the German public sector and other industries, including the manufacturing, automotive, renewable energy, scientific research, and healthcare sectors.</p><p>As part of the move, Oracle confirmed startups and investors across Germany will be given access to infrastructure for <a href="https://www.itpro.com/technology/artificial-intelligence/dollar100-billion-to-build-an-ai-model-anthropic-ceo-dario-amodei-predicts-soaring-ai-training-costs-but-models-will-become-far-more-powerful">AI training</a> and inference, as well as multi-cloud options. </p><p>"We are pleased about increasing investments, both from Germany and internationally, and expressly welcome this investment," said Karsten Wildberger, federal minister for <a href="https://www.itpro.com/strategy/29899/three-reasons-why-digital-transformation-is-essential-for-business-growth">digital transformation</a> and government modernization.</p><p>"It strengthens our <a href="https://www.itpro.com/cloud/infrastructure-as-a-service-iaas/361845/practices-for-maximising-the-business-value-of">digital infrastructure</a> and enables companies and public authorities to benefit from state-of-the-art <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>and cloud technologies."</p><p>Meanwhile, in the Netherlands, Oracle is planning to invest $1 billion over the same timespan to meet growing demand for AI and cloud services. This will see the company significantly expand <a href="https://www.itpro.com/infrastructure/ai-infrastructure-global-divide">AI infrastructure</a> capacity in the Oracle Cloud Amsterdam region.</p><p>The plan is to target organizations in key local industries such as financial services, logistics, life sciences, and energy.</p><h2 id="oracle-is-all-in-on-european-expansion">Oracle is all in on European expansion</h2><p>These latest investment announcements come amid a <a href="https://www.itpro.com/policy-legislation/data-governance/368517/oracle-to-build-sovereign-cloud-regions-in-the-eu-for-2023">big push across the region</a>, which the hyperscaler views as a market ripe with opportunities. </p><p>Earlier this year, Oracle unveiled plans to <a href="https://www.itpro.com/infrastructure/uk-cloud-infrastructure-set-for-boost-amid-usd5-billion-oracle-investment"><u>invest $5 billion in the UK</u></a>, significantly expanding its OCI footprint across the country. </p><p>A <a href="https://www.itpro.com/cloud/cloud-computing/oracle-expands-spanish-cloud-offerings-with-dollar1-billion-investment"><u>similar $1 billion investment in Spain</u></a> last year was also announced, with a keen focus on supporting the country’s financial services sector. </p><p>Larry Ellison, CTO and chairman of Oracle, has been highly vocal about Oracle's plans across Europe in recent years, identifying it as a key market for the company amidst the growing demand for sovereign cloud services. </p><p>Speaking last year, Ellison said he <a href="https://www.itpro.com/cloud/cloud-computing/oracle-is-betting-big-that-every-country-will-soon-have-its-own-sovereign-cloud"><u>expects every country to have its own sovereign cloud</u></a> setup, noting at the time that the company was in negotiations with a number of national governments. </p><p>Enterprise appetite for sovereign cloud options has surged across Europe, largely in response to stringent regulatory requirements on data protection. </p><p>Speaking to <em>ITPro </em>last year, senior Forrester analyst said sovereign cloud options are <a href="https://www.itpro.com/cloud/cloud-computing/sovereign-cloud-services-are-now-the-bare-minimum-expected-by-customers-and-hyperscalers-are-scrambling-to-meet-demand"><u>now the “bare minimum” expected from customers</u></a> in the region - and providers have pivoted hard to expand options on this front.  </p><p>Alongside Oracle, a host of industry competitors including Google, Microsoft, and AWS have been rushing to launch their own sovereign cloud services.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/cloud/cloud-computing/openai-oracle-cloud-deal-stargate">Turns out OpenAI is the customer behind Oracle's mysterious $30 billion cloud deal</a></li><li><a href="https://www.itpro.com/business/business-strategy/oracle-is-entering-the-multi-cloud-era-and-partnership-is-its-rallying-cry">Partnerships are Oracle's key to success in the "multi-cloud era"</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/ai-agent-announcements-are-a-dime-a-dozen-right-now-heres-what-oracle-thinks-its-doing-differently">AI agent announcements are a dime a dozen right now – here’s what Oracle thinks it’s doing differently</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Confusing for developers and bad for users’: Apple launches appeal over ‘unprecedented’ EU fine ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/confusing-for-developers-and-bad-for-users-apple-launches-appeal-over-unprecedented-eu-fine</link>
                                                                            <description>
                            <![CDATA[ Apple is pushing back against new app store rules imposed by the European Commission, suggesting a €500m fine is a step too far. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SgBNKK3ovJuVCqEr9dFTBn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xFFY74w8NVNvf4jaQpUham-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Jul 2025 10:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xFFY74w8NVNvf4jaQpUham-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A pedestrian passes by an Apple smart products flagship store on Nanjing Road in Shanghai, China on June 29, 2025.]]></media:description>                                                            <media:text><![CDATA[A pedestrian passes by an Apple smart products flagship store on Nanjing Road in Shanghai, China on June 29, 2025.]]></media:text>
                                <media:title type="plain"><![CDATA[A pedestrian passes by an Apple smart products flagship store on Nanjing Road in Shanghai, China on June 29, 2025.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xFFY74w8NVNvf4jaQpUham-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/uk/software/apple">Apple </a>is pushing back against new app store rules imposed by the European Commission (EC), claiming the EU body has taken changes and a €500 million (£430m) fine too far. </p><p>The EC levied the fine in April, arguing Apple was in breach of anti-steering obligations in the <a href="https://www.itpro.com/business/policy-legislation/368435/what-is-the-eus-digital-markets-act-dma">EU Digital Markets Act (DMA)</a>. That refers to Apple's long-running ban on <a href="https://www.itpro.com/security/forcing-apple-to-allow-alternative-app-stores-might-cause-major-security-risks">alternative app stores</a> and rules that stop developers from telling users about discounts or other offers outside of the Apple platform. </p><p>Apple previously took a cut of up to 30% on sales inside apps and has been locked in a war of words over the practice with <a href="https://www.itpro.com/software/development/burnout-is-now-rife-across-the-software-community-with-almost-half-of-developers-turning-to-self-help-apps">developers</a>. </p><p>The tech giant complied with the app store rule changes last month in order to avoid additional fines that could reach 5% of its average revenue globally. </p><p>That included a wider range of commission rates up to 13%, alongside user acquisition fees, with the costs dependent on what marketing support the developer wants in the App Store as well as technical aspects such as automatic updates. </p><p>Developers will also be able to promote alternative ways of purchasing services outside the app, though Apple would charge a commission on sales advertised via apps in its App Store. </p><h2 id="apple-is-baffled-the-ec-is-standing-firm">Apple is baffled, the EC is standing firm</h2><p>Key to Apple’s argument, and appeal, is that the company claims this new system is "confusing" to business users. </p><p>"Today we filed our appeal because we believe the European Commission’s decision – and their unprecedented fine – go far beyond what the law requires," said Apple in a statement. </p><p>"As our appeal will show, the EC is mandating how we run our store and forcing business terms which are confusing for developers and bad for users."</p><p>Apple has yet to reply to a request for comment from <em>ITPro</em>. </p><p>The Commission, meanwhile, is standing by its decision. In a statement responding to the appeal, it <a href="https://www.theguardian.com/technology/2025/jul/07/apple-appeals-eu-fine-app-store#:~:text=%E2%80%9CToday%20we%20filed%20our%20appeal,highest%20court%20in%20the%20EU." target="_blank"><u>said</u></a>: "We stand ready to defend our decisions in court.” </p><p>The EC previously <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_24_3433" target="_blank"><u>said</u></a> that Apple shouldn't charge developers for the right to "steer" customers, suggesting that a commission on sales promoted in-app wouldn't meet requirements.</p><h2 id="political-battle">Political battle</h2><p>A legal expert told <a href="https://www.theguardian.com/technology/2025/jul/07/apple-appeals-eu-fine-app-store#:~:text=%E2%80%9CToday%20we%20filed%20our%20appeal,highest%20court%20in%20the%20EU." target="_blank"><u><em>The Guardian</em></u></a><em> </em>that Apple may be employing delay tactics. </p><p>"The blunt truth is that it is worth spending a few million on legal fees in order to disrupt and delay the development of a more open app ecosystem, which is a market that is worth many billions a year to Apple," Tom Smith, a competition lawyer at Geradin Partners, told the publication. </p><p>The app store quarrel isn't the only ongoing battle between the EU and tech companies. In April, Meta was hit with a €200m fine for charging users to get rid of ads, while last year Apple was fined €1.8bn over music streaming competition.</p><p>The appeal comes ahead of US President Donald Trump's 9 July deadline to settle a trade deal with the EU or risk 50% tariffs. The Trump administration has repeatedly said the EU is targeting US tech companies in retaliation for trade disruption and other political concerns, with Trump trade advisor Peter Navarro <a href="https://www.euronews.com/my-europe/2025/04/08/big-tech-probes-non-negotiable-in-us-trade-talks-brussels-warns" target="_blank"><u>calling</u></a> it "lawfare". </p><p>EU action against tech giants stretches back well before even the first Trump administration, with a €497 million fine against Microsoft in 2004 over Windows Media Player bundling that was later increased to €899 million for non-compliance. </p><p>That was followed by cases against Intel in 2009, an investigation against Google on search that began in 2010, and investigations into taxes that pulled in Apple and Amazon beginning in 2014. </p><p>That said, things have accelerated since 2017 with a €2.42bn fine against Google over price comparison shopping services. In subsequent years, EU lawmakers imposed a €4.34bn for Android and €1.49bn over AdSense, with other cases targeting Apple, Amazon and Meta in recent years. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/technology/artificial-intelligence/apple-ai-reasoning-research-paper-openai-google-anthropic">Apple throws cold water on the potential of AI reasoning</a></li><li><a href="https://www.itpro.com/security/apple-is-offering-rewards-of-up-to-usd1-million-to-find-critical-flaws-in-its-private-ai-cloud-systems">Apple is offering rewards of up to $1 million to find critical flaws in its private AI cloud systems</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/apple-our-ai-data-was-gathered-responsibly">Apple: Our AI data was gathered responsibly</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ European Commission calls for cyber security proposals ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/european-commission-calls-for-cyber-security-proposals</link>
                                                                            <description>
                            <![CDATA[ With a special focus on healthcare, the Commission is looking to allocate €145.5 million ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5igpwudYV98wpS78KUzG3h</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qnGSwbfzp9zTsFt2t49oUT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 16 Jun 2025 12:01:58 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qnGSwbfzp9zTsFt2t49oUT-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[EU flags fly outside the union headquarters in Brussels, Belgium.]]></media:description>                                                            <media:text><![CDATA[EU flags fly outside the union headquarters in Brussels, Belgium.]]></media:text>
                                <media:title type="plain"><![CDATA[EU flags fly outside the union headquarters in Brussels, Belgium.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qnGSwbfzp9zTsFt2t49oUT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The European Commission is making €145.5 million available to help small and medium-sized enterprises and public bodies to boost their <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a>, with specific help for hospitals and healthcare providers.</p><p>It's launched two calls for proposals. The first is part of the Digital Europe Programme, with a budget of €55 million, €30 million of which will go to enhance the cybersecurity of hospitals and healthcare providers.</p><p>€15 million will go to post-quantum Public Key Infrastructures, meanwhile, with €10 million allocated to enhance the Network Connectivity Center (NCC) Networks.</p><p>The plan is to help organizations detect, monitor, and respond to cyber threats, particularly <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a>. The aim is to have identified the key ransomware strains targeting healthcare by the end of this year, and to set up a ransomware recovery subscription service by 2026.</p><p>"This will boost the resilience of the European healthcare system, especially in the current geopolitical context, aligning with the EU action plan on cybersecurity in hospitals and healthcare," said the Commission.</p><p>The fund will be used for pilot projects including national or regional hospital clusters, healthcare systems, professional associations, and cybersecurity service providers.</p><p>These could include, for example, the creation of security operation centers offering real-time monitoring, threat detection, and rapid incident response, as well as the use of cybersecurity tools including Security Information and Event Management (SIEM) platforms, threat intelligence, and automated response capabilities.</p><p>The second call, forming part of the Horizon Europe Programme, has a budget of around €90.5 million. It will, said the Commission, support the use and development of <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai">generative AI</a> for cybersecurity applications and new advanced tools and processes for operational cybersecurity, along with privacy-enhancing technologies and post-quantum cryptography.</p><p>Of this, €40 million will go to generative AI for cybersecurity applications, €23.55 million on new tools and processes for operational cybersecurity, and €11 on privacy enhancing technologies.</p><p>Security evaluations of Post-Quantum Cryptography (PQC) primitives will get €4 million, with €6 million for the security of implementations of PQC algorithms and another €6 million for the integration of PQC) algorithms into high-level protocols.</p><p>Proposals for the first call can be submitted until 7 October <a href="https://ec.europa.eu/info/funding-tenders/opportunities/portal/screen/opportunities/calls-for-proposals?order=DESC&pageNumber=1&pageSize=50&sortBy=startDate&isExactMatch=true&status=31094501,31094502,31094503&programmePeriod=2021%20-%202027&frameworkProgramme=43152860&callIdentifier=DIGITAL-ECCC-2025-DEPLOY-CYBER-08">here</a>, with the second <a href="https://ec.europa.eu/info/funding-tenders/opportunities/portal/screen/opportunities/calls-for-proposals?order=DESC&pageNumber=1&pageSize=50&sortBy=startDate&isExactMatch=true&status=31094501,31094502,31094503&programmePeriod=2021%20-%202027&frameworkProgramme=43108390&callIdentifier=HORIZON-CL3-2025-02-CS-ECCC">here</a>, open until 12 November.</p><p>According to the Commission, in 2023 alone, EU countries reported 309 significant cybersecurity incidents targeting the healthcare sector -- more than any other critical sector. And the call for healthcare cybersecurity proposals follows an EU action plan launched earlier this year.</p><p>"Digital technologies and health data-driven solutions have opened unparalleled opportunities in healthcare. They enable precision medicine, real-time patient monitoring, and seamless communication between healthcare providers across borders," said Olivér Várhelyi, commissioner for health and animal Welfare. </p><p>"But digitalization is only as strong as the trust it inspires and resilient from cyberattacks. Patients must feel confident that their most sensitive information is secure. Healthcare professionals must have faith in the systems they use daily to save lives."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple, Meta hit back at EU after landmark DMA fines ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/apple-meta-hit-back-at-eu-after-landmark-fines-under-digital-markets-act</link>
                                                                            <description>
                            <![CDATA[ The European Commission has issued its first penalties under the EU Digital Markets Act (DMA), fining Apple €500 million and Meta €200m. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oxT6CeYyAfhF3kKMfaGQZM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qnGSwbfzp9zTsFt2t49oUT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 24 Apr 2025 09:57:45 +0000</pubDate>                                                                                                                                <updated>Thu, 24 Apr 2025 10:02:27 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qnGSwbfzp9zTsFt2t49oUT-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[EU flags fly outside the union headquarters in Brussels, Belgium.]]></media:description>                                                            <media:text><![CDATA[EU flags fly outside the union headquarters in Brussels, Belgium.]]></media:text>
                                <media:title type="plain"><![CDATA[EU flags fly outside the union headquarters in Brussels, Belgium.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qnGSwbfzp9zTsFt2t49oUT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The European Commission has issued its first penalties under the <a href="https://www.itpro.com/business/policy-legislation/368435/what-is-the-eus-digital-markets-act-dma"><u>EU Digital Markets Act</u></a> (DMA), fining Apple €500 million and Meta €200m and requiring both to make changes to how they operate. </p><p>The DMA came into effect in 2023 and was created to regulate competition in the digital economy, in part by reining in abuse of power by larger platforms.  </p><p>Apple was found to be in breach of "anti-steering obligations" over restrictions that ban apps from informing customers of offers outside the App Store, which the EC said limited customer choice. </p><p>The Commission has ordered Apple to remove that restriction, and the tech giant plans to appeal the fine. </p><p>Meta, meanwhile, was fined for its introduction of a <a href="https://www.itpro.com/security/privacy/why-metas-pay-or-consent-ad-model-has-landed-it-in-hot-water-with-eu-regulators"><u>model that would force users to pay</u></a> for an ad-free service or consent to their data being used for advertising. </p><p>The Commission said that fell foul of an obligation under the DMA to give consumers the choice of a service that uses less of their personal data.</p><h2 id="apple-and-meta-respond">Apple and Meta respond </h2><p>Both companies made it clear they disagreed with the fines. In a <a href="https://x.com/jackeparrock/status/1914980345310556652"><u>statement</u></a>, Apple hit out at the Commission, suggesting the penalties show it is “unfairly targeting” the company. </p><p>The tech giant said the decisions are “bad for the privacy and security of our users, bad for products, and force us to give away our technology for free”.</p><p>"We have spent hundreds of thousands of engineering hours and made dozens of changes to comply with this law, none of which our users have asked for,” the statement added. </p><p>“Despite countless meetings, the Commission continues to move the goal posts every step of the way. We will appeal and continue engaging with the Commission in service of our European customers.”</p><p>Meta offered harsher criticism in its response, accusing the EC of treating US businesses unfairly. </p><p>"The European Commission is attempting to handicap successful American businesses while allowing Chinese and European companies to operate under different standards," Meta's Chief Global Affairs Officer, Joel Kaplan, said in a <a href="https://about.fb.com/news/2025/04/metas-statement-in-response-to-the-european-commissions-decision-on-the-digital-markets-act/" target="_blank"><u>statement</u></a>. </p><p>"This isn’t just about a fine; the Commission forcing us to change our business model effectively imposes a multi-billion-dollar tariff on Meta while requiring us to offer an inferior service," he added. "And by unfairly restricting personalized advertising the European Commission is also hurting European businesses and economies."</p><h2 id="a-strong-and-clear-message-from-the-eu">A ‘strong and clear’ message from the EU</h2><p>Despite the complaints, Teresa Ribera, Executive Vice-President for a Clean, Just and Competitive Transition, said in a <a href="https://ec.europa.eu/commission/presscorner/detail/en/mex_25_1088" target="_blank"><u>statement</u></a> the fines send a "strong and clear message" to digital companies, adding that the legislation is a crucial tool to ensuring fair markets. </p><p>"Apple and Meta have fallen short of compliance with the DMA by implementing measures that reinforce the dependence of business users and consumers on their platforms," Ribera said. "As a result, we have taken firm but balanced enforcement action against both companies, based on clear and predictable rules."</p><p>"All companies operating in the EU must follow our laws and respect European values,” she added.</p><p>That reference to <a href="https://www.itpro.com/business/policy-and-legislation/the-eus-long-arm-regulatory-approach-could-create-frosty-us-environment-for-european-tech-firms"><u>European values reflects geopolitical turmoil</u></a> between the US and the rest of the world, according to Joe Jones, director of research and insights at IAPP. </p><p>"The fines land at a time of heightened scrutiny by the current US Administration on the application of EU laws to US companies," Jones said. </p><p>"The EU Digital Markets Act was even name-checked in an Executive Order issued by President Trump last February as facing scrutiny as part of the Administration’s work to “defend American companies and innovators from overseas extortion,” he added.</p><p>"Open questions include not only how will addressed companies respond to EU regulatory enforcement but how will overseas governments, including and especially the US, respond.  The U.S. Administration has declared it will consider responsive actions like tariffs to combat certain foreign government policies levied against US companies."</p><h2 id="beyond-the-fines">Beyond the fines</h2><p>As Meta noted, there's more to the decision than fines. Indeed, despite the seemingly large figures, the fines were much smaller than the EU could have levied, as high as <a href="https://www.itpro.com/business/policy-and-legislation/big-tech-firms-face-10-turnover-fines-under-new-competition-law"><u>10% of their global annual turnover</u></a>. Last year, Meta's earnings topped $165 billion and Apple's was $391 billion.  </p><p>In a statement, the EC said that developers using Apple's App Store should be able to tell customers about alternative offers outside that store, such as discounted subscription offers. The EC added that Apple had failed to give a reason why such restrictions are "necessary and proportionate." </p><p>Beyond the fine, the EC has ordered Apple to remove such restrictions and not introduce similar restrictions in the future. </p><p>The EC also <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_25_1086"><u>closed an investigation</u></a> into Apple's tactic of not allowing its own pre-installed apps to be removed from its devices, such as its Safari web browser. </p><p>Following a "constructive dialogue", Apple made it easier to select a new default browser on iPhones, uninstall several Apple pre-installed apps, and change default settings for other tools such as keyboards and translation.</p><p>Alongside those two investigations, the EC also issued preliminary findings on Apple banning third-party app stores and requiring users to download apps via the official App Store. </p><p>The EC said that its preliminary view is that Apple isn't complying with the DMA by disincentivising developers from offering apps elsewhere via a new fee, the Core Technology fee, while also introducing strict eligibility requirements. </p><p>Apple can now respond to those findings ahead of a final ruling. </p><p>For Meta, it has been fined under DMA rules that mean "gatekeepers" must get user consent for combining personal data between services, and still offer an equivalent alternative service for any who refuse to consent. </p><p>This decision refers to Meta's "consent or pay" advertising model that was introduced in November 2023, which gave Facebook and Instagram users the option of consenting to their data being combined for personalized advertising or paying a subscription to opt out and receive an ad-free service. </p><p>The EC said that model didn't offer enough of an alternative service for those who opted out. A year later, Meta offered a new version that included a tier that used less personal data to display ads. </p><p>This particular fine applies only to the period up to November 2024 when those changes came into effect, as the regulator is still considering the changes. </p><p>Alongside the advertising data ruling, the EC also announced that Facebook Marketplace was small enough that it should no longer be designated under the DMA.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/business/policy-and-legislation/how-the-eu-ai-act-compares-to-other-international-regulatory-approaches">How the EU AI Act compares to other international regulatory approaches</a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/dora-and-why-resilience-once-again-matters-to-the-board">DORA and why resilience (once again) matters to the board</a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/the-fractured-regulatory-landscape-tech-companies-face-in-2025">The fractured regulatory landscape tech companies face in 2025</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Europe could do it, but it's chosen not to do it’: Eric Schmidt thinks EU regulation will stifle AI innovation – but Britain has a huge opportunity ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/eric-schmidt-eu-ai-regulation-uk</link>
                                                                            <description>
                            <![CDATA[ Former Google CEO Eric Schmidt believes EU AI regulation is hampering innovation in the region and placing enterprises at a disadvantage. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iLgsqgqzd7DfFoV9m2CxLS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iCDsnwPWSth6HFoamxBPUh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Feb 2025 10:06:44 +0000</pubDate>                                                                                                                                <updated>Wed, 19 Feb 2025 12:16:47 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iCDsnwPWSth6HFoamxBPUh-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Former Google CEO Eric Schmidt pictured at the AI Action Summit in Paris, France, on Monday, Feb. 10, 2025.]]></media:description>                                                            <media:text><![CDATA[Former Google CEO Eric Schmidt pictured at the AI Action Summit in Paris, France, on Monday, Feb. 10, 2025.]]></media:text>
                                <media:title type="plain"><![CDATA[Former Google CEO Eric Schmidt pictured at the AI Action Summit in Paris, France, on Monday, Feb. 10, 2025.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iCDsnwPWSth6HFoamxBPUh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/business/business-strategy/eric-schmidt-s-car-crash-stanford-interview-showed-big-tech-s-true-colors-on-remote-work">Former Google CEO Eric Schmidt</a> has hit out at <a href="https://www.itpro.com/business/policy-and-legislation/how-the-eu-ai-act-compares-to-other-international-regulatory-approaches">EU AI regulation</a>, suggesting overburdening rules put European companies at an inherent disadvantage compared to global counterparts. </p><p>Speaking on the <a href="https://www.bbc.co.uk/sounds/play/m0027tw9">BBC Radio 4<em>Today </em>program</a>, Schmidt said a combination of factors are hampering AI innovation in the region, including restrictive regulation and the natural “structure” of European markets. </p><p>Reflecting on his time at Google, Schmidt said he worked for “at least 10 years to try to get Europe up to the bar”, noting that lucrative talent pools on both the continent and in the UK give enterprises a prime opportunity to compete. </p><p>Regulatory barriers, however, are preventing the region from making any headway in the global AI race. </p><p>“The system doesn't work, right? They can't build big enough companies. The markets are not integrated. Partly it's just the structure of Europe, but it’s also that Brussels, in addition to promising uniform markets, also regulates in a particularly strong way,” he said. </p><p>“The result of this is that the AI revolution, which is the most important revolution in my opinion since electricity, is not going to be invented in Europe, and that's to Europe's disservice,” Schmidt added. </p><p>“Europe could do it, but it's chosen not to do it, and I'm really quite brutal on this.”</p><h2 id="fair-game-in-the-us-ai-market">Fair game in the US AI market</h2><p>The situation is quite different across the Atlantic, Schmidt noted. The US’ approach to <a href="https://www.itpro.com/technology/machine-learning/local-machine-learning-promises-to-cut-the-cost-of-ai-development-in-2024">AI development</a> stands in stark contrast to the European market, with lawmakers and enterprises alike engaged in a rabid race to the top. </p><p>With the Trump administration now in place in Washington DC, Schmidt pointed to a sense of burgeoning optimism among leading enterprises in the AI space, many of whom have invested billions of dollars thus far and intend to ramp up spending in the year ahead. </p><p>So far this year, Meta, AWS, Microsoft, and Google have all outlined plans to accelerate capital expenditure – and a key factor in this will be expanding AI infrastructure. Meta, for example, expected to spend upwards of $60 billion this year, marking a significant increase from $39 billion in 2024.</p><p>“When I looked at the swearing in with my friends behind the president I thought, ‘wow, we have arrived’ - and that doesn’t necessarily mean that we are going to be unregulated,” he said. </p><p>“It means the inverse in my view,” he added. “Everyone, starting with you, are watching what we're doing, which I view as a good thing.”</p><iframe allow="" height="200px" width="100%" data-lazy-priority="high" data-lazy-src="https://player.captivate.fm/episode/e72e3adf-5bdc-4be4-bfe8-51510b6b9843/"></iframe><p>This doesn’t mean that the US will pursue a ‘Wild West’ approach to AI development, however. Instead, providing enterprises the regulatory flexibility to develop AI models and adopting a gentler approach is the ideal situation.</p><p>“The truth is that AI and the future is largely going to be built by private companies,” Schmidt said.</p><p>“It has to do with the incentives and the money, where the talent is, and how the world works, they're not going to be built in the equivalent of a Manhattan Project.”</p><p>Schmidt noted that it’s “really important that governments understand what we’re doing and keep their eye on us”. </p><p>“We’re not arguing that we should unilaterally be able to do things without oversight,” he added. </p><p>Schmidt has been highly vocal on the potential dangers posed by unchecked <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a> development in recent months, warning that systems could be used by bad actors for nefarious purposes ranging from biological warfare to <a href="https://www.itpro.com/security/cyber-crime/agentic-ai-cybersecurity-risks">cyber crime</a>. </p><h2 id="britain-has-an-opportunity-to-differentiate-itself">Britain has an opportunity to differentiate itself</h2><p>While discussions over the potential barriers to AI innovation in Europe continue, Schmidt did point to the UK’s opportunity, suggesting it can differentiate itself from European counterparts. </p><p>The <a href="https://www.itpro.com/technology/artificial-intelligence/uk-and-us-reject-paris-ai-summit-agreement-as-atlantic-rift-on-regulation-grows">UK joined the US in refusing to sign an international agreement</a> on sustainable AI development at this week’s global summit in Paris, prompting suggestions an ‘Atlantic rift’ is opening up on the topic of AI. </p><p>This decision was based on concerns that the declaration lacked 'practical clarity', officials said, particularly on the issue of global governance and national security.</p><p>The <a href="https://www.itpro.com/business/policy-and-legislation/is-the-uk-falling-behind-the-eu-on-ai-regulation">UK’s approach to AI has deviated from that in Europe</a>, and the current government has made clear it hopes to position itself as a global leader on this front by attracting international investment and building out infrastructure. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nMPk3hYgRaNUm4dqd8ZtSQ" name="Discover how these data centers from Germany and Australia became more resilient to disruption, while also lowering operating costs and CO2 emission" caption="" alt="Discover how these data centers from Germany and Australia became more resilient to disruption, while also lowering operating costs and CO2 emission." src="https://cdn.mos.cms.futurecdn.net/nMPk3hYgRaNUm4dqd8ZtSQ.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ABB)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/data-centres/discover-how-these-data-centers-from-germany-and-australia-became-more-resilient-to-disruption-while-also-lowering-operating-costs-and-co2-emission"><em>Data centers fortified with robust maintenance</em></a></p></div></div><p>Notably, Schmidt said the UK has success stories to champion that will stand it in good stead. </p><p>“So some credit to Britain,” he said. “Much of the path to general intelligence was pioneered in King’s Cross in a building occupied by a subsidiary of Google called DeepMind by - now a Nobel Prize winner - <a href="https://www.itpro.com/software/google/demis-hassabis-the-man-behind-google-deepmind-commits-to-ethical-ai"><u>Demis Hassabis</u></a>.”</p><p>“What they have done is so extraordinary it should be a point of national pride,” Schmidt added. “It may be the most important thing that Britain has done in the last five years, in my opinion.”</p><p>Schmidt further hailed the government’s apparent pursuit US-style regulation, which involves consultation and close collaborative ties with industry. </p><p>“It looks to me like the pairing of the US and the UK is a winning strategy,” he said. “And it looks to me like the Europeans, because of Brussels, are being held behind.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/infrastructure/salesforce-thinks-the-uk-is-ready-to-lead-the-next-wave-of-ai">Salesforce thinks the UK is ready to lead the next wave of AI</a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/the-uk-needs-to-be-more-hands-on-with-ai-legislation-simply-standing-on-the-world-stage-isnt-enough">Why the UK needs to look inward on AI legislation</a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/google-says-uk-needs-policy-step-change-to-embrace-its-ai-potential">Google says UK needs policy step change to embrace its AI potential</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The EU just shelved its AI liability directive ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/the-eu-just-shelved-its-ai-liability-directive</link>
                                                                            <description>
                            <![CDATA[ The European Commission has scrapped plans to introduce the AI Liability Directive aimed at protecting consumers from harmful AI systems. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">JgdzVsZCoMw2qCdUhsXvC5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qnGSwbfzp9zTsFt2t49oUT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Feb 2025 12:08:59 +0000</pubDate>                                                                                                                                <updated>Wed, 19 Feb 2025 12:15:34 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qnGSwbfzp9zTsFt2t49oUT-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[EU flags fly outside the union headquarters in Brussels, Belgium.]]></media:description>                                                            <media:text><![CDATA[EU flags fly outside the union headquarters in Brussels, Belgium.]]></media:text>
                                <media:title type="plain"><![CDATA[EU flags fly outside the union headquarters in Brussels, Belgium.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qnGSwbfzp9zTsFt2t49oUT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The European Commission has shelved plans to impose civil liability rules on enterprises using harmful <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>systems in a move critics have described as a “strategic mistake”. </p><p>First proposed in 2022, the AI Liability Directive aimed to overhaul existing rules on harmful AI systems and protect consumers. </p><p>However, the <a href="https://commission.europa.eu/strategy-and-policy/strategy-documents/commission-work-programme/commission-work-programme-2025_en" target="_blank"><u>publication of the Commission’s final work program</u></a> shows plans to introduce the rules will now be scrapped, noting that “no foreseeable agreement” has been reached by lawmakers. </p><p>The documents add that the Commission will “assess whether another proposal should be tabled or another type of approach should be chosen”.</p><p>The move comes in the wake of the <a href="https://www.itpro.com/technology/artificial-intelligence/uk-and-us-reject-paris-ai-summit-agreement-as-atlantic-rift-on-regulation-grows">AI Action Summit</a>, held in Paris, which saw industry stakeholders come together to discuss the future of <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a> innovation both across the European Union (EU) and globally. </p><p>During the summit, US vice president JD Vance voiced concerns over the EU’s supposed heavy handed regulatory approach to the technology. <a href="https://www.politico.eu/article/vp-jd-vance-calls-europe-row-back-tech-regulation-ai-action-summit/" target="_blank"><u>Vance urged European enterprises</u></a> and lawmakers to view the “new frontier of AI with optimism and not trepidation”. </p><p>“We want to embark on the AI revolution before us with the spirit of openness and collaboration, but to create that kind of trust we need international regulatory regimes that foster creation," he told attendees.</p><p>The liability directive was originally tabled alongside the <a href="https://www.itpro.com/technology/artificial-intelligence/eu-ai-act-everything-you-need-to-know-about-the-legislation-including-rules-requirements-and-who-will-be-forced-to-comply">EU AI Act</a>, but has since taken a backseat amid the push to impose the landmark legislation. </p><p>Some EU lawmakers have voiced their disapproval,. According to reports from <a href="https://www.euronews.com/next/2025/02/12/dont-drop-ai-liability-mechanism-lead-lawmaker-warns-commission" target="_blank"><u><em>Euronews</em></u></a>, Axel Voss, the EU Parliament’s lead representative for developing liability rules, described the move as a “strategic mistake”.</p><p>Voss told the publication the decision will lead to “legal uncertainty, corporate power imbalances, and a Wild West approach to <a href="https://www.itpro.com/security/data-breaches/threat-of-personal-liability-has-cisos-sweating">AI liability</a> that only benefits big tech”. </p><p>"The reality now is that AI liability will be dictated by a fragmented patchwork of 27 different national legal systems, suffocating European AI startups and SMEs,” he added.</p><iframe allow="" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/e72e3adf-5bdc-4be4-bfe8-51510b6b9843/"></iframe><h2 id="liability-directive-move-could-clean-up-patchwork-ai-regulation">Liability directive move could “clean up” patchwork AI regulation</h2><p>Peter van der Putten, director of <a href="https://www.itpro.com/technology/artificial-intelligence/pegasystems-ceo-alan-trefler-wants-to-help-enterprises-sift-through-the-ai-hype">Pegasystems</a>’ AI Lab and assistant professor at Leiden University, said that while the move may raise consumer protection concerns, the “impact may be relative” given new regulations such as the EU AI Act. </p><p>“The idea was that if a customer, citizen or business was claiming to have suffered harm, they wouldn’t have to prove in-depth causality between the AI system and the damage caused,” he explained. </p><p>“This would be more on the public or private organization operating the AI system (and/or underlying vendors).”</p><p>Ultimately, consumers and entities will still be protected against AI-related harms through the legislation, he noted, and the decision to shelve the proposals will create a more aligned regulatory environment. </p><p>“So whilst it is tempting to frame this all as a move towards less consumer protection in the global AI rat race, it can also just be seen as a sensible move to clean up the patchwork of AI regulation a bit, and not incite all kinds of litigation that in the end could either be resolved by existing regulation, or would likely not have been successful for claimants anyway,” van der Putten said. </p><h2 id="betting-on-a-blended-approach">Betting on a blended approach</h2><p>The decision to withdraw from the AI Liability Directive is being read by critics as the EU retreating on consumer protection in the face of AI companies.</p><p>While the EU AI Act contains protections for citizens and measures to monitor and control the harms of AI model deployment, it does not provide a direct route for consumers making claims against AI developers for damages such as algorithmic bias. </p><p>The AI Liability Directive was specifically designed to set out such a route, establishing concrete law on civil liability relating to AI and assisting consumers in making claims. </p><p>Timing is everything when it comes to the optics of a decision like this. In dropping the AI Liability Directive just one day after JD Vance’s warning that “excessive regulation” could kill AI innovation, the Commission could invite unwanted suggestions that it’s moving in lock-step with US approaches on AI.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="sN9hzieUPYt9YngAjVNAJK" name="Whitepaper_ DevSecOps is dead...or is it__" caption="" alt="Whitepaper: DevSecOps is dead...or is it?:" src="https://cdn.mos.cms.futurecdn.net/sN9hzieUPYt9YngAjVNAJK.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Snyk)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/devsecops-is-dead-or-is-it"><em>Integrate security into the development processes</em></a></p></div></div><p>But there’s every indication that rather than a reactive decision, this is more of a pragmatic move by the EU to maintain a handle on the AI sector. If it doesn’t keep its seat at the table by supporting EU-based AI developers and attracting investments from US tech giants, the EU Commission could lose any leverage it has over AI safety altogether.</p><p>The EU isn’t naïve and Vance’s statements on AI regulation wouldn’t have come as a surprise to anyone at the Paris Summit. As EU member states like France move to make the most of their established AI talent and the Commission gets more ambitious with its backing for AI infrastructure via its <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_25_467"><u>InvestAI initiative</u></a>, there will be more pragmatic decisions to come.</p><p>Attracting US investment, alongside home-grown talent, will be a necessity for the time being.</p><p>For the EU Commission’s part, it has stated that it saw “no foreseeable agreement” on the terms of the directive, adding “the Commission will assess whether another proposal should be tabled or another type of approach should be chosen”. </p><p>As yet, an alternative approach has not been officially put forward.</p><p>Ultimately, the EU may have made the bet that any reduced consumer power in the short term can be balanced out by regional success at AI advancement. If it can carve out a space for innovative AI that doesn’t infringe on inviolable rights, it could beat the US at its own game. </p><p>But it still has significant ground to make up, especially in comparison to the US and China.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/technology/artificial-intelligence/a-big-enforcement-deadline-for-the-eu-ai-act-is-just-around-the-corner#:~:text=The%20EU%20AI%20Act%20employs,human%20rights%2C%20or%20financial%20livelihood.">A big enforcement deadline for the EU AI Act just passed</a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/regulatory-uncertainty-is-holding-back-ai-adoption-heres-what-the-industry-needs-going-forward">Why regulatory uncertainty is holding back AI adoption</a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/why-ai-could-be-a-legal-nightmare-for-years-to-come">AI is going to be a legal nightmare for years to come</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK and US reject Paris AI summit agreement as “Atlantic rift” on regulation grows ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence/uk-and-us-reject-paris-ai-summit-agreement-as-atlantic-rift-on-regulation-grows</link>
                                                                            <description>
                            <![CDATA[ The UK and US have refused to sign an international agreement on AI governance amid concerns over "practical clarity'. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dE4TWMLFdY4B6jvwtgLrwV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cGNvjja9wSLVA5d3EMAsuj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Feb 2025 11:25:02 +0000</pubDate>                                                                                                                                <updated>Wed, 12 Feb 2025 14:57:23 +0000</updated>
                                                                                                                                            <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/cGNvjja9wSLVA5d3EMAsuj-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[France&#039;s President Emmanuel Macron (front C) poses for a group picture with world leaders and attendees at the end of the plenary session of the AI Action Summit.]]></media:description>                                                            <media:text><![CDATA[France&#039;s President Emmanuel Macron (front C) poses for a group picture with world leaders and attendees at the end of the plenary session of the AI Action Summit.]]></media:text>
                                <media:title type="plain"><![CDATA[France&#039;s President Emmanuel Macron (front C) poses for a group picture with world leaders and attendees at the end of the plenary session of the AI Action Summit.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cGNvjja9wSLVA5d3EMAsuj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK and US have refused to sign an international agreement on inclusive and <a href="https://www.itpro.com/cloud/cloud-storage/sustainable-ai-is-key-to-pure-storage-and-pureaccelerate-2024-will-make-that-mission-clear">sustainable AI</a> at this week's global summit in Paris.</p><p>The UK said its decision was based on concerns that the declaration lacked 'practical clarity' on global governance and didn't address issues of national security.</p><p>Meanwhile, US vice president JD Vance told delegates to the summit that over-regulation of AI could hold the industry back.</p><p>"The Trump administration believes that AI will have countless revolutionary applications in economic innovation, job creation, national security, health care, free expression and beyond, and to restrict its development now will not only unfairly benefit incumbents in this space, it would mean paralyzing one of the most promising technologies we have seen in generations," he said. </p><p>Vance's speech was very much in line with the Trump policy of 'America First'. He beat the drum for the US AI industry, and issued a warning to nations aiming to restrict its power. </p><p>"The Trump administration is troubled by reports that some foreign governments are considering tightening screws on US tech companies with international footprints," he said. </p><p>"America cannot and will not accept that, and we think it's a terrible mistake."</p><p>Vance's stance has been widely criticized by rights groups.</p><p>Alexandra Reeve Givens, CEO of the Center for Democracy and Technology (CDT), said that for AI to benefit both nations and individuals, robust safeguards and accountability must be implemented.</p><p>"When AI is being used to determine who gets a job, who gets a loan, who gets access to government services, the stakes are too high to shrug off the risks."</p><p>Meanwhile, Dr Andrew Bolster, senior research and development manager for data science at <a href="https://www.itpro.com/business/leadership/black-duck-continues-leadership-expansion-with-double-hire">Black Duck</a>, warned that the lack of transatlantic agreement might leave organizations deploying AI with a tricky course to steer.</p><p>"This growing Atlantic AI rift is a wake-up call for any organization looking to deploy or operate global AI solutions," he said.</p><p>"The regulatory landscape is not as settled as it may seem, and while alignment to existing principles such as <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR</a>, the <a href="https://www.itpro.com/network-internet/34504/what-is-the-california-consumer-privacy-act-ccpa">California Consumer Privacy Act (CCPA)</a> - and its amendment, the California Privacy Rights Act (CPRA) - or Australia’s Privacy Act may stand you in good stead, that is no guarantee of continued operations."</p><h2 id="61-nations-still-signed-the-ai-agreement">61 nations still signed the AI agreement</h2><p>Despite the UK and US’ disapproval, the agreement was signed by 61 other countries, including Canada, Japan, India ,and China, as well as European nations. </p><p>They pledged to focus on ensuring that AI is 'open, inclusive, transparent, <a href="https://www.itpro.com/technology/30736/what-is-ethical-ai">ethical</a>, safe, secure and trustworthy'.</p><p>The agreement also stresses the importance of strengthening international coordination in AI governance and preventing market monopolization, along with working to keep AI sustainable.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="W7u5GYpepdmUjNdTFtjZ4W" name="Giving your people the tools to stay productive, wherever they spend their working day.jpg" caption="" alt="Giving your people the tools to stay productive, wherever they spend their working day" src="https://cdn.mos.cms.futurecdn.net/W7u5GYpepdmUjNdTFtjZ4W.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Virgin, O2, Samsung)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/giving-your-people-the-tools-to-stay-productive-wherever-they-spend-their-working-day"><em>Freedom to work where you want</em></a></p></div></div><p>During the summit, European Commission president Ursula von der Leyen announced a €200 billion plan to advance <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a> research and <a href="https://www.itpro.com/infrastructure">infrastructure </a>across the bloc.</p><p>InvestAI will finance four AI gigafactories across the EU focused on <a href="https://www.itpro.com/technology/artificial-intelligence/dollar100-billion-to-build-an-ai-model-anthropic-ceo-dario-amodei-predicts-soaring-ai-training-costs-but-models-will-become-far-more-powerful">training models</a> for complex applications such as medicine and science.</p><p>"This unique public-private partnership, akin to a CERN for AI, will enable all our scientists and companies – not just the biggest – to develop the most advanced very large models needed to make Europe an AI continent," she said.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/technology/artificial-intelligence/a-big-enforcement-deadline-for-the-eu-ai-act-is-just-around-the-corner">A big enforcement deadline for the EU AI Act just passed</a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/how-the-eu-ai-act-compares-to-other-international-regulatory-approaches">How the EU AI Act compares to other international legislation</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/looking-to-use-deepseek-r1-in-the-eu-this-new-study-shows-its-missing-key-criteria-to-comply-with-the-eu-ai-act">Looking to use DeepSeek R1 in the EU? Maybe think again</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Looking to use DeepSeek R1 in the EU? This new study shows it’s missing key criteria to comply with the EU AI Act ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence/looking-to-use-deepseek-r1-in-the-eu-this-new-study-shows-its-missing-key-criteria-to-comply-with-the-eu-ai-act</link>
                                                                            <description>
                            <![CDATA[ The DeepSeek R1 AI model might not meet key requirements to comply with aspects of the EU AI Act, according to new research. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gUCptVgnFrNDe8EQVZmoZa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MUZbb2FPBJsBCiUyGvvfAo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Feb 2025 08:15:00 +0000</pubDate>                                                                                                                                <updated>Wed, 05 Feb 2025 14:39:58 +0000</updated>
                                                                                                                                            <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                <author><![CDATA[ rory.bathgate@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rory Bathgate is the Features and Multimedia Editor at ITPro, overseeing all in-depth content and case studies. He is a subject expert on artificial intelligence and business networks but in his time at ITPro has also covered a wide range of areas including cyber security and hardware. Throughout his time at ITPro, Rory has charted the rise in popularity of generative AI and specifically companies such as Microsoft, OpenAI, and Google.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Alongside this, he has delved into increasing calls for ethical and responsible AI as global legislators circle the technology, as well as the latest in mobile networking technology, from 5G mmWave to the 3G sunset and how it will affect businesses.&lt;/p&gt;
&lt;p&gt;He has provided coverage from high-profile tech conferences such as Dell Technologies World, SuiteWorld, and VMware Explore Europe. His on-the-ground coverage has included live blogs, extensive daily coverage of the most significant announcements, analysis pieces, and podcasts.&lt;/p&gt;
&lt;p&gt;Indeed, Rory is also a full-time co-host of the ITPro Podcast alongside Jane McCallion, where he swaps a keyboard for a microphone to discuss the latest learnings in tech. Each week, a guest comes onto the show to discuss topics such as cyber security, productivity, or digital transformation in detail.&lt;/p&gt;
&lt;p&gt;Rory has an MA in Eighteenth-Century Studies from King’s College London, as well as a BA in English and American Literature from the University of Kent. He joined ITPro in 2022 as a graduate, after four years in student journalism.&lt;/p&gt;
&lt;p&gt;In his free time, Rory enjoys photography and video editing, and can often be found at the cinema or reading a good science fiction paperback.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MUZbb2FPBJsBCiUyGvvfAo-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Landing page for the DeepSeek R1 website pictured on a smartphone held in a person&#039;s hand.]]></media:description>                                                            <media:text><![CDATA[Landing page for the DeepSeek R1 website pictured on a smartphone held in a person&#039;s hand.]]></media:text>
                                <media:title type="plain"><![CDATA[Landing page for the DeepSeek R1 website pictured on a smartphone held in a person&#039;s hand.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MUZbb2FPBJsBCiUyGvvfAo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The popular<a href="https://www.itpro.com/strategy/28181/what-is-ai"> AI</a> model <a href="https://www.itpro.com/technology/artificial-intelligence/the-deepseek-bombshell-has-been-a-wakeup-call-for-us-tech-giants">DeepSeek R1</a> may contain inherent flaws that make it incompatible with the <a href="https://www.itpro.com/business/policy-and-legislation/how-the-eu-ai-act-compares-to-other-international-regulatory-approaches">EU AI Act</a>, according to new research.</p><p>DeepSeek R1 took the tech industry by storm in early January, offering an open source option for performance comparable to <a href="https://www.itpro.com/technology/artificial-intelligence/openai-strawberry-what-is-o1-preview-and-what-can-it-do"><u>OpenAI’s o1</u></a> at a fraction of the cost. </p><p>But the model’s outputs may contain vulnerabilities that jeopardize its rollout in the EU. Using a new framework known as COMPL-AI, researchers analyzed both DeepSeek R1 models: one distilled from <a href="https://www.itpro.com/technology/artificial-intelligence/metas-llama-31-promises-to-compete-with-closed-source-competition">Meta’s Llama 3.1</a> and the other from Alibaba’s Qwen 2.5.</p><p>The framework was created by researchers at ETH Zurich, the Institute for Computer Science, Artificial Intelligence and Technology (INSAIT), and LatticeFlow AI. It aims to evaluate models on a range of factors such as transparency, risk, bias, and cybersecurity readiness, measured against the requirements of the <a href="https://www.itpro.com/technology/artificial-intelligence/eu-ai-act-everything-you-need-to-know-about-the-legislation-including-rules-requirements-and-who-will-be-forced-to-comply">EU AI Act</a>.</p><p>In a test of whether the model could be hijacked with jailbreaks and prompt injection attacks, both DeepSeek models scored the lowest of all models benchmarked by COMPL-AI. DeepSeek R1 Distill Llama 8B scored just 0.15 for the hijacking and prompt leakage out of a possible 1.0, compared to 0.43 for <a href="https://www.itpro.com/technology/artificial-intelligence/metas-llama-2-is-the-first-free-chatgpt-competitor-but-experts-rebut-open-source-claims"><u>Llama 2 70B</u></a> and 0.84 for Claude 3 Opus.</p><p>This could put it in jeopardy with Article 15, paragraph 5 of the EU AI Act, which states: “High-risk AI systems shall be resilient against attempts by unauthorized third parties to alter their use, outputs or performance by exploiting system vulnerabilities”.</p><p>The analysis comes after similar research into <a href="https://www.itpro.com/technology/artificial-intelligence/deepseek-r1-model-jailbreak-security-flaws"><u>DeepSeek jailbreaking techniques</u></a> conducted  by Cisco, which found the model was susceptible to prompts intended to produce malicious outputs 100% of the time.</p><p>In other areas, the models outperformed some of the most popular open and proprietary <a href="https://www.itpro.com/technology/artificial-intelligence/generative-ai-vs-large-language-models">LLMs</a>. The model was found to consistently deny it was human, a feat not achieved by <a href="https://www.itpro.com/technology/artificial-intelligence-ai/368288/what-is-gpt-4">GPT-4</a> or the baseline version of Qwen.</p><p>Tested with HumanEval, a widely-used benchmark for assessing an LLM’s code generation capabilities, DeepSeek also outperformed other <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> models. DeepSeek R1 Qwen 14B scored 0.71 versus Llama 2 70b’s 0.31, exceeded in COMPL-AI’s leaderboard only by GPT-3.5 (0.76), GPT-4 (0.84) and Claude 3 Opus (0.85).</p><p>"As corporate AI governance requirements tighten, enterprises need to bridge internal AI governance and external compliance with technical evaluations to assess risks and ensure their AI systems can be safely deployed for commercial use," said Dr. Petar Tsankov, co-founder and CEO at LatticeFlow AI. </p><p>"Our evaluation of DeepSeek models underscores a growing challenge: while progress has been made in improving capabilities and reducing inference costs, one cannot ignore critical gaps in key areas that directly impact business risks – <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a>, bias, and censorship. With COMPL-AI, we commit to serving society and businesses with a comprehensive, technical, transparent approach to assessing and mitigating AI risks."</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="h5EwYmo3wCf7esjKQNods5" name="How to enable M365 Copilot for your organisation" caption="" alt="How to enable M365 Copilot for your organisation" src="https://cdn.mos.cms.futurecdn.net/h5EwYmo3wCf7esjKQNods5.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: CDW | Microsoft Copilot)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/how-to-enable-m365-copilot-for-your-organisation"><em>Migrate and optimize your IT environment</em></a></p></div></div><p>COMPL-AI is not formally associated with the EU Commission, nor able to provide an official third-party analysis of the EU AI Act. Companies looking to adopt DeepSeek or other models into their tech stack will still need to follow best practices for implementing <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai">generative AI</a>.</p><p>Leaders may also look into hiring for roles such as <a href="https://www.itpro.com/technology/artificial-intelligence/does-your-business-need-a-chief-ai-officer"><u>chief AI officers</u></a> and <a href="https://www.itpro.com/business/careers-and-training/what-is-a-data-ethicist"><u>data ethicists</u></a>, alongside the establishment of <a href="https://www.itpro.com/cloud/cloud-computing/what-is-a-sovereign-cloud"><u>sovereign cloud</u></a> clusters to ensure data used for AI within the EU is compliant with regional laws.</p><iframe allow="" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=64064708&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=true&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ European AI alliance looks to take on Silicon Valley and develop home-grown LLMs ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence/european-ai-alliance-looks-to-take-on-silicon-valley-and-develop-home-grown-llms</link>
                                                                            <description>
                            <![CDATA[ OpenEuroLLM is a consortium of 20 leading European research institutions, companies, and EuroHPC centers hoping to develop a family of open source LLMs. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6A5hdZNwJp9j7QCqLNTL8g</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sMeavPaHEiJU8DRrvz2BFi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Feb 2025 10:44:50 +0000</pubDate>                                                                                                                                <updated>Wed, 19 Feb 2025 12:16:15 +0000</updated>
                                                                                                                                            <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sMeavPaHEiJU8DRrvz2BFi-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[View of Europe from space with lines showing connections denoting wireless connectivity]]></media:description>                                                            <media:text><![CDATA[View of Europe from space with lines showing connections denoting wireless connectivity]]></media:text>
                                <media:title type="plain"><![CDATA[View of Europe from space with lines showing connections denoting wireless connectivity]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sMeavPaHEiJU8DRrvz2BFi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new alliance with a budget of €37.4 million is working on a European alternative to OpenAI’s <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369965/what-is-chatgpt-and-what-does-it-mean-for-businesses">ChatGPT</a> and <a href="https://www.itpro.com/technology/artificial-intelligence/deepseek-r1-model-jailbreak-security-flaws">DeepSeek’s R1</a>.</p><p>OpenEuroLLM is a consortium of 20 leading European research institutions, companies, and EuroHPC centers hoping to develop a family of high-performance, multilingual, large language foundation models for commercial, industrial, and public service applications.</p><p>The aim is to create a home-grown rival to models from foreign tech firms, trained specifically on European data.</p><p>"The transparent and compliant open-source models will democratize access to high-quality AI technologies and strengthen the ability of European companies to compete on a global market and public organizations to produce impactful public services,” the consortium said.</p><p>"The OpenEuroLLM project is aligned with the imperative to improve Europe’s competitiveness and digital sovereignty."</p><p>The consortium will work with <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> and open science communities such as LAION, open-sci and OpenML, along with additional experts in the field.</p><p>Models, software, data, and evaluation will be fully open, researchers said, and can be fine-tuned and instruction-tuned for specific industries or public sector bodies. </p><p>Additionally, the model will be trained in 35 languages.</p><p>The project will be co-led by computational linguist Jan Hajič of Czechia's Charles University and Peter Sarlin, co-founder of Finland's Silo AI - Europe's largest private AI lab, which was acquired last year by AMD for $665 million.  </p><p>It also includes a dozen European universities, along with Germany's Aleph Alpha Research and ellamind, France's LightOn, and Spain's Prompsit Language Engineering. </p><p>Also participating are four EuropHPC centers: the Barcelona Supercomputing Center in Spain, Cineca Interuniversity Consortium in Italy, CSC - IT Center for Science in Finland, and the Netherlands' SURF.</p><p>"The OpenEuroLLM project stands as a testament to Europe’s ability to lead in AI innovation while adhering to principles of openness, trust, and fairness," said the Eindhoven University of Technology in a statement. </p><p>"By involving research institutions, industry leaders, and EuroHPC centers, the initiative ensures a broad and inclusive approach to AI development."</p><p>The European Commission has backed OpenEuroLLM to the tune of €37.4 million, with €20.6 million coming from the Digital Europe Programme. </p><p>The consortium is supported by the Strategic Technologies for Europe Platform (STEP), aimed at raising and steering funding to increase European investment into critical technology projects.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="PVTgVkPVjkmkdMPBJBtHH7" name="Secure cloud best practices" caption="" alt="Secure cloud best practices" src="https://cdn.mos.cms.futurecdn.net/PVTgVkPVjkmkdMPBJBtHH7.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: AWS)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/secure-cloud-best-practices"><em>Strengthen your organization's cybersecurity</em></a></p></div></div><p>"Europe has the talent and resources necessary to take a leading position in this global <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a> competition," said Laurent Daudet, co-CEO and co-founder of LightOn. </p><p>"To transform these efforts into a real strategic lever, Europe must not only capitalize on the AI Act, a true catalyst for innovation towards <a href="https://www.itpro.com/technology/artificial-intelligence-ai/370342/inside-mozillas-mission-to-champion-trustworthy-ai">trustworthy AI</a>, but also support a coordinated approach from its leaders. This is now possible thanks to the OpenEuroLLM consortium."</p><iframe allow="" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/e72e3adf-5bdc-4be4-bfe8-51510b6b9843/"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A big enforcement deadline for the EU AI Act just passed – here's what you need to know ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence/a-big-enforcement-deadline-for-the-eu-ai-act-is-just-around-the-corner</link>
                                                                            <description>
                            <![CDATA[ The first set of compliance deadlines for the EU AI Act passed on the 2nd of February, and enterprises are urged to ramp up preparations for future deadlines. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nAVdzBbjirg8bjBEKEywfA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qnGSwbfzp9zTsFt2t49oUT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Jan 2025 13:40:25 +0000</pubDate>                                                                                                                                <updated>Wed, 19 Feb 2025 12:17:19 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ george.fitzmaurice@futurenet.com (George Fitzmaurice) ]]></author>                    <dc:creator><![CDATA[ George Fitzmaurice ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/N4xHCjSAXKcijjt3oiQtfc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qnGSwbfzp9zTsFt2t49oUT-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[EU flags fly outside the union headquarters in Brussels, Belgium.]]></media:description>                                                            <media:text><![CDATA[EU flags fly outside the union headquarters in Brussels, Belgium.]]></media:text>
                                <media:title type="plain"><![CDATA[EU flags fly outside the union headquarters in Brussels, Belgium.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qnGSwbfzp9zTsFt2t49oUT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The first of a number of enforcement actions for the <a href="https://www.itpro.com/business/policy-and-legislation/how-the-eu-ai-act-compares-to-other-international-regulatory-approaches">EU AI Act</a> have officially come into effect, and experts have warned firms should accelerate preparations for the next batch of deadlines. </p><p><a href="https://www.itpro.com/technology/artificial-intelligence/eu-ai-act-everything-you-need-to-know-about-the-legislation-including-rules-requirements-and-who-will-be-forced-to-comply">Passed in March last year</a>, the first elements of the EU’s landmark legislation came into effect on the 2nd February 2025, bringing with it a series of rules and regulations that AI developers and deployers must adhere to. </p><p>The EU AI Act employs a risk-based approach to assessing the potential impact of <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a> systems, designating them as being minimal, limited, or high-risk. High-risk systems, for example, are those defined as posing a potential threat to life, human rights, or financial livelihood. </p><p>These particular systems are in the crosshairs following the introduction of the new rules this month. </p><p>Speaking to <em>ITPro</em> ahead of the deadline, Enza Iannopollo, principal analyst at Forrester, said lawmakers specifically chose to target the most dangerous AI use cases with the first round of rules. </p><p>“Requirements enforced on this deadline focus on AI use-cases the EU considers pose the greatest risk to core Union values and fundamental rights, due to their potential negative impacts,” Iannopollo said.</p><p>“These rules are those related to prohibited AI use-cases, along with requirements related to AI literacy. Organizations that violate these rules could face severe fines — up to 7% of their global turnover — so it’s crucial that requirements are met effectively,” she added.</p><p>Iannopollo noted that fines will not be issued immediately, however, as details about sanctions are still a work-in-progress and the authorities in charge of enforcement are still not in place. </p><p>While there may not be any big fines in the headlines in the next few months, Iannopollo said this is still an important milestone.</p><p>Tim Roberts, UK country co-leader at AlixPartners, said the first set of compliance obligations will act similarly to GDPR, mainly in that they will apply to any organization doing business with AI models in Europe. </p><p>With this in mind, it’s critical that companies are aware of these first batch of rules, even if they are not EU-based. </p><p>“Naturally, this also reignites the debate about striking the right balance between innovation and regulation. But instead of seeing them as opposing forces, it’s more useful to think of them as two things we need to get right in parallel … because regulation can be a facilitator of innovation - not a blocker,” Roberts said.  </p><p>“The speed at which AI is advancing has caused discomfort for some consumers, but strong safeguards can build trust and create a thriving (and fairer) environment for greater business innovation. </p><p>“The EU AI Act is an important first step in this journey, and its success will depend on how well it is applied and how well it evolves, with the end goal being smarter regulation that drives businesses to continue pushing boundaries for the benefit of all.”</p><h2 id="eu-ai-act-firms-should-tighten-up-risk-assessments">EU AI Act: Firms should tighten up risk assessments </h2><p>Due to the global reach of the Act and the fact that requirements span the entire AI value chain, Iannopollo said enterprises must ensure they adhere to the regulation. </p><p>“The EU AI Act will have a significant impact on AI governance globally. With these regulations, the EU has established the ‘de facto’ standard for trustworthy AI and AI risk management,” she added.</p><p>To prepare for the rules, enterprises are advised to begin refining risk assessment practices to ensure they’ve classified AI use cases in line with the designated risk categories contained in the Act. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="XHwXjqsAzm6yMEXvN6seNV" name="Protect your organization with Microsoft 365" caption="" alt="Protect your organization with Microsoft 365" src="https://cdn.mos.cms.futurecdn.net/XHwXjqsAzm6yMEXvN6seNV.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: CDW | Microsoft)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/protect-your-organization-with-microsoft-365"><em>Implement the right Microsoft 365 solution</em></a></p></div></div><p>Systems that would fall within the ‘prohibited’ category need to be switched off immediately.</p><p>“Finally, they need to be prepared for the next key deadline on 2nd August. By this date, the enforcement machine and sanctions will be in better shape, and authorities will be much more likely to sanction firms that are not compliant. In other words, this is when we will see a lot more action.”</p><iframe allow="" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/e72e3adf-5bdc-4be4-bfe8-51510b6b9843/"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The EU just launched a bold new initiative to support regional AI startups and drive innovation ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence/the-eu-just-launched-a-bold-new-initiative-to-support-regional-ai-startups-and-drive-innovation</link>
                                                                            <description>
                            <![CDATA[ EU-based artificial intelligence firms will be given financial support and access to supercomputers in a bid to accelerate innovation and boost competition with global counterparts ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">FGGv9rLUDLaB66tCM2D9AN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Y5ejojjmbwXwu2fKWKojZi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 26 Jan 2024 12:55:47 +0000</pubDate>                                                                                                                                <updated>Thu, 08 Feb 2024 18:05:26 +0000</updated>
                                                                                                                                            <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Y5ejojjmbwXwu2fKWKojZi-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Margrethe Vestager talking to media  the Berlaymont, the EU Commission headquarter on June 20, 2023, in Brussels, Belgium]]></media:description>                                                            <media:text><![CDATA[Margrethe Vestager talking to media  the Berlaymont, the EU Commission headquarter on June 20, 2023, in Brussels, Belgium]]></media:text>
                                <media:title type="plain"><![CDATA[Margrethe Vestager talking to media  the Berlaymont, the EU Commission headquarter on June 20, 2023, in Brussels, Belgium]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Y5ejojjmbwXwu2fKWKojZi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The European Commission has announced a series of new measures aimed at providing support for AI startups and small businesses across the EU. </p><p>The <em>AI Innovation</em> package builds on a pledge made by Commission president Ursula von der Leyen in September last year that European <a href="https://www.itpro.com/business-strategy/startups/359742/uks-ai-startup-ecosystem-600-percent-growth-over-decade">AI startups</a> would be given access to the bloc&apos;s <a href="https://www.itpro.com/cognitive-technology/30944/new-supercomputers-planned-at-three-uk-universities">supercomputers</a> to train <a href="https://www.itpro.com/technology/artificial-intelligence-ai/370342/inside-mozillas-mission-to-champion-trustworthy-ai">trustworthy AI</a> models.</p><p>It involves amending the EuroHPC Regulation to set up what the Commission is calling ‘<em>AI Factories</em>’ to acquire, upgrade, and operate AI-dedicated supercomputers to handle <a href="https://www.itpro.com/strategy/28071/what-is-machine-learning">machine learning</a> and the training of large general purpose <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a> models.</p><p>A &apos;large number&apos; of public and private users, including startups and SMEs, will be given access to the scheme, the Commission said, and supported in algorithmic development, testing evaluation, and validation of large-scale AI models.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="UKadY9bbpr7uHiM7VUwopY" name="European_Union_Flag_GettyImages-524184525 (1).jpg" caption="" alt="Close up shot of the flag of the European Union" src="https://cdn.mos.cms.futurecdn.net/UKadY9bbpr7uHiM7VUwopY.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-and-legislation/ill-informed-eu-lawmakers-risk-blurring-the-definition-of-open-source-in-cyber-resilience-act">"Ill-informed" EU lawmakers risk blurring the definition of open source in Cyber Resilience Act</a><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-and-legislation/satya-nadella-says-microsoft-and-openai-have-a-pro-competition-partnership-regulators-arent-so-sure">Satya Nadella says Microsoft and OpenAI have a “pro-competition partnership” – regulators aren&apos;t so sure</a><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-and-legislation/european-firms-say-theyre-being-left-in-the-dark-by-big-tech-gatekeepers-ahead-of-digital-markets-act">European firms say they’re being “left in the dark” by big tech gatekeepers ahead of Digital Markets Act</a></p></div></div><p>"You need computing power to develop AI. A lot of it. So we want to give SMEs and startups privileged access to the network of European supercomputers," said Margrethe Vestager, executive vice president of the European Commission.</p><p>"We are committed to innovation of AI and innovation with AI. And we will do our best to build a thriving AI ecosystem in Europe."</p><p>A dedicated AI Office will be set up to handle the development and coordination of AI policy at European level, officials said, as well as to supervise the implementation and enforcement of the EU AI Act.</p><p>Meanwhile, financial support from the Commission will be provided through Horizon Europe and the Digital Europe programme in a package that lawmakers said will offer an additional boost of public and private investment of around €4 billion until 2027.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="eCE7byiwX3xMLQDc8sanVD" name="The smarter way to serve customers_listing.jpg" caption="" alt="An on-demand webinar from IBM to help you understand the profound impact and potential of generative AI for customer service" src="https://cdn.mos.cms.futurecdn.net/eCE7byiwX3xMLQDc8sanVD.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><em>Discover how generative AI is shaping the future </em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/the-smarter-way-to-serve-customers-ai-for-customer-service">WATCH NOW</a></p></div></div><p>There are also plans for education, training, skilling, and <a href="https://www.itpro.com/digital-transformation/31792/why-reskilling-isnt-just-about-learning-new-technology">reskilling</a> programs, as well as venture capital or equity support. The Commission said it also aims to speed up the development and deployment of Common European Data Spaces for the AI community.</p><p>Finally, there&apos;s a new GenAI4EU initiative, aimed at supporting the development of novel use cases and emerging applications in <a href="https://www.itpro.com/tags/robotics">robotics</a>, health, biotech, manufacturing, mobility, climate, and virtual worlds.</p><p>"Today, we announce the launch of AI Factories, bringing together the ‘raw materials’ for AI: computing power, data, algorithms and talent," said Thierry Breton, commissioner for internal markets.</p><p>"They will serve as a one-stop shop for Europe’s AI start-ups, enabling them to develop the most advanced AI models and industrial applications. We are making Europe the best place in the world for trustworthy AI."</p><p>The support for EU-based AI startups follows a period of intense criticism of the union’s flagship EU AI Act, which industry stakeholders and critics both warned could have an adverse effect on the broader European AI industry.</p><p>Last year, tech policy group DigitalEurope said that the legislation risked “<a href="https://www.itpro.com/business/policy-and-legislation/european-ai-startups-risk-being-regulated-out-of-existence-under-eu-ai-act">regulating AI startups out of existence</a>”. </p><p>The group warned that strict new rules around the development and deployment of AI could prevent companies in the union from competing with global counterparts, particularly in the US.</p><h2 id="additional-support-for-european-digital-infrastructure">Additional support for European digital infrastructure</h2><p>The Commission said it will also establish two European Digital Infrastructure Consortiums (EDICs) as part of the scheme. </p><p>The first of these, the Alliance for Language Technologies, is aimed at developing a common European infrastructure in language technologies to address the shortage of European language data for the training of AI solutions.</p><p>Meanwhile, CitiVERSE will apply state-of-the-art <a href="https://www.itpro.com/technology/artificial-intelligence/amazing-ai-tools-to-try-today">AI tools</a> to develop Local Digital Twins for Smart Communities, helping cities simulate and optimize processes from traffic management to waste management.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Open source advocates "cautiously optimistic" about Cyber Resilience Act after industry pushback prompts changes ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/open-source-advocates-cautiously-optimistic-about-cyber-resilience-act-after-industry-pushback-prompts-changes</link>
                                                                            <description>
                            <![CDATA[ Amendments to the Cyber Resilience Act in December curtailed the potential impact on open source developers in the region, an industry body has said ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6yvgaTvynFw3FEAtzXbE9h</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/y6tegU6S8qaKFmtHCKZp5Y-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 26 Jan 2024 11:59:51 +0000</pubDate>                                                                                                                                <updated>Thu, 08 Feb 2024 18:02:57 +0000</updated>
                                                                                                                                            <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z2aSrrbwGAyWwinHzGraAP.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a Staff Writer at ITPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;
&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2018 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;
&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/y6tegU6S8qaKFmtHCKZp5Y-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Flags of the European Union (EU) pictured on a still day with sunshine in background]]></media:description>                                                            <media:text><![CDATA[Flags of the European Union (EU) pictured on a still day with sunshine in background]]></media:text>
                                <media:title type="plain"><![CDATA[Flags of the European Union (EU) pictured on a still day with sunshine in background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/y6tegU6S8qaKFmtHCKZp5Y-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Changes made to the EU’s <a href="https://www.itpro.com/business/policy-and-legislation/what-is-the-eus-cyber-resilience-act-cra"><u>Cyber Resilience Act</u></a> (CRA) have been welcomed by open source developers, who believe the updated legislation will be less deleterious to the ecosystem than its previous iterations.</p><p>The amended version of the CRA was published on 20 December 2023 and includes clarifications reducing the scope of the regulation, as well as a ‘light-touch and tailor-made regulatory regime’ for <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> developers.</p><p>Thierry Carrez, general manager of the Open Infrastructure Foundation, said changes made to the CRA highlight the success of the pressure applied to the EU by open source advocates.</p><p>“It’s clear from reading the CRA version published on 20 December that the engagement of many open source advocacy groups — including the OpenInfra Foundation — has led to multiple clarifications regarding the openly developed open source model.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="UKadY9bbpr7uHiM7VUwopY" name="European_Union_Flag_GettyImages-524184525 (1).jpg" caption="" alt="Close up shot of the flag of the European Union" src="https://cdn.mos.cms.futurecdn.net/UKadY9bbpr7uHiM7VUwopY.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/software/open-source/reprieve-for-open-source-industry-as-agreement-reached-on-cyber-resilience-act">Reprieve for open source industry as agreement reached on Cyber Resilience Act</a><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-and-legislation/ill-informed-eu-lawmakers-risk-blurring-the-definition-of-open-source-in-cyber-resilience-act">"Ill-informed" EU lawmakers risk blurring the definition of open source in Cyber Resilience Act</a></p></div></div><p>Carrez said open source advocates are hopeful these clarifications will reduce the negative impact the CRA will have on open source <a href="https://www.itpro.com/software">software</a>, which represents more than 70% of software used in European digital products.</p><p>"We’re cautiously optimistic that those clarifications will reduce the risk of CRA having global chilling effects around open source development and participation.”</p><p>He added, however, that open source community bodies will continue to lobby the EU in upcoming public discussions of the legislation.</p><p>“We will continue to be proactive and urgent in our advocacy for open source as CRA implementation plans and timelines are determined. In the near term, we’ll be participating in discussions at the EU Open Source Policy Summit and FOSDEM.”</p><h2 id="the-cyber-resilience-act-has-been-a-minefield-for-open-source-devs">The Cyber Resilience Act has been a minefield for open source devs</h2><p>According to Carrez, this new legislation is not as threatening as the heavy handed approach previous iterations of the Act included since it was first unveiled in September 2022.</p><p>The legislation was intended to boost cyber security and add further protections to digital products like <a href="https://www.itpro.com/cloud-computing/28037/what-is-iot">Internet of Things</a> (IoT) devices that have caused a dramatic expansion in attack surfaces.</p><p>In addition, the CRA placed new obligations on open source developers to ensure any software developed for commercial products conforms to new rules by submitting documentation, risk assessments, and post-release <a href="https://www.itpro.com/security">security</a> requirements.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="zHcjrcoxJqcY5UDouneP5Q" name="digital_europe_concept_GettyImages-1044188400 (1).jpg" caption="" alt="Blue futuristic Europe vector with hexagonal grids and light beams" src="https://cdn.mos.cms.futurecdn.net/zHcjrcoxJqcY5UDouneP5Q.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/">What&apos;s the EU&apos;s problem with open source?</a></p></div></div><p>These requirements were deemed overly demanding by industry experts who signed an <a href="https://www.itpro.com/software/open-source/eu-cyber-resilience-act-a-death-knell-for-open-source-software-critics-warn%5C"><u>open letter</u></a> in April 2023 outlining their concerns to the European Parliament.  </p><p>“If the CRA is, in fact, implemented as written, it will have a chilling effect on open source software development as a global endeavor, with the net effect of undermining the EU’s own expressed goals for innovation, <a href="https://www.itpro.com/security/data-protection/why-the-matrix-offers-valuable-lessons-on-data-sovereignty-for-channel-partners">digital sovereignty</a>, and future prosperity.”</p><p>This public outcry was successful in pushing the EU into amending the CRA so that some of the most severe restrictions placed on open source developers will be relaxed.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ZhfDScDRLze3CZL24fjUo" name="The Total Economic Impact™ Of IBM Security MaaS360 With Watson.jpg" caption="" alt="The Total Economic Impact™ Of IBM Security MaaS360 With Watson whitepaper" src="https://cdn.mos.cms.futurecdn.net/ZhfDScDRLze3CZL24fjUo.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><em>Discover how MaaS360 enables cost savings </em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/endpoint-security/367053/the-total-economic-impacttm-of-ibm-security-maas360-with-watson">DOWNLOAD NOW</a></p></div></div><p>Some of the amendments made by the EU included tightening the definition of what constitutes commercial activity so that funding essential project support functions without the intention to profit is exempt. </p><p>A clearer distinction between the development and supply phases was also implemented, whereby the regulation comes into effect when software is made available on the market in the course of commercial activity.</p><p>Another example involves a separate definition for Foundations that are now considered “open-source software stewards” and subject to a ‘light-touch and tailor-made regulatory regime’.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Forcing Apple to allow alternative app stores might cause major security risks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/forcing-apple-to-allow-alternative-app-stores-might-cause-major-security-risks</link>
                                                                            <description>
                            <![CDATA[ Apple will be forced to allow third-party marketplaces on its devices, but some experts have raised serious security concerns ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ALFsgXEcaNBw2NyhosHctM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7sjrkAfjGK8PYMVXm3ME7Z-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 18 Jan 2024 14:02:28 +0000</pubDate>                                                                                                                                <updated>Thu, 08 Feb 2024 17:13:27 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z2aSrrbwGAyWwinHzGraAP.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a Staff Writer at ITPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;
&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2018 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;
&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7sjrkAfjGK8PYMVXm3ME7Z-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Apple logo displayed on a store front in Shanghai, China. ]]></media:description>                                                            <media:text><![CDATA[Apple logo displayed on a store front in Shanghai, China. ]]></media:text>
                                <media:title type="plain"><![CDATA[Apple logo displayed on a store front in Shanghai, China. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7sjrkAfjGK8PYMVXm3ME7Z-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Apple is set to make fundamental changes to its App Store in the EU to comply with the European Commission’s <a href="https://www.itpro.com/business/policy-legislation/368435/what-is-the-eus-digital-markets-act-dma"><u>Digital Markets Act</u></a> (DMA), but some experts are worried these changes could have serious negative security implications.</p><p>The DMA will introduce a mandate on <a href="https://www.itpro.com/software/apple"><u>Apple</u></a>, and other designated ‘gatekeepers’ to start letting users install third-party app stores and sideload apps onto their devices, aiming to increase competition on online platforms. </p><p>Security specialists are concerned this decision will open up another <a href="https://www.itpro.com/security/cyber-attacks/email-still-the-top-vector-for-attackers"><u>attack vector </u></a>for threat actors, however, and potentially result in a flood of dangerous applications being downloaded.</p><p>Jamie Moles, senior technical manager at ExtraHop, told <em>ITPro</em> the DMA could have unintended consequences for security of online platforms by removing the operator’s ability to freely moderate the software being distributed.</p><p>“It [the DMA] would increase the overall risks to the platform because it creates an entirely new attack vector,” he said. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="owtgL5igKBGSs2dYxRpAhm" name="Apple_Logo_GettyImages-1704958734.jpg" caption="" alt="Apple logo displayed on a storefront in China in 2023 coniciding with the launch of Apple MLX" src="https://cdn.mos.cms.futurecdn.net/owtgL5igKBGSs2dYxRpAhm.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/why-apples-generative-ai-plan-may-see-it-abandon-its-closed-shop-approach">Why Apple’s generative AI plan may see it abandon its closed-shop approach</a><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/machine-learning/apple-just-discreetly-launched-a-raft-of-new-machine-learning-tools-and-theyre-free">Apple just discreetly launched a raft of new machine learning tools, and they’re free</a><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/why-the-apple-uk-hiring-spree-makes-sense-for-the-tech-giant">Why the Apple UK hiring spree "makes sense" for the tech giant</a></p></div></div><p>“The requirements for an app to appear on the app store are, in part, designed to protect the security of the system and comply with Apple’s own privacy policy. If you remove the ability to directly audit the programs being distributed to the platform, then it is inevitable that there will be more security risks.”</p><p>For example, Moles highlighted a recent example of security flaws in the <a href="https://www.itpro.com/cyber-crime/32804/epics-battle-royale-game-fortnite-used-to-launder-money"><u>Epic Games Store</u></a>, which could be accessible on <a href="https://www.itpro.com/software/apple/ios">iOS</a> under the new DMA stipulations.</p><p>“The Epic Games Store (EGS), a platform that could be added to iOS if the courts rule in Epic Games’s favor, had issues with privacy upon release. EGS was deriving contacts from other games stores by directly accessing files stored locally by a competing app store, Steam, rather than using a more secure API link”, Moles commented.</p><p>“Epic Games apologized but has not changed the method by which it syncs contacts with Steam contacts. This is a security risk created by a company with good intentions, so the potential downsides for a company with bad intentions are huge.”</p><h2 id="how-will-apple-respond-to-these-changes">How will Apple respond to these changes?</h2><p>Moles said he expects the changes to the Apple App Store to be limited to the EU region, as opposed to the regulation prompting a universal policy shift from the tech giant like it did with the mandated USB-C connectors for iPhones.</p><p>“Another app store is a software change, and Apple already has different software configurations for different regions. In October, Apple required an Internet Content Provider license for apps to appear on the Chinese version of the app store, so the precedent is there for each region to have its app store configured for different regulatory environments.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="UKadY9bbpr7uHiM7VUwopY" name="European_Union_Flag_GettyImages-524184525 (1).jpg" caption="" alt="Close up shot of the flag of the European Union" src="https://cdn.mos.cms.futurecdn.net/UKadY9bbpr7uHiM7VUwopY.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/368435/what-is-the-eus-digital-markets-act-dma">What is the EU&apos;s Digital Markets Act (DMA)?</a></p></div></div><p>Apple could introduce a series of permission layers on <a href="https://www.itpro.com/software/apple/ios"><u>iOS</u></a> to protect the majority of its users from inadvertently accessing unaudited marketplaces or sideloading malicious applications, Moles suggested. </p><p>Another measure <a href="https://www.itpro.com/software/apple">Apple</a> could use to mitigate the risks associated with this shift could be to force unverified apps to be opened in a dedicated <a href="https://www.itpro.com/software">software</a> environment to minimize its access to the device&apos;s files and other applications.</p><p>Moles added that Apple could implement a similar approach to its policy on aftermarket <a href="https://www.itpro.com/hardware">hardware</a> components, such as batteries or screens.</p><p>“Imagine when downloading or booting one of these applications, several layers of warning notifications for each permission being granted to the software will appear on screen”,  he explained.</p><p>“The implementation would be similar to those in place for apps already, but likely in more explicit terms. Installing and sideloading could result in voiding warranty for devices, something Apple already does with aftermarket batteries and screens.”</p><h2 id="balance-is-needed-to-prevent-monopolies-and-limit-security-risks">Balance is needed to prevent monopolies and limit security risks</h2><p>The DMA was first tabled in 2022 to address the significant advantage big tech companies have over smaller competitors in the industry by limiting the control these companies have over how business is conducted on their platforms.</p><p>The regulation is targeted at preventing gatekeepers from using their privileged position as platform operators to promote their own products or services above those of their competitors. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="koNvE9zmQFam7EYpnGTT9m" name="ThreatLabz Report_The state of encrypted attacks_listing.jfif.jpg" caption="" alt="Whitepaper cover with title over image of high rise buildings with red circular digital icons dotted around" src="https://cdn.mos.cms.futurecdn.net/koNvE9zmQFam7EYpnGTT9m.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zscaler)</span></figcaption></figure><p class="fancy-box__body-text"><em>Discover the best practices for stopping encrypted attacks<br></em><br><a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/threatlabz-report-the-state-of-encrypted-attacks">DOWNLOAD NOW</a></p></div></div><p>On the subject of whether this act will produce a net benefit for consumers in the long run, Moles said, overall, the EU’s tech regulation in recent years has been warranted and in the interest of business and consumers alike, but it needs to be careful it isn’t creating more problems than it solves with the DMA.</p><p>“Most of the EU regulation in the tech space has been a good thing. The USB-C requirements are, by and large, to the benefit of consumers and <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR</a>, and as annoying as cookie notices can be, they set important protections on user data” Moles told <em>ITPro.</em></p><p>“However, while well intentioned, this particular change exposes users to far more risk with less obvious reward. Preventing large tech monopolies is essentially a good idea, but one that has to balance the challenges of creating and operating a platform of iOS’s size.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ EU agrees amendments to Cyber Solidarity Act in bid to create ‘cyber shield’ for member states ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/eu-agrees-amendments-to-cyber-solidarity-act-in-bid-to-create-cyber-shield-for-member-states</link>
                                                                            <description>
                            <![CDATA[ The EU’s Cyber Solidarity Act will provide new mechanisms for authorities to bolster union-wide security practices ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xBih98WVgZtUXU79byUPP6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UKadY9bbpr7uHiM7VUwopY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 21 Dec 2023 14:49:16 +0000</pubDate>                                                                                                                                <updated>Thu, 21 Dec 2023 19:03:49 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UKadY9bbpr7uHiM7VUwopY-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Close up shot of the flag of the European Union]]></media:description>                                                            <media:text><![CDATA[Close up shot of the flag of the European Union]]></media:text>
                                <media:title type="plain"><![CDATA[Close up shot of the flag of the European Union]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UKadY9bbpr7uHiM7VUwopY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>EU member states have reached a common position on the planned Cyber Solidarity Act, aimed at making Europe more resilient and reactive in the face of cyber threats.</p><p>The aim of the draft legislation is to support the detection and awareness of significant or large-scale <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> threats and incidents, to bolster preparedness, and to protect critical infrastructure and essential services such as hospitals and public utilities. </p><p>It&apos;s also intended to boost cooperation between member states in the event of a union-wide security incident and improve coordinated crisis management and response capabilities.</p><p>EU lawmakers hailed the announcement as a vital piece of legislation that will create a more robust security landscape for member states and organizations across the union.</p><p>"Today’s agreement is another step to improve <a href="https://www.itpro.com/security/369055/gartner-most-businesses-are-dropping-security-vendors-to-improve-cyber-resiliency">cyber resilience</a> in Europe," said José Luis Escrivá, Spanish minister for digital transformation.</p><p>"It will certainly strengthen EU’s and member states’ capabilities to prepare, prevent, respond, and recover from large-scale cyber threats and attacks in a more efficient and effective manner."</p><h2 id="cyber-solidarity-act-looks-to-x2018-shield-x2019-eu-from-threats">Cyber Solidarity Act looks to ‘shield’ EU from threats</h2><p>A major feature of the draft legislation is the creation of a &apos;European cyber shield&apos;, a pan-European infrastructure composed of national and cross-border security operations centers (SOCs) across the EU.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="jsDf3jLZpHDSCdinKXkGKb" name="security_padlock_GettyImages-1472032995 (1).jpg" caption="" alt="A digital padlock pictured on a circuit board" src="https://cdn.mos.cms.futurecdn.net/jsDf3jLZpHDSCdinKXkGKb.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-and-legislation/what-is-the-eus-cyber-resilience-act-cra">What is the EU&apos;s Cyber Resilience Act?</a></p></div></div><p>These will use <a href="https://www.itpro.com/strategy/28181/what-is-ai">artificial intelligence</a> (AI) and advanced <a href="https://www.itpro.com/business-intelligence/28220/what-is-data-analytics">data analytics</a> to detect and share warnings on cyber threats and incidents across borders. There are also plans for the creation of a cyber emergency mechanism to increase preparedness and enhance incident response capabilities.</p><p>This will include testing entities in highly critical sectors, such as healthcare, transport, and energy, to probe for potential vulnerabilities based on common risk scenarios, lawmakers said.</p><p>Similarly, a new EU ‘cyber security reserve’ will be set up consisting of incident response services from trusted private sector providers, all of which pre-contracted so they&apos;re ready to intervene at the request of a member state or EU institution, body, or agency.</p><p>There are also plans for a mutual financial assistance fund aimed at enabling member states to offer financial aid to others in the event of a serious security incident.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="25utcNEJH3jmoHFdCaevtA" name="Replacing VPN and protect hybrid work architecture_listing.jpg" caption="" alt="A webinar from Cloudflare on how to replace your VPN and secure your hybrid workforce" src="https://cdn.mos.cms.futurecdn.net/25utcNEJH3jmoHFdCaevtA.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Cloudflare)</span></figcaption></figure><p class="fancy-box__body-text"><em>Achieve your zero trust goals and gain a solid SASE architecture</em></p><p class="fancy-box__body-text"><br><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-computing/replacing-vpn-and-protect-hybrid-work-architecture">WATCH NOW</a></p></div></div><p>As part of the legislation, new mechanisms will be introduced to conduct reviews and assessments of large-scale cyber security incidents after they have taken place.</p><p>ENISA, the EU’s cyber security agency, will play a key role in supporting this aspect of the legislation, lawmakers said.</p><p>At the request of the European Commission or of national authorities, the security agency will conduct reviews of certain incidents and deliver reports to relevant governmental departments.</p><h2 id="cyber-solidarity-act-changes-align-with-nis2">Cyber Solidarity Act changes align with NIS2</h2><p>The new common position introduces a few, mostly minor, changes to the draft legislation. In particular, it clarifies terminology and adapts the text to member states’ specificities, particularly around the SOCs and the cyber shield.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="zHcjrcoxJqcY5UDouneP5Q" name="digital_europe_concept_GettyImages-1044188400 (1).jpg" caption="" alt="Blue futuristic Europe vector with hexagonal grids and light beams" src="https://cdn.mos.cms.futurecdn.net/zHcjrcoxJqcY5UDouneP5Q.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/370403/what-is-the-network-and-information-security-2-nis2-directive">What is the Network and Information Security 2 (NIS2) Directive?</a></p></div></div><p>Meanwhile, definitions have been modified and aligned with other legislation, such as the recently-revised <a href="https://www.itpro.com/business/policy-and-legislation/three-quarters-of-uk-firms-unprepared-for-nis2-regulations-study-finds">Network and Information Security Directive</a> (NIS2).</p><p>ENISA’s role has also been reinforced and clarified throughout the text, and improvements have been introduced around procurement, funding, information sharing, and the incident review mechanism.</p><p>The next step in the process is for the incoming presidency to start negotiating with the European Parliament on a final version of the proposed legislation.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The EU's 'long-arm' regulatory approach could create frosty US environment for European tech firms ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/the-eus-long-arm-regulatory-approach-could-create-frosty-us-environment-for-european-tech-firms</link>
                                                                            <description>
                            <![CDATA[ US tech firms are throwing their toys out of the pram over the EU’s Digital Markets Act, but will this come back to bite European companies? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hS9zohTo9v74Ap8WVabaVF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HEvtCwadjLxzx2kMEEvyBk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 20 Dec 2023 12:48:31 +0000</pubDate>                                                                                                                                <updated>Wed, 20 Dec 2023 15:14:12 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z2aSrrbwGAyWwinHzGraAP.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a Staff Writer at ITPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;
&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2018 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;
&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HEvtCwadjLxzx2kMEEvyBk-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[European Union and United States flags on display]]></media:description>                                                            <media:text><![CDATA[European Union and United States flags on display]]></media:text>
                                <media:title type="plain"><![CDATA[European Union and United States flags on display]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HEvtCwadjLxzx2kMEEvyBk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The EU risks making the US a hostile environment for European tech firms with its Digital Markets Act (DMA), according to industry experts.</p><p>Tech leaders have voiced their concerns that stringent regulations from the EU may lead to US tech companies using their influence to increase the cost of doing business for European organizations in the US.</p><p>This comes after a group of US lawmakers signed a letter to President Biden arguing the DMA will unfairly target US tech firms.</p><p>Speaking to <em>ITPro, </em>CEO at OpenUK Amanda Brock said the reaction from lawmakers in the US was understandable but it was also no stranger to ‘long-arm regulations’.</p><p>“When looking at the letter, it’s hardly surprising that the EU’s long arm reach is frustrating US regulators, though then again the US has pushed a long-arm regulatory reach across the globe for many years,” she said. </p><p>Brock added she feels the EU’s ‘waterfall approach’ to legislation is outdated and incongruent with the new digital landscape.</p><p>“The question the EU needs to ask themselves is will this approach really allow a tech sector to flourish? </p><p>“Its waterfall approach to legislation – extremely prescriptive, detailed, and often paternalistic is one that might have worked in tech 25-30 years ago but which doesn’t reflect the way our digital economy works – which is agile and flexible. Somehow legislators need to move to this.” </p><h2 id="european-tech-firms-could-face-frosty-reception-in-us">European tech firms could face frosty reception in US</h2><p>Dr Ilia Kolochenko, chief architect at ImmuniWeb and adjunct professor of <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> and cyber law at Capitol Technology University, told <em>ITPro </em>the EU’s regulatory approach is not perfect, but argued it is preferable to the ‘Byzantine’ regulatory framework in the US.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="zHcjrcoxJqcY5UDouneP5Q" name="digital_europe_concept_GettyImages-1044188400 (1).jpg" caption="" alt="Blue futuristic Europe vector with hexagonal grids and light beams" src="https://cdn.mos.cms.futurecdn.net/zHcjrcoxJqcY5UDouneP5Q.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-and-legislation/is-the-uk-us-data-bridge-doomed-to-fail">Is the UK-US data bridge doomed to fail?</a></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-and-legislation/do-big-tech-fines-make-a-difference">Do Big Tech fines make a difference?</a></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-and-legislation/new-sec-rules-around-data-breach-disclosures-arrive-on-monday-heres-what-you-need-to-know">New SEC rules around data breach disclosures arrive on Monday – here&apos;s what you need to know</a></p></div></div><p>“While it’s true that technology regulation in the EU – spanning from the mature GDPR to novel AI Act – is not 100% perfect, it’s still better than the convoluted patchwork of state legislation on privacy and <a href="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures">data protection</a> matters in the US, which are only partially addressed by pretty obsolete US federal laws and regulations.”</p><p>Kolochenko noted the two regions’ approaches to tech regulation are “innately incompatible’. </p><p>The result of this incompatibility, Kolochenko fears, will be a punitive response from the US.</p><p>“US tech companies and other industries concerned by the extensive and arguably harsh EU regulations will probably lobby for a legislative response to make European companies pay a high price for doing business on American soil,” he said. </p><p>“This outcome will be highly undesirable and counterproductive for both the US and EU. The ideal solution would be to find a middle ground approach to sustainably <a href="https://www.itpro.com/strategy/23583/who-should-control-innovation">regulate innovation</a> and technology that would peacefully coexist on both sides of the Atlantic.”</p><h2 id="how-will-the-digital-markets-act-affect-us-tech-firms">How will the Digital Markets Act affect US tech firms?</h2><p>The Chamber of Progress, a US-based technology industry trade group, has hit out at EU legislation, including the Digital Services Act and <a href="https://www.itpro.com/business/policy-legislation/368435/what-is-the-eus-digital-markets-act-dma">Digital Markets Act</a>, arguing that the latter will force companies to limit their products at the expense of foreign competitors. </p><p>The lobby group has called on the Biden administration to provide greater support for US-based firms, who it suggested could be put at a significant disadvantage in European markets. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="oWoz7SrSXnsswimF7CnyyW" name="Ten must-have capabilities for ZTNA_listing.jfif.jpg" caption="" alt="Whitepaper cover with title and logo over image of female colleague wearing glasses looking at a smartphone" src="https://cdn.mos.cms.futurecdn.net/oWoz7SrSXnsswimF7CnyyW.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zscaler)</span></figcaption></figure><p class="fancy-box__body-text"><em>Discover why Zscaler ZTNA is ahead of the rest.</em><br><br><a data-analytics-id="inline-link" href="https://www.itpro.com/security/want-to-secure-your-hybrid-workforce-with-ztna">DOWNLOAD NOW</a></p></div></div><p>“By imposing rules on their services but not those of foreign competitors, the DMA would effectively mandate top US firms offer products to consumers that are less secure, less useful, and less innovative than rival products from foreign tech companies”.</p><p>The DMA will designate five US tech majors including Alphabet, <a href="https://www.itpro.com/tag/amazon">Amazon</a>, Apple, Meta, and <a href="https://www.itpro.com/software/microsoft">Microsoft</a>, as ‘gatekeeper’ service providers, who will be subject to stricter requirements to open up their messaging platforms.</p><p>Claims the DMA is not specifically targeting non-US firms are not strictly accurate, as the Chinese tech company <a href="https://www.itpro.com/marketing-comms/social-media/356607/bytedance-investors-value-tiktok-at-50-billion-in-acquisition">Bytedance</a>, owner of video hosting service TikTok, is also included on the European Commission’s list of designated service providers. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why Mistral AI could be Europe’s answer to US dominance ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence/why-mistral-ai-could-be-europes-answer-to-us-dominance</link>
                                                                            <description>
                            <![CDATA[ Mistral AI has raised a significant amount of investment amid a meteoric rise ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">29v6s8yixPBtDAgXebbVFk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Sh2vmMAyc94k5yzwGv46D9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 12 Dec 2023 15:12:06 +0000</pubDate>                                                                                                                                <updated>Tue, 12 Dec 2023 15:56:22 +0000</updated>
                                                                                                                                            <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is a staff writer at ITPro, ChannelPro, and CloudPro, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                        <dc:contributor><![CDATA[ Rory Bathgate ]]></dc:contributor>
                                                                    <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Sh2vmMAyc94k5yzwGv46D9-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Mistral AI co-founder and CEO Arthur Mensch]]></media:description>                                                            <media:text><![CDATA[Mistral AI co-founder and CEO Arthur Mensch]]></media:text>
                                <media:title type="plain"><![CDATA[Mistral AI co-founder and CEO Arthur Mensch]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Sh2vmMAyc94k5yzwGv46D9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>French startup Mistral AI has rapidly emerged as one of Europe’s leading AI industry darlings, having recently secured a $415 million Series A funding round. </p><p>With the funding propelling the company’s value to around $2 billion, this raises the question of whether Mistral AI can truly position itself as Europe’s equivalent to <a href="https://www.itpro.com/technology/artificial-intelligence/openai-could-fast-become-a-money-pit-for-investors">OpenAI</a>, which it has been keen to impress in recent months.</p><p>In the wake of the funding round, co-founder and CEO Arthur Mensch specifically targeted the goal of “creating a European champion” in the generative AI space. A bold statement given the monumental task that European companies often face in competing with US hyperscaler-backed giants.</p><p>However, at present everything points toward this goal being very much within the company’s grasp. Mistral’s foundations, its backers, and its approach to generative AI could be a key differentiator for the firm in a post-AI Act environment.</p><p>The French startup was co-founded by former members of <a href="https://www.itpro.com/software/google/demis-hassabis-the-man-behind-google-deepmind-commits-to-ethical-ai">Google DeepMind</a> and Meta, and its rise to prominence has been impressive so far.</p><p>Within just a month of launching, it raised $112 million in seed funding and boasts some serious VCs and industry heavyweights as notable backers.</p><p>Andreessen Horowitz led the recent Series A funding scoop while firms such as Salesforce, General Catalyst, and BNP Paribas all participated in the round.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="i82riUzZ98oP93VKyMVrFn" name="AI_Brain_Stock_Image_GettyImages-1609437924 (1).jpg" caption="" alt="Generative AI concept art featuring a glass human brain on digital background" src="https://cdn.mos.cms.futurecdn.net/i82riUzZ98oP93VKyMVrFn.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/google-gemini-shows-tech-giant-is-still-in-the-generative-ai-race-as-model-outperforms-gpt-4">Google Gemini shows tech giant is still in the generative AI race as model outperforms GPT-4</a></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/openai-could-fast-become-a-money-pit-for-investors">OpenAI could fast become a money pit for investors</a></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/public-cloud/competitor-mudslinging-at-reinvent-suggests-aws-is-sweating">Competitor mudslinging at re:Invent shows AWS is sweating</a></p></div></div><p>What sets the company apart from contemporaries across the pond is that its objectives center around creating an “open, responsible, and decentralized approach” to <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai">generative AI</a>, according to Mensch.</p><p>In September, the company unveiled its first large language model, dubbed ‘Mistral 7B’.</p><p>The 7.3 billion parameter model doesn’t quite match the performance capabilities of <a href="https://www.itpro.com/technology/artificial-intelligence-ai/368288/what-is-gpt-4">GPT-4</a>, or Anthropic’s <a href="https://www.itpro.com/technology/artificial-intelligence/anthropic-just-released-claude-21-and-it-offers-more-than-double-the-token-capacity-of-gpt-4">Claude 2</a> models. But it does outperform both of Meta’s Llama 2 13B and 34B models across a range of benchmarks.</p><p>The decision to make this model publicly available could prove a master stroke. This <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> approach to LLM access has proven popular so far this year, most notably with the release of <a href="https://www.itpro.com/technology/artificial-intelligence/metas-llama-2-is-the-first-free-chatgpt-competitor-but-experts-rebut-open-source-claims">Meta’s Llama 2</a> model.</p><p>In an announcement coinciding with the a16z investment raise, the Parisian tech firm also launched its Mixtral 8x7B model, which has been released publicly under the Apache 2.0 license.</p><p>This most certainly appears to be Mistral’s attempt to contend with platforms such as <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369965/what-is-chatgpt-and-what-does-it-mean-for-businesses">ChatGPT</a> or <a href="https://www.itpro.com/technology/artificial-intelligence-ai/370018/googles-bard-billion-strong-user-base-challenge-chatgpt">Google Bard</a>.</p><h2 id="maybe-mistral-ai-needs-a-patron">Maybe Mistral AI needs a patron</h2><p>Mistral AI’s success so far paints a promising picture for its future prospects. But what it boasts in dynamism it may lack in industry backers at present. </p><p>A quick glance across the Atlantic and one can’t help but think it has a significant uphill battle if it’s to truly contend with OpenAI or Anthropic, for example. Both are backed by a number of industry heavyweights, and the funding pouring into these firms over 2023 has been astounding to say the least.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="25iuj5eeHVLdW4QiUACdx9" name="Anthropic_Claude_GettyImages-1737213579.jpg" caption="" alt="Anthropic Claude logo displayed on a smartphone with company logo in background" src="https://cdn.mos.cms.futurecdn.net/25iuj5eeHVLdW4QiUACdx9.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/anthropic-could-be-the-champion-aws-and-google-need">Anthropic could be the champion AWS and Google need</a></p></div></div><p>Microsoft has <a href="https://www.itpro.com/business/business-strategy/369850/microsofts-10b-openai-investment-could-end-ai-competition">backed OpenAI to the tune of around $13 billion</a>, with $10 billion of that coming in 2023 alone. Anthropic, meanwhile, boasts AWS and Google as key backers as the pair look to the startup to bridge gaps with Microsoft.</p><p>AWS announced <a href="https://www.itpro.com/technology/artificial-intelligence/aws-invests-dollar4-billion-in-anthropic-to-improve-bedrock-experience">plans to invest up to $4 billion in Anthropic</a> in September as part of a deal to make AWS its primary cloud provider. That was followed by $1.5 billion in funding from Google on top of an original $500 million investment earlier in the year.</p><p>With cash like this pouring into US-based firms, the prospects don’t look quite so promising.</p><h2 id="cost-might-be-the-game-changer">Cost might be the game changer</h2><p>Companies embracing generative AI have quickly realized that it’s a costly affair. </p><p>Research earlier this year from CCS Insight predicted a “cold shower” for generative AI in 2024 <a href="https://www.itpro.com/technology/artificial-intelligence/prohibitive-generative-ai-costs-could-pose-challenges-for-firms-in-2024-analysts-warn">due to skyrocketing costs</a>.</p><p>Mistral’s open source approach, however, does offer benefits. These models are typically cheaper to deploy compared to proprietary models such as ChatGPT or Claude.</p><p>In its Series A announcement this week, a16z specifically highlighted the fact that open source approaches enable developers to build “cheaper, faster, and safer software infrastructure”.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="GBLQds7Cg9vJWqxRpKLJAi" name="Four cyber security use cases for AI_listing.jpg" caption="" alt="A webinar from Cloudflare on cyber security for AI" src="https://cdn.mos.cms.futurecdn.net/GBLQds7Cg9vJWqxRpKLJAi.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Cloudflare)</span></figcaption></figure><p class="fancy-box__body-text"><em>Discover how your security team can increase productivity with AI</em> </p><p class="fancy-box__body-text"><br><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-computing/four-cyber-security-use-cases-for-ai">WATCH NOW</a></p></div></div><p>But does Mistral AI really offer this? Its model benchmarks appear to meet expectations due to the fact it uses a “router network” to streamline processes.</p><p>Mixtral, for example, has around 45B total parameters but only uses 12B parameters per token, according to the firm. This means that the model “processes input and generates output at the same speed and for the same cost as a 12B model”.</p><p>“This technique increases the number of parameters of a model while controlling cost and latency, as the model only uses a fraction of the total set of parameters per token,” the firm said in a <a href="https://mistral.ai/news/mixtral-of-experts/">blog post</a>.</p><h3 class="article-body__section" id="section-eu-ai-regulation-could-hamstring-mistral-ai"><span>EU AI regulation could hamstring Mistral AI</span></h3><p>Mistral AI represents one of the standout companies in the sector for the whole EU. While the lawmakers across the EU have finally <a href="https://www.itpro.com/technology/artificial-intelligence/eu-hammers-out-deal-on-ai-act-but-it-may-have-missed-the-mark"><u>come to an agreement on the AI Act</u></a>, much is left to be debated. </p><p>France, Germany, and Italy caused friction in the EU in November as the <a href="https://www.itpro.com/technology/artificial-intelligence/france-germany-and-italy-align-themselves-on-ai-regulation-but-the-eu-may-not-like-it"><u>countries signed an agreement</u></a> on voluntary AI regulation, specifically relating to foundation models.</p><p>Lawmakers from the countries have expressed their doubts about the impact of the EU AI Act on the innovation landscape within Europe, with the former French secretary for the digital economy Cédric O having warned that undue bureaucracy arising from the EU AI Act could kill Mistral AI entirely.</p><p>For the moment, the firm sits at the eye of the storm in Europe. There are some standout nations, with France and Germany standing guard over Mistral and the German startup Aleph Alpha, respectively. But unlike its American counterparts, this period of calm could be short-lived.</p><p>It’s likely that Mistral will have to continue to comply with future agreements around AI regulation in the EU.</p><p>There’s no question that the EU’s risk-based approach comes with benefits to consumer privacy, and many in the sector have praised it for its cautious approach to a technology that, unchecked, could entrench societal biases or put the data of EU citizens at risk. </p><p>The problem is that firms playing fair by these rules will still have to compete with US firms with first-mover advantage such as OpenAI and Anthropic, who face a comparatively lax regulatory environment.</p><p>Through firms like Mistral AI, the EU’s arguments that the AI Act doesn’t unfairly inhibit AI innovation could be put to the test – the region’s sovereign AI sector hangs in the balance.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The EU just launched a €1.2 billion cloud project to crack US dominance ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-computing/the-eu-just-launched-a-euro12-billion-cloud-project-to-crack-us-dominance</link>
                                                                            <description>
                            <![CDATA[ State aid from seven countries will provide support boost competition with US providers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">urWfbYbJqkD7U5FLGdzafF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/d63amyUPCZFoGA47cq73qH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 06 Dec 2023 14:15:43 +0000</pubDate>                                                                                                                                <updated>Wed, 06 Dec 2023 15:20:26 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Computing]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/d63amyUPCZFoGA47cq73qH-1280-80.jpg">
                                                            <media:credit><![CDATA[Santiago Urquijo/Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[European Union flags at Berlaymont building of the European Commission in Brussels, Belgium]]></media:description>                                                            <media:text><![CDATA[European Union flags at Berlaymont building of the European Commission in Brussels, Belgium]]></media:text>
                                <media:title type="plain"><![CDATA[European Union flags at Berlaymont building of the European Commission in Brussels, Belgium]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/d63amyUPCZFoGA47cq73qH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The EU has approved state aid of up to €1.2 billion for a cloud and edge computing project across Europe in a bid to compete more effectively with the US.</p><p>The scheme, called IPCEI Next Generation Cloud Infrastructure and Services (IPCEI CIS), has been backed by France, Germany, Hungary, Italy, the Netherlands, Poland, and Spain, and is aimed at creating the first interoperable and openly accessible European data processing ecosystem.</p><p>Nineteen companies, including several <a href="https://www.itpro.com/tag/smb">SMBs</a>, will be involved, helping to develop data processing capabilities, along with software and data sharing tools to enable federated, energy-efficient and trustworthy cloud and <a href="https://www.itpro.com/cloud/31389/what-is-edge-computing">edge</a> distributed data processing technologies.</p><p>Companies involved in the project include Atos, Orange, Deutsche Telekom, Siemens, Telecom Italia and Telefonica Espana.</p><p>Commissioner Didier Reynders, head of the EU’s competition policy, said the scheme aims to drive “highly ambitious research” to bolster support for EU-based companies.</p><p>"This Important Project of Common European Interest is the first one in the cloud and edge computing domain. The participating member states provide up to €1.2 billion in public funding, expected to unlock an additional €1.4 billion in private investments," he said.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="jRy6pk2zz9gc5TYQ4TNQq7" name="Cloud_stock_Image_GettyImages-1408906928.jpg" caption="" alt="A virtual image of a cloud in light blue on a dark blue background signifying public cloud" src="https://cdn.mos.cms.futurecdn.net/jRy6pk2zz9gc5TYQ4TNQq7.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/public-cloud/competitor-mudslinging-at-reinvent-suggests-aws-is-sweating">Competitor mudslinging at re:Invent suggests AWS is sweating</a><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-computing/mercedes-f1-accelerates-ai-adoption-in-off-track-it-transformation-project">Mercedes F1 accelerates AI adoption in off-track IT transformation project</a><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-computing/aws-joins-google-in-calling-out-restrictive-microsoft-cloud-practices">AWS joins Google in calling out restrictive Microsoft cloud practices</a></p></div></div><p>"The IPCEI will provide for highly ambitious research, necessary to enable the uptake of innovative data processing applications and services for European businesses, public administrations, and citizens."</p><p>The plan is to develop <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> software that will allow for real-time and low-latency services, EU lawmakers said, with individual projects covering the entire cloud edge continuum, from the basic software layer to sector-specific applications.</p><p>There will be several areas of focus. The first, Cloud Edge Continuum Infrastructure, looks to update existing technology to work with new applications, including developing <a href="https://www.itpro.com/software/open-source/open-source-software-attacks-everything-you-need-to-look-out-for">open source software</a> to help cloud service edge nodes from various providers interoperate.</p><p>There are also plans to develop open source software that enables businesses to form their own private clouds by pooling resources from various <a href="https://www.itpro.com/infrastructure/data-centres">data centers</a>.</p><p>Advanced Smart Data Processing Tools and Services covers cross-industry cloud and edge services, along with AI models that can process text and multimedia in various languages and provide platforms to simplify developing <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>applications.</p><p>And finally, Advanced Applications are aimed at using these technologies in specific fields such as the energy, health, and maritime sectors.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="QE4MkrGza49w36z7ny6prY" name="How Roche enables life-changing innovation.jpg" caption="" alt="How Roche enables life-changing innovation webinar" src="https://cdn.mos.cms.futurecdn.net/QE4MkrGza49w36z7ny6prY.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Cloudflare)</span></figcaption></figure><p class="fancy-box__body-text"><em>Watch this on-demand webinar to learn how Roche drives workforce productivity by simply and securely connecting internal users to applications.</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-computing/how-roche-enables-life-changing-innovation"><strong>WATCH NOW</strong></a></p></div></div><p>One company to receive funding is Italy&apos;s Tiscali, which says it will be setting up a lab to develop specific large language models for each European language.</p><p>Deutsche Telecom, meanwhile, will be working on a common European cloud and edge cloud infrastructure.</p><p>"Edge Cloud represents the next frontier in telecommunications and digital infrastructure," said managing director, business customers, Klaus Werner. "With the support of the German government and European partners, we&apos;re not just exploring this frontier; we want to shape and define it."</p><p>The project is expected to create around 1,000 jobs, initially for data scientists and AI specialists, with another 5,000 or so coming during the commercialization phase.</p><p>If projects receiving a large amount of aid turn out to be very successful, generating extra net revenues, a claw-back mechanism means that the companies will return part of the cash.</p><p>R&D and the first industrial deployment phase will last until 2031, with the first result, an open-source reference infrastructure, due around the end of 2027.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ EU AI Act risks collapse if consensus not reached, experts warn ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/eu-ai-act-risks-collapse-if-consensus-not-reached-experts-warn</link>
                                                                            <description>
                            <![CDATA[ Industry stakeholders have warned the EU AI Act could stifle innovation ahead of a crunch decision ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">L6riaeNyWuSeHuQBdxJRVJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UKadY9bbpr7uHiM7VUwopY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 05 Dec 2023 13:41:00 +0000</pubDate>                                                                                                                                <updated>Tue, 05 Dec 2023 15:48:48 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is a staff writer at ITPro, ChannelPro, and CloudPro, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UKadY9bbpr7uHiM7VUwopY-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Close up shot of the flag of the European Union]]></media:description>                                                            <media:text><![CDATA[Close up shot of the flag of the European Union]]></media:text>
                                <media:title type="plain"><![CDATA[Close up shot of the flag of the European Union]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UKadY9bbpr7uHiM7VUwopY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Key questions over the scope and extent of the EU AI Act still remain unanswered and could create uncertainty among businesses, according to legal experts. </p><p>David Dumont, partner at Hunton Andrews Kurth, said there are several elements around which no common ground has yet been established as EU lawmakers approach a critical juncture in negotiations.</p><p>In particular, rules pertaining to the development and use of foundation models and <a href="https://www.itpro.com/technology/artificial-intelligence/sundar-pichai-ai-keeps-me-up-at-night">AI-related harms</a> have not been agreed upon, which could create confusion for businesses and hamper innovation.</p><p>“<a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>presents challenging legal questions and there are still key elements on which the Council and the European Parliament have not found common ground,” he said. “Such as the rules around foundational models and prohibited AI uses.”</p><p>Dumont warned that given the critical stage of negotiations, if no agreement is reached on certain aspects of the legislation, the bill is unlikely to pass before next year’s European elections, representing a significant setback in the union’s attempts to push through the sweeping regulations.</p><p>“December 6th is a key date for the EU AI Act as it is the last political trialogue negotiation that is currently scheduled for the EU AI Act,” he said. “If the EU legislative bodies do not succeed in reaching an agreement at this meeting, it will likely be difficult to pass the EU AI Act before next year’s European Parliament elections.”</p><p>“This would cause a significant delay and possibly result in the EU losing its first mover advantage in regulating AI. “</p><h2 id="eu-ai-act-could-x201c-stifle-innovation-x201d">EU AI Act could “stifle innovation”</h2><p>Industry stakeholders have repeatedly hit out at EU lawmakers over the proposed legislation, with some arguing the bill could stifle innovation unless it delivers a balanced regulatory approach to artificial intelligence. </p><p>Particular concerns have been raised that the proposals could impede smaller enterprises and academics from conducting vital research into the technology.</p><p>Naveen Rao, VP of generative AI at Databricks, warned that reactionary legal efforts to combat AI risks could risk “overregulating AI” and harming European efforts to drive AI innovation.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="zHcjrcoxJqcY5UDouneP5Q" name="digital_europe_concept_GettyImages-1044188400 (1).jpg" caption="" alt="Blue futuristic Europe vector with hexagonal grids and light beams" src="https://cdn.mos.cms.futurecdn.net/zHcjrcoxJqcY5UDouneP5Q.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-and-legislation/european-ai-startups-risk-being-regulated-out-of-existence-under-eu-ai-act">European AI startups risk being “regulated out of existence” under EU AI act</a></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/france-germany-and-italy-align-themselves-on-ai-regulation-but-the-eu-may-not-like-it">France, Germany, and Italy align themselves on AI regulation, but the EU may not like it</a></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-and-legislation/is-the-uk-falling-behind-the-eu-on-ai-regulation">Is the UK falling behind the EU on AI regulation?</a></p></div></div><p>“Any new regulation must not be at the cost of stifling smaller startups and academic researchers from being able to do their work and research”, he said. “The more we understand these models, the more we can share ideas on how to safely shape a future with AI.”</p><p>His comments follow similar concerns regarding the potential impact on smaller firms in recent weeks. In November, tech policy group DigitalEurope said EU-based startups <a href="https://www.itpro.com/business/policy-and-legislation/european-ai-startups-risk-being-regulated-out-of-existence-under-eu-ai-act">could be “regulated out of existence”</a> due to the legislation.</p><p>Rao further warned that the EU must avoid a “rigid, one-size-fits-all approach” to AI regulation and instead focus on a more flexible framework that enables innovation while balancing potential risks.</p><p>“I believe it will be critical for regulators to clearly mark the distinction between AI developers and AI deployers,” he said. “The developer creates the original AI, the deployer puts it into use.”</p><p>This distinction between AI development and deployment has become a political flashpoint in recent weeks amidst member state concerns over the scope of the EU AI Act and its potential impact on individual tech ecosystems.</p><p>In October, France, Germany, and Italy, three of the EU’s leading economies, published a joint paper <a href="https://www.itpro.com/technology/artificial-intelligence/france-germany-and-italy-align-themselves-on-ai-regulation-but-the-eu-may-not-like-it">pledging their support for “mandatory self regulation”</a> of foundation models through the creation of voluntary codes of conduct.</p><p>The joint paper specifically called on EU lawmakers to distinguish between regulating the use of AI tools in society and the regulation of AI technologies themselves.</p><p>Speaking to <em>Reuters </em>at the time, German digital affairs minister Volker Wissing said lawmakers need to “regulate the applications and not the technology” if European economies are to compete on a global scale.</p><h2 id="the-eu-ai-act-has-been-a-repeated-source-of-controversy">The EU AI Act has been a repeated source of controversy</h2><p>The EU AI Act has been a source of controversy in the global technology industry in recent months over claims that the regulations could negatively impact European tech ecosystems. </p><p>The act itself aims to curb the potential risks and harms associated with generative AI, such as misinformation, bias, and its use by cyber criminals to wage sophisticated attacks against enterprises.</p><p>Under the act, lawmakers will categorize models based on their risk factor. This ranges from ‘minimal’ to ‘unacceptable’ and ‘high risk’, and takes into account the potential for AI models to cause harm to both individuals and broader society.</p><p>Rao emphasized that “AI models on their own” are not necessarily ‘high risk’, but noted that developers do have a responsibility to curtail potential harms.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="SBd5rTjoNYFs8m5ExX35RJ" name="Managing Data for AI and Analytics at Scale with an Open Data Lakehouse Approach.jpg" caption="" alt="Managing Data for AI and Analytics at Scale with an Open Data Lakehouse Approach: IBM watsonx.data whitepaper" src="https://cdn.mos.cms.futurecdn.net/SBd5rTjoNYFs8m5ExX35RJ.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><em>Discover how IBM watsonx.data supports a range of current standard technologies </em><br><br><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/managing-data-for-ai-and-analytics-at-scale-with-an-open-data-lakehouse-approach-ibm-watsonxdata">DOWNLOAD NOW</a></p></div></div><p>“<a href="https://www.itpro.com/cloud/370113/aws-and-hugging-face-partner-to-democratise-ml-ai-models">AI models</a> on their own are not “high risk”, and in fact, hold the potential to bring much good,” he said. “However, there will always be those who use new technology irresponsibly, or actively pursue nefarious intent.”</p><p>“That is not to say that developers have no responsibility. They should carry out risk assessment and mitigation, for instance, as well as clear documentation around data sources, <a href="https://www.itpro.com/data-protection/34416/how-to-perform-a-data-protection-impact-assessment-dpia-under-gdpr">impact assessments</a> around possible bias, and so on.”</p><h2 id="eu-ai-act-may-harm-open-source-industry">EU AI Act may harm open source industry</h2><p>Stringent rules placed on open source developers through the EU AI Act have also been a key flashpoint throughout the legislative process so far in 2023. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="i82riUzZ98oP93VKyMVrFn" name="AI_Brain_Stock_Image_GettyImages-1609437924 (1).jpg" caption="" alt="Generative AI concept art featuring a glass human brain on digital background" src="https://cdn.mos.cms.futurecdn.net/i82riUzZ98oP93VKyMVrFn.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/software/open-source/whats-the-eus-problem-with-open-source">What’s the EU’s problem with open source?</a></p></div></div><p>Open source advocates have repeatedly warned that the regulations will harm innovation in the European open source ecosystem.</p><p>A key focus has centered around whether research and testing of AI models could be interpreted as “commercial activity” under the legislation, and therefore subject to stricter rules.</p><p>In July, a consortium of companies including GitHub, Hugging Face, and Creative Commons called for greater flexibility on the testing of <a href="https://www.itpro.com/technology/artificial-intelligence/ai-needs-kill-switch-and-open-source-influence-to-remain-safe-expert-says">open source AI</a> models.</p><p>The group called for EU lawmakers to include more concise definitions of AI components, as well as more leeway for <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> AI research.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Reprieve for open source industry as agreement reached on Cyber Resilience Act ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/reprieve-for-open-source-industry-as-agreement-reached-on-cyber-resilience-act</link>
                                                                            <description>
                            <![CDATA[ The Cyber Resilience Act has been maligned by open source advocates across Europe ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZuWPgaS6m77AYpCfLixCML</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DFxSE87P88iW6pX6P92trE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 04 Dec 2023 12:13:13 +0000</pubDate>                                                                                                                                <updated>Mon, 04 Dec 2023 14:43:19 +0000</updated>
                                                                                                                                            <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is a staff writer at ITPro, ChannelPro, and CloudPro, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DFxSE87P88iW6pX6P92trE-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A CGI render of the EU flag shown as 12 gold stars hovering and creating a ripple effect in a wave of blue data]]></media:description>                                                            <media:text><![CDATA[A CGI render of the EU flag shown as 12 gold stars hovering and creating a ripple effect in a wave of blue data]]></media:text>
                                <media:title type="plain"><![CDATA[A CGI render of the EU flag shown as 12 gold stars hovering and creating a ripple effect in a wave of blue data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DFxSE87P88iW6pX6P92trE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Open source developers have been granted a reprieve after European lawmakers reached an agreement on the terms of the Cyber Resilience Act (CRA). </p><p>An agreement between the EU Parliament and European Council was struck on Thursday 30 November that will fast-track the legislation to its final approval stage.</p><p>Under the CRA, more robust cyber security and resilience rules will require organizations to adhere to minimum standards to protect digital products, such as IoT devices.</p><p>Terms outlined in the regulation will force software and hardware manufacturers to adhere to a 24-hour disclosure rule for security vulnerabilities and provide a minimum five-year guaranteed patch support for products.</p><p>Once introduced, organizations operating in the EU will be required to implement changes to their security practices to comply with the regulation. Those who fail to meet standards within the allocated time frame could be fined up to 2.% of annual turnover. </p><p>Last-minute changes to the CRA mean stringent rules around open source software development will be somewhat relaxed, preventing fears over the bill’s potentially negative impact on the European ecosystem.</p><p>In its current iteration, the CRA will not specifically target open source software developers with stringent rules, according to EU lawmakers.</p><p>“In order not to hamper innovation or research, free and open source software developed or supplied outside the course of a commercial activity should not be covered by this regulation,” the CRA states.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="aEqLCd2eKuD4Zq2b8gRXAb" name="GettyImages-1262670427.jpg" caption="" alt="An abstract image showing a digital padlock on a blue and black futuristic platform" src="https://cdn.mos.cms.futurecdn.net/aEqLCd2eKuD4Zq2b8gRXAb.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-and-legislation/what-is-the-eus-cyber-resilience-act-cra">What is the EU’s Cyber Resilience Act (CRA)?</a> </p></div></div><p>“This is in particular the case for software, including its source code and modified versions, that is openly shared and freely accessible, usable, modifiable and redistributable.”</p><p>Nicola Danti, lead member of the European Parliament, said talks between the EU Parliament and Council will strike an adequate balance between robust regulation and flexibility for the open source ecosystem. </p><p>“We have ensured support for micro and small enterprises and better involvement of stakeholders, and addressed the concerns of the open source community, while keeping an ambitious European dimension," he said.</p><p>"Only together will we be able to tackle successfully the cybersecurity emergency that awaits us in the coming years.”</p><h2 id="open-source-fears-over-the-cyber-resilience-act">Open source fears over the Cyber Resilience Act</h2><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="NcNKbuv42eQsvp88SaeaSE" name="Top SSE Use Cases.jpg" caption="" alt="Top SSE Use Cases" src="https://cdn.mos.cms.futurecdn.net/NcNKbuv42eQsvp88SaeaSE.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zscaler)</span></figcaption></figure><p class="fancy-box__body-text"><em>Read data protection use cases that will stop data breaches</em></p><p class="fancy-box__body-text"><br><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-protection/top-sse-use-cases">DOWNLOAD NOW</a></p></div></div><p>The CRA has been the source of recurring political flashpoints in recent months, with open source figures across the EU voicing serious concerns over its heavy-handed approach to open source development.</p><p>In April, a host of industry bodies criticized the CRA, suggesting that the <a href="https://www.itpro.com/software/open-source/eus-cyber-resilience-act-would-benefit-from-us-open-source-approach">introduction of the legislation would harm innovation</a> across the open source ecosystem across the union.</p><p>A key concern highlighted in this first pushback centered around proposals that would make developers liable for software vulnerabilities. Critics argued that the requirements would have a “chilling effect” on the industry.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="zHcjrcoxJqcY5UDouneP5Q" name="digital_europe_concept_GettyImages-1044188400 (1).jpg" caption="" alt="Blue futuristic Europe vector with hexagonal grids and light beams" src="https://cdn.mos.cms.futurecdn.net/zHcjrcoxJqcY5UDouneP5Q.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/software/open-source/whats-the-eus-problem-with-open-source">What&apos;s the EU&apos;s problem with open source?</a></p></div></div><p>In July, open source advocates once again hit out at the legislation ahead of a crunch vote in the European Parliament, arguing that the CRA <a href="https://www.itpro.com/software/open-source/eu-cyber-resilience-act-a-death-knell-for-open-source-software-critics-warn">represented a “death knell” for open source development</a> in Europe.</p><p>The EU’s unwavering position throughout this period was a source of extreme frustration by members of the community, some of whom suggested that lawmakers were purposefully ignoring legitimate concerns.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Three quarters of UK firms unprepared for NIS2 regulations, study finds ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/three-quarters-of-uk-firms-unprepared-for-nis2-regulations-study-finds</link>
                                                                            <description>
                            <![CDATA[ Senior management can be held personally liable for non-compliance under NIS2 rules ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dcVHNpExNfaSuLcywb7gN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/e6zeYCopy4dSbbjb6kpzhi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 17 Oct 2023 11:08:38 +0000</pubDate>                                                                                                                                <updated>Tue, 17 Oct 2023 14:43:06 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is a staff writer at ITPro, ChannelPro, and CloudPro, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/e6zeYCopy4dSbbjb6kpzhi-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Gold lock floating above a digitally rendered motherboard with blue and red glowing hues, denoting ransomware]]></media:description>                                                            <media:text><![CDATA[Gold lock floating above a digitally rendered motherboard with blue and red glowing hues, denoting ransomware]]></media:text>
                                <media:title type="plain"><![CDATA[Gold lock floating above a digitally rendered motherboard with blue and red glowing hues, denoting ransomware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/e6zeYCopy4dSbbjb6kpzhi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Three-quarters of UK organizations have yet to complete preparations for the EU’s <a href="https://www.itpro.com/business/policy-legislation/370403/what-is-the-network-and-information-security-2-nis2-directive">Network and Information Security Directive</a> (NIS2), according to a new study. </p><p>With just one year to go until the deadline for implementation, a majority of UK organizations are yet to fully address and compensate for the five key compliance requirements outlined in the new regulations, SailPoint found. </p><p>The new rules are an updated version of previous NIS regulations, introduced by the EU in 2018. </p><p>NIS2 essentially aims to build on the previous regulations and implement more robust <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> and resilience standards among EU organizations, as well as more stringent reporting measures in the event of a security incident. </p><p>Under the updated regulations, all public and private entities operating in the EU will be required to adhere to new standards. The regulations specifically target organizations working in <a href="https://www.itpro.com/security/cyber-security/368440/the-new-wave-of-cyber-security-threats-facing-critical-national">critical infrastructure</a> sectors, such as energy, finance, and healthcare. </p><p>SailPoint’s study, based on a survey of 1,500 IT decision makers across the UK, France, and Germany, found that many UK firms have yet to even begin preparations for the new rules. </p><p>Four in five (80%) revealed they still need to properly secure <a href="https://www.itpro.com/strategy/28710/what-is-the-supply-chain-1">supply chains</a> while three-quarters (76%) said they have yet to assess the efficiency of existing cyber security measures.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="VMijHAaX6UXm6jUbbFnym8" name="lock-encryption-security-GettyImages-1485193235.jpg" caption="" alt="Encryption denoted by a series of gold padlocks lined up side-by-side, with the center padlock cracked down the middle, showing a break" src="https://cdn.mos.cms.futurecdn.net/VMijHAaX6UXm6jUbbFnym8.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/361094/the-truth-about-cyber-security-training">The truth about cyber security training</a><a data-analytics-id="inline-link" href="https://www.itpro.com/security/work-related-stress-keeps-cyber-security-professionals-awake-at-night">Work-related stress “keeps cyber security professionals awake at night”</a><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/what-is-business-email-compromise-bec">What is business email compromise (BEC)?</a></p></div></div><p>Three-quarters of organizations also need to add new <a href="https://www.itpro.com/security/do-risk-awareness-and-risk-management-strategies-actually-make-a-difference">risk management</a> measures (74%), implement HR security (76%), or provide <a href="https://www.itpro.com/security/cyber-security/354950/10-ways-to-get-employees-invested-in-cyber-security-awareness">cyber security training</a> to staff (72%). </p><p>SailPoint warned that those who fail to comply with the new obligations could face harsh penalties. Organizations can face fines of up to €10 million for non-compliance, or the equivalent of 2% of their annual turnover. </p><p>“With just one year to go, businesses must put their foot to the floor when it comes to NIS2 compliance and get ahead on their cyber preparation,” said Stephen Bradford, senior vice president for EMEA at SailPoint.</p><p>“The threat landscape has been growing in volume and sophistication over recent years meaning the stakes have never been higher. Operational downtime, <a href="https://www.itpro.com/security/data-breaches/357941/how-much-will-a-data-breach-really-damage-your-organisations">reputational damage</a>, customer loss, and system restoration that follow any breach can cause a real headache for businesses."</p><p>Bradford said the current lax approach among some UK organizations bears similarities to the months preceding the implementation of the EU’s <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">General Data Protection Regulation</a> (GDPR). </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="3Mrwt6j2gxaQmDtBumW5qi" name="Monitoringandloggingrequirements.jpg" caption="" alt="Ultimate guide to monitoring and logging requirements" src="https://cdn.mos.cms.futurecdn.net/3Mrwt6j2gxaQmDtBumW5qi.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Graylog)</span></figcaption></figure><p class="fancy-box__body-text"><em>Comply with multiple regulations and industry standards<br></em><br><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ultimate-guide-to-monitoring-and-logging-requirements">DOWNLOAD NOW</a> </p></div></div><p>He urged that businesses “must learn from GDPR” and use the next 12 months to ensure <a href="https://www.itpro.com/business/policy-and-legislation/what-is-the-eus-cyber-resilience-act-cra">cyber resilience</a> “is at the core of the business models” to avoid falling foul of the regulations. </p><p>This is particularly important given certain aspects of the regulations pertaining to personal liability. </p><p>Under the new rules, senior management could be held liable for cyber security failings and regulatory infringements if their organization does not comply with its obligations. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US-UK data bridge: Everything you need to know ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/us-uk-data-bridge-everything-you-need-to-know</link>
                                                                            <description>
                            <![CDATA[ The US-UK data bridge will ease the complexity of transatlantic data transfers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fmq2xUxu95FGhFLoGWXsWD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sTqDBxxJyaBWeigs99apfY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 12 Oct 2023 09:27:44 +0000</pubDate>                                                                                                                                <updated>Fri, 13 Oct 2023 11:20:16 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is a staff writer at ITPro, ChannelPro, and CloudPro, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sTqDBxxJyaBWeigs99apfY-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The national flags of the United Kingdom and United States pictured side by side against a blue sky backdrop]]></media:description>                                                            <media:text><![CDATA[The national flags of the United Kingdom and United States pictured side by side against a blue sky backdrop]]></media:text>
                                <media:title type="plain"><![CDATA[The national flags of the United Kingdom and United States pictured side by side against a blue sky backdrop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sTqDBxxJyaBWeigs99apfY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US-UK data bridge marks a major step toward easing the complexity of transatlantic data transfers, experts say. </p><p>Coming into effect officially on October 12, the US-UK data bridge forms part of the EU-US Data Privacy Framework, which permits the flow of EU-based data to the United States under certain conditions. </p><p>The framework was formally adopted by EU lawmakers in July 2023, and replaces the <a href="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield">EU-US Privacy Shield</a>, which was deemed invalid by the European Court of Justice in 2020 amidst data privacy concerns. </p><p>In June 2023, the UK and US <a href="https://www.itpro.com/business/policy-and-legislation/atlantic-declaration-expected-to-bring-uk-companies-closer-to-us-economic-sphere">reached an agreement in principle</a> to extend the Data Privacy Framework, creating the data bridge between the two countries.</p><p>Sarah Pearce, partner at the Hunton Andrews Kurth law firm, says the introduction of the data bridge will create a more flexible and streamlined business environment for organizations operating on both sides of the Atlantic. </p><p>“It’s fair to say that the <a href="https://www.itpro.com/security/privacy-shield/367221/eu-and-us-reach-agreement-on-privacy-shield-replacement">EU-US Data Privacy Framework</a> – and the add-on UK-US data bridge – represent critical steps forward in easing the current complexity of transatlantic data transfers and should be heralded as a success,” she says. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LedvtgoMDRvfcTWGyWUQcN" name="Cyber-resilient infrastructure starts with server security_listing.jpg" caption="" alt="Whitepaper from Dell on improving your infrastructure cyber-resilience with server security, with image of colleagues looking at a laptop on the cover" src="https://cdn.mos.cms.futurecdn.net/LedvtgoMDRvfcTWGyWUQcN.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Dell)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Cyber-resilient infrastructure starts with server security</strong></p><p class="fancy-box__body-text"><em>Transform revenue operations through data-driven decision-making.<br></em><br><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/cyber-resilient-infrastructure-starts-with-server-security">DOWNLOAD FOR FREE</a></p></div></div><p>Charlie Bromley-Griffiths, corporate counsel at Conga, echoes Pearce’s comment, but warns that businesses will be forced to assign a greater focus to data management and protection from now on. </p><p>“This sets the tone for the future of business. From here onwards, enterprises will need to be scrupulous with their data management and ensure they have the right measures in place to comply with the new regulations. </p><p>“A lot has changed in the last year, with the Electronic Trade Documents Act, [Northern Ireland] Protocol data sharing agreement and the Schrems II legislation all coming into effect; organizations will need to review their data architecture and contract clauses with their customers and partners.”</p><h2 id="the-us-uk-data-bridge-explained">The US-UK data bridge explained</h2><p>The data bridge essentially permits the flow of UK data to another country without the need for further safeguards, according to the UK government. </p><p>In this instance, the data bridge takes into account the level of protection provided by the recipient country – the US – and its handling of UK data.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="VGzkXrzhdDXaUHzZM6tc5L" name="GettyImages-1471976069.jpg" caption="" alt="A CGI image of cubes rippling at slightly varying heights, each marked with a '1', a '0', or the image of an orange padlock to represent data security. It is lit in blue and purple light." src="https://cdn.mos.cms.futurecdn.net/VGzkXrzhdDXaUHzZM6tc5L.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-and-legislation/eu-us-data-transfer-framework-will-be-overturned-within-five-years-says-expert">EU-US Data Transfer Framework will be overturned within five years, says expert</a><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/370216/uks-new-data-protection-bill-more-cosmetic-than-substantive">UK’s new data protection bill “more cosmetic than substantive”, experts warn</a><a data-analytics-id="inline-link" href="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield">What is EU-US Privacy Shield?</a></p></div></div><p>The UK government is satisfied current US data protection and privacy regulations are adequate to support the data bridge, and that personal data will be protected to a level on-par with the <a href="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018">Data Protection Act 2018</a>.</p><p>“The US data bridge will ensure that high standards of protection for personal data are maintained when the data is sent to certified US organisations,” the government said in an explainer on the issue. “Any US company that elects to receive UK data under the data bridge will be required to maintain those standards.”</p><p>Initially, concerns around <a href="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures">data protection</a> and privacy practices in the US were a key stumbling block for EU regulators,  especially the potential use of data for surveillance purposes. </p><p>Long-term, the UK government believes the establishment of the data bridge will unlock growth for businesses, enabling them to share information for research and support science and innovation in both the UK and US. </p><h2 id="us-uk-data-bridge-lingering-concerns">US-UK data bridge: Lingering concerns</h2><p>Pearce said that questions surrounding the data bridge still remain, particularly among privacy rights campaigners such as Max Schrems. </p><p>The campaigner has argued that changes made to US data privacy rules to accommodate for the framework “do not address fundamental surveillance issues”, Pearce added. </p><p>“It’s very likely that this type of criticism will provide ammunition to potential [legal] challenges, and we should expect that the courts will, again, be asked to assess whether the new safeguards are sufficient to be considered essentially equivalent to the safeguards in the EU and the UK,” she said. </p><p>“Schrems has already publicly stated he will appeal the adequacy decision in respect of the framework,” Pearce added. “Whether such challenges will be successful, however, is another matter.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New EU vulnerability disclosure rules deemed an "unnecessary risk" ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/new-eu-vulnerability-disclosure-rules-deemed-an-unnecessary-risk</link>
                                                                            <description>
                            <![CDATA[ The vulnerability disclosure rules in the Cyber Resilience Act could also cause a “chilling effect” on security researchers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MnPfY9eKivMtiVPeb4ZAEF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nqVGsNQ7iiMUyLf5u8sgFW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 03 Oct 2023 09:45:00 +0000</pubDate>                                                                                                                                <updated>Tue, 03 Oct 2023 12:51:16 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is a staff writer at ITPro, ChannelPro, and CloudPro, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nqVGsNQ7iiMUyLf5u8sgFW-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images/John Lamb]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A close up image of the flag of the European Union featuring 12 stars]]></media:description>                                                            <media:text><![CDATA[A close up image of the flag of the European Union featuring 12 stars]]></media:text>
                                <media:title type="plain"><![CDATA[A close up image of the flag of the European Union featuring 12 stars]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nqVGsNQ7iiMUyLf5u8sgFW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>New vulnerability disclosure requirements in the EU’s <a href="https://www.itpro.com/business/policy-and-legislation/what-is-the-eus-cyber-resilience-act-cra">Cyber Resilience Act</a> (CRA) could create unnecessary risks for consumers and businesses, security experts have warned.</p><p>In an open letter signed by senior figures at more than 50 organizations, experts said that aspects of Article 11 in the CRA are “counterproductive and will create new threats that undermine the security of digital products and the individuals who use them”.</p><p>Article 11 of the CRA will require software publishers to disclose unpatched vulnerabilities to the European Union Agency for Cybersecurity (ENISA) within 24 hours of exploitation. Information on vulnerabilities would then be passed on to various government agencies responsible for member state security. </p><p>The requirement means that software providers will essentially feed known vulnerabilities into a “real-time database” containing information on unpatched flaws to provide agencies with an overview of ongoing or potential <a href="https://www.itpro.com/uk/security">security</a> issues. </p><p>This move is part of an effort from EU lawmakers to speed up vulnerability disclosures, ensure greater transparency and accountability, and ultimately protect consumers. </p><p>However, critics of the move argue this places organizations at heightened risk by having a repository of unmitigated vulnerabilities that could be targeted by threat actors. </p><p>The open letter also suggests that the move could prompt a trend of “rushing the disclosure process”, which places greater strain on security practitioners and software providers and could result in <a href="https://www.itpro.com/security/19607/microsoft-pulls-patch-following-botched-security-update"><u>botched patches</u></a>.  </p><div  class="fancy-box"><div class="fancy_box-title">READ MORE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="DFxSE87P88iW6pX6P92trE" name="GettyImages-923485692.jpg" caption="" alt="A CGI render of the EU flag shown as 12 gold stars hovering and creating a ripple effect in a wave of blue data" src="https://cdn.mos.cms.futurecdn.net/DFxSE87P88iW6pX6P92trE.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/software/open-source/eu-cyber-resilience-act-a-death-knell-for-open-source-software-critics-warn">Cyber Resilience Act a "death knell" for open source community</a><a data-analytics-id="inline-link" href="https://www.itpro.com/software/open-source/eus-cyber-resilience-act-would-benefit-from-us-open-source-approach">EU&apos;s Cyber Resilience Act would benefit from US approach to open source</a><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-and-legislation/what-is-the-eus-cyber-resilience-act-cra">What is the EU&apos;s Cyber Resilience Act? </a></p></div></div><p>“Dozens of government agencies would have access to a real-time database of software with unmitigated vulnerabilities, without the ability to leverage them to protect the online environment and simultaneously creating a tempting target for malicious actors,” the letter reads.</p><p>“There are several risks associated with rushing the disclosure process and having a widespread knowledge of unmitigated vulnerabilities.”</p><p>The “risk of exposure to malicious actors” is a key concern highlighted in the open letter. </p><p>The potential for breaches and exploitation of vulnerabilities recorded by government agencies aren’t merely a “theoretical threat” and could place organizations in the cross-hairs of threat actors while scrambling to issue patches, the letter adds.</p><p>“Breaches and the subsequent misuse of government held vulnerabilities are not a theoretical threat but have happened at some of the best protected entities in the world,” the letter reads.</p><p>“While the CRA does not require a full technical assessment to be disclosed, even the knowledge of a vulnerability&apos;s existence is sufficient for a skillful person to reconstruct it.”</p><p>Alex Rice, co-founder and CTO at <a href="https://www.itpro.com/security/cyber-security/368797/darktrace-partners-with-hackerone-to-bring-ai-to-attack-resistance"><u>HackerOne</u></a> and a signatory of the open letter said the proposed reporting practices could create a “strong incentive” for threat actors to target specific government agencies. </p><p>“HackerOne is an advocate for vulnerability disclosure, but that disclosure must be done responsibly and cannot open organizations to more <a href="https://www.itpro.com/security/28133/what-is-cyber-security"><u>cyber security</u></a> risk,” he said. </p><p>“Reporting highly sensitive data into only a handful of EU government agencies creates a strong incentive for bad actors to breach those hubs and acquire vulnerabilities to attack susceptible organizations — among a whole host of other risks.”</p><h2 id="article-11-x201c-goes-against-reporting-best-practices-x201d">Article 11 “goes against reporting best practices”</h2><p>Rice acknowledged that reporting obligations are necessary to ensure transparency and improve security, adding that the “intentions of the Cyber Resilience Act are great”. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LedvtgoMDRvfcTWGyWUQcN" name="Cyber-resilient infrastructure starts with server security_listing.jpg" caption="" alt="Whitepaper from Dell on improving your infrastructure cyber-resilience with server security, with image of colleagues looking at a laptop on the cover" src="https://cdn.mos.cms.futurecdn.net/LedvtgoMDRvfcTWGyWUQcN.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Dell)</span></figcaption></figure><p class="fancy-box__body-text"><em>Read this study on the continuing need for server security and the challenges organizations face in fully securing their servers.</em><br><br><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/cyber-resilient-infrastructure-starts-with-server-security"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>However, the proposed requirements “conflict with vulnerability reporting best practices” and as such should be amended. </p><p>The open letter outlined a series of proposed revisions to Article 11 to accommodate factors such as severity of vulnerabilities and the likelihood of exploitation by threat actors.</p><p>This includes a recommendation that mandatory reporting requirements should be changed to within 72 hours of “effective mitigation” to prevent the risk of exploitation. </p><p>“We support this obligation, but also advocate for a responsible and coordinated disclosure process that balances the need for transparency with the need for security,” the letter reads.</p><p>“We recommend that the CRA adopt a risk-based approach to vulnerability disclosure, taking into account factors such as the severity of the vulnerability, the availability of mitigations, the potential impact on users, and the likelihood of broader exploitation.”</p><h2 id="article-11-could-have-x201c-chilling-effect-x201d-on-security-researchers">Article 11 could have “chilling effect” on security researchers</h2><p>Casey Ellis, founder and CTO at BugCrowd and signatory of the open letter, told <em>ITPro </em>that disclosure requirements could have a “chilling effect” on good faith security researchers and <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained"><u>white hat hackers</u></a>. </p><p>The potential impact on security researchers was highlighted in the open letter, which warned that, in its current form, the Act could “prematurely interfere with the coordination and collaboration between software publishers and security researchers”. </p><p>Tight deadlines for disclosure set by the CRA fail to recognize the time required to verify, test, and patch vulnerabilities before revealing them publicly, the letter argued. </p><p>Ellis told <em>ITPro</em> that this aspect of the Act could create “friction” for <a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker"><u>security researchers</u></a> and their willingness to engage in activities such as bug hunting. </p><p>In addition, the requirements could complicate managing reports from the researchers community and make organizations less receptive to good-faith security research. </p><p>“We’ve spent the past 10 years basically trying to remove friction and it’s been a struggle, so I think anything that comes in and re-introduces friction is a bad thing.” </p><p>“People that hack in good faith are here to act as the internet’s immune system, and the internet, for the better part, has had an auto-immune deficiency that we’re now climbing out of.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Are you ready for NIS2? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/are-you-ready-for-nis2</link>
                                                                            <description>
                            <![CDATA[ Find out what you should be doing to prepare for the EU’s latest data protection regulation and UK equivalent with our free webinar ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7S9vQLuohckhafmcxJXrYJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BAHuQxqbAF8uxzdUdGRiy9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sun, 17 Sep 2023 20:18:36 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ dale.walker@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/JpDGYSnD7yNNModq5jFThm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                    <sponsoredContent>true</sponsoredContent>
                                <cf:isSponsored>true</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BAHuQxqbAF8uxzdUdGRiy9-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A young woman looking at her phone with an urban cityscape in the background at sunset]]></media:description>                                                            <media:text><![CDATA[A young woman looking at her phone with an urban cityscape in the background at sunset]]></media:text>
                                <media:title type="plain"><![CDATA[A young woman looking at her phone with an urban cityscape in the background at sunset]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BAHuQxqbAF8uxzdUdGRiy9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>There’s a saying in security that criminals only have to get lucky once to count a success. This is as true in cyber security and data protection as it is anywhere else – organizations need to be on alert and ready to defend against a possible attack every minute of every hour of every day. There is, sadly, no respite.</p><p>Companies don’t have to face this challenge alone, though; governments, regulatory bodies and the wider security industry are increasingly collaborating to introduce best practice and legislation to help increase everyone’s security posture.</p><p>One example of this is the NIS2 Directive, which was created by the European Commission in January 2023 with the aim of boosting cyber security across the European Union. It expands on the existing NIS Directive to include new sectors and entities, improving the resilience and incident response capacities of public and private organizations alike. Members of the 27-nation bloc have until 17 October 2024 to transpose the directive into their own legislation and the UK government has also confirmed it plans to update its NIS regulations as well.</p><p>With so much to consider, ITPro, in association with Rubrik, bring you an informative webinar to offer you real-world guidance and insight.</p><p>Madeline Bennett, ITPro’s Contributing Editor will be joined by Richard Cassidy, Field CISO at Rubrik to:</p><ul><li>Help businesses understand more about the latest updates around the NIS2 EU Directive including what will – and won’t – be covered by it.</li><li>Learn why we all need to take this new directive more seriously, starting now. </li><li>Explore how Rubrik's products can help organizations align it's compliance with EMEA regulations such as the NIS 2 Directive.</li></ul><p>To hear all this and more, <a href="https://event.on24.com/wcc/r/4345995/35AA7843868FE7727CB44FB595B15645"><u>register for the webinar today</u></a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What's the EU's problem with open source? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/whats-the-eus-problem-with-open-source</link>
                                                                            <description>
                            <![CDATA[ The open source community has raised concerns about a raft of new regulatory changes in the EU in recent months ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9CQAupnBWyNX5hEMi8didd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zHcjrcoxJqcY5UDouneP5Q-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 28 Jul 2023 13:00:00 +0000</pubDate>                                                                                                                                <updated>Mon, 31 Jul 2023 12:19:45 +0000</updated>
                                                                                                                                            <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zHcjrcoxJqcY5UDouneP5Q-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Blue futuristic Europe vector with hexagonal grids and light beams]]></media:description>                                                            <media:text><![CDATA[Blue futuristic Europe vector with hexagonal grids and light beams]]></media:text>
                                <media:title type="plain"><![CDATA[Blue futuristic Europe vector with hexagonal grids and light beams]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zHcjrcoxJqcY5UDouneP5Q-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The open source community is very much at a critical juncture amid a period of regulatory uncertainty in the EU, with new legislation posing a threat to the industry. </p><p>This week, a consortium of companies including GitHub, Creative Commons, and Hugging Face published a <a href="https://github.blog/wp-content/uploads/2023/07/Supporting-Open-Source-and-Open-Science-in-the-EU-AI-Act.pdf" target="_blank"><u>policy paper</u></a> aimed at EU regulators requesting greater support for open source AI development in the upcoming AI Act. </p><p>The coalition outlined a series of suggestions for EU lawmakers in the paper, making a number of requests. These included more concise definitions of AI components and greater support and leeway for open source research into the development of AI models. </p><p>A key focus here centers around whether research and testing of AI models will be interpreted as “commercial activity” and thus subject to stringent rules under the act. </p><p>Under the proposed EU guidelines, real-world testing of AI systems will not be granted exemption from the regulations, which the companies argued could be inhibitive to innovation and prove costly for enterprises. </p><p>Instead, the coalition suggested a change in language to accommodate for testing which is done “on a limited scale with sufficient documentation and transparency to users”. </p><p>“Research and development (R&D) is crucial to the development of beneficial, trustworthy <a href="https://www.itpro.com/strategy/28181/what-is-ai"><u>AI systems</u></a>,” the paper reads. </p><p>“The act should recognize that some real-world testing, including preliminary exploration of a model’s appropriateness to specific deployment conditions and allowing scrutiny and evaluation by relevant civil society organizations outside of the development chain, can be necessary and appropriate for R&D.”</p><h2 id="warranted-criticism">Warranted criticism</h2><p>The policy paper is by no means a scathing criticism of the AI Act, but does contain suggestions on how regulators and open source developers might foster a closer relationship that fuels innovation. </p><p>However, the paper does warn that, based on its current iteration, the Act risks creating “impractical barriers” for contributors in the ecosystem. </p><p>“The AI Act holds promise to set a global precedent in regulating AI to address its risks while encouraging innovation,” the paper reads. </p><p>“By supporting the blossoming open ecosystem approach to AI, the regulation has an important opportunity to further this goal through increased transparency and collaboration between stakeholders.”</p><p>“Unfortunately, current proposals threaten to create impractical barriers to and disadvantages for contributors to this open ecosystem,” it added. </p><p>Peter Chichon, senior policy manager at GitHub, one of the leading voices in this discussion with regulators, warned in a <a href="https://github.blog/2023-07-26-how-to-get-ai-regulation-right-for-open-source/" target="_blank"><u>blog post</u></a> that the act risks “chilling open source AI development” and undermining “responsible innovation” across the union. </p><h2 id="long-running-concerns">Long-running concerns</h2><p>Given recent clashes between regulators and the community, the move from GitHub et al should be welcomed and provide food for thought among lawmakers in the EU who appear determined to stifle open source innovation. </p><p>This isn’t the first time industry stakeholders have, justifiably, raised concerns about restrictive policies from the union. </p><p>The Brookings think tank published a report criticizing the proposals in September last year warning that the act would seriously undermine open source AI development and harm developers. </p><p>Similarly, earlier this month, Wikipedia founder Jimmy Wales and OpenUK chief executive Amanda Brock suggested that the act’s stringent rules for open source developers could harm broader European AI ambitions and <a href="https://www.itpro.com/technology/artificial-intelligence/wikipedia-co-founder-warns-that-the-usa-could-run-away-with-ai-development"><u>enable the US to “outpace” Europe in the space</u></a>. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="g9YYJ2DwunXRzNtkVLDSMS" name="The business value of IBM AI-powered automation solutions_listing.jpg" caption="" alt="Whitepaper with title, IDC logo, contributors photos, and background digital globe graphic" src="https://cdn.mos.cms.futurecdn.net/g9YYJ2DwunXRzNtkVLDSMS.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><strong>The business value of IBM AI-powered automation solutions</strong></p><p class="fancy-box__body-text"><em>Discover the IT improvements businesses are seeing with the adoption of automation.</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/369403/the-business-value-of-ibm-ai-powered-automation">DOWNLOAD FOR FREE</a></p></div></div><p>Speaking during a roundtable discussion, Brock described the act as “very prescriptive” and suggested that exemptions for open source development “don’t go far enough”. </p><p>“It’s not going to work,” she said. </p><p>With such strong pushback - and repeated pushback from industry figureheads - EU regulators could be faced with the prospect of curtailing worrisome aspects of the legislation. </p><p>But will it work? History tells us otherwise. Ahead of GDPR implementation in 2018, EU lawmakers fought off a wave of complaints and concerns from the industry and continued to steam ahead with plans. </p><p>The EU has already brushed off complaints from industry big-hitters such as OpenAI, whose CEO Sam Altman warned earlier this year that the company could be forced to ‘pull out of Europe’ due to aspects of the regulation. </p><p>Altman’s comments were met with a fierce response from lawmakers and later prompted a u-turn from the chief executive in a debacle that highlighted the unwavering resolve of regulators. </p><h2 id="clashing-heads-with-regulators">Clashing heads with regulators</h2><p>This current call to action also bears similarities to other battles we’ve seen between the open source community and regulators in recent months. </p><p>In April, 13 open source industry bodies penned an open letter to EU lawmakers voicing concerns over the Cyber Resilience Act (CRA), arguing that aspects of the legislation would <a href="https://www.itpro.com/software/open-source/eus-cyber-resilience-act-would-benefit-from-us-open-source-approach"><u>harm the open source community across Europe</u></a>. </p><p>The letter, signed by Linux Foundation Europe, the Open Source Initiative (OSI), and the Eclipse Foundation, said the proposals would have a “chilling effect” on open source software due to rules that would leave developers liable for software vulnerabilities. </p><p>More recently, critics once again reared their heads ahead of a crunch vote in the European Parliament on the cyber act, claiming that in its current form, the legislation <a href="https://www.itpro.com/software/open-source/eu-cyber-resilience-act-a-death-knell-for-open-source-software-critics-warn"><u>represents a “death knell” for open source</u></a> in Europe. </p><p>Despite this, MEPs on the Industry Committee nonetheless voted to back the draft bill, with 61 votes to 1 and 10 abstentions. </p><p>Once again, lawmakers in the EU proved their resolve and reaffirmed their apparent disregard for the concerns raised by members of the open source community. </p><p>This all begs the question of whether the EU views the open source industry as a valuable player within the broader technology landscape. While regulations are being pushed to protect consumers and businesses alike, there is no denying that significant pressure is being placed on the open source community, which offers valuable economic benefits. </p><p>Millions of businesses spanning all 27 member states rely on open source software in their day-to-day operations. The vital applications and platforms that represent the lifeblood of the European tech economy are maintained by a dedicated community of developers, who in the EU’s eyes it seems cannot be trusted. </p><p>With the European Parliament voting to adopt its position on the AI Act in June, time is fast running out for the open source community to see any meaningful changes implemented by lawmakers. </p><p>And if the EU’s approach to the Cyber Resilience Act is anything to go by, it’s likely that the industry will be ignored and have stifling changes imposed on it that harm developers and long-term innovation.</p><p>Critics of EU regulations have warned that developers may choose to “back out” of projects as a result of the potential penalties, threatening one of the most celebrated corners of the industry.</p><p>Gabriele Columbro, general manager for the Linux Foundation in Europe, told <em>ITPro </em>in April that this could become a reality as contributors seek to avoid being “slapped with lawsuits”. </p><p>If this proves to be the case, then the open source community, which is already <a href="https://www.itpro.com/cloud/cloud-computing/building-human-connections-key-to-cloud-native-success"><u>stretched and becoming increasingly burnt out</u></a>, could enter a dark period - and that spells trouble for innovation in Europe, undoubtedly harming businesses. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Wikipedia co-founder warns that the USA could run away with AI development ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence/wikipedia-co-founder-warns-that-the-usa-could-run-away-with-ai-development</link>
                                                                            <description>
                            <![CDATA[ Jimmy Wales and OpenUK fear EU regulations could stifle open-source AI ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QejRrhrszgmVpT5mBYE3o9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7DZGnbuekvDAXavdUMMp2h-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 19 Jul 2023 10:27:41 +0000</pubDate>                                                                                                                                <updated>Mon, 31 Jul 2023 10:44:27 +0000</updated>
                                                                                                                                            <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                <author><![CDATA[ richard.speed@futurenet.com (Richard Speed) ]]></author>                    <dc:creator><![CDATA[ Richard Speed ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9i9jXkpYyoBCECh2PbJBGP.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7DZGnbuekvDAXavdUMMp2h-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A cross fade between the US flag in the bottom left half of the frame, and the EU flag in the top right of the frame.]]></media:description>                                                            <media:text><![CDATA[A cross fade between the US flag in the bottom left half of the frame, and the EU flag in the top right of the frame.]]></media:text>
                                <media:title type="plain"><![CDATA[A cross fade between the US flag in the bottom left half of the frame, and the EU flag in the top right of the frame.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7DZGnbuekvDAXavdUMMp2h-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Wikipedia co-founder Jimmy Wales has warned that the EU risks being outpaced by the US on AI development because of the stringent legislative approach it’s adopting with the rapidly developing technology.</p><p>Referencing the EU’s approach with its proposed AI Act, he said it represented the ‘typical’ attitude taken by the Union whenever it wants to control a potentially harmful technology.</p><p>“The EU AI act is going to be a classic European attempt to regulate something that’s just going to completely leave Europe behind the US.”</p><p>Wales’ comments were made during a roundtable discussion at which Amanda Brock, CEO at OpenUK, was also present.</p><p>Brock agreed with Wales regarding the dramatic pace of change over recent months. She called for an agile approach to legislation that was flexible and could adapt as AI evolved.</p><p>With the Wikipedia co-founder in agreement, Brock warned that AI regulation in the EU would present issues, saying: “It’s very prescriptive, it’s very detailed, it’s going to be very hard to follow and the open-source exclusions don’t go far enough”.</p><p>“It’s not going to work,” she said.</p><h2 id="what-is-the-eu-ai-act">What is the EU AI Act?</h2><p>The purpose of the act is to regulate the use of <a href="https://www.itpro.com/strategy/28181/what-is-ai" target="_blank"><u>AI</u></a> in the EU. At a high level, <a href="https://www.europarl.europa.eu/news/en/headlines/society/20230601STO93804/eu-ai-act-first-regulation-on-artificial-intelligence" target="_blank">it aims</a> to ensure that AI systems in the EU are “safe, transparent, traceable, non-discriminatory and environmentally friendly”.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LRrgzsXGoa6Lpzkz6LcgbX" name="AI and cyber security_listing.jpg" caption="" alt="Purple whitepaper cover with white text over background image of suited female wearing glasses" src="https://cdn.mos.cms.futurecdn.net/LRrgzsXGoa6Lpzkz6LcgbX.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><strong>AI and cyber security</strong></p><p class="fancy-box__body-text"><em>Read why AI/ML is crucial to cyber security, how it fits in, and its best use cases</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-crime/ai-and-cyber-security"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Significantly, the European Parliament also wants to ensure that AI systems are overseen by people rather than automation in order “to prevent harmful outcomes”. </p><p>It also wishes to establish a technology-neutral, uniform definition for AI that has future applications.</p><p>The concern regarding the EU’s plans is around the inhibitive effect of regulation. </p><p>Brock noted that existing regulations already concern the handling of data depending on the use case - citing healthcare and finance as examples - and said “the amount of regulation around AI itself should probably be quite light and minimal”.</p><p>While the <a href="https://www.itpro.com/business/policy-legislation/369539/jeremy-hunts-autumn-statement-harnesses-brexit-freedoms-to-grow">UK is no longer part of the EU</a>, the actions taken by the Union and the flow of AI venture capital are two points of concern.</p><h2 id="the-uk-ai-and-open-source">The UK, AI, and open source</h2><p>According to <a href="https://openuk.uk/wp-content/uploads/2023/07/FINAL-State-of-Open-The-UK-in-2023-Phase-Two-Part-2-1.pdf" target="_blank"><u>OpenUK’s report</u></a>, the Organisation of Economic Cooperation and Development (OECD) - using data from GitHub - found that the UK was the third largest contributor to public AI projects, accounting for 4% in 2022. India was top at 23%, and the 27 EU member states and the USA accounted for 14% each.</p><p>So far in 2023, the UK has received $29.2 billion in venture capital investment for AI, an 8.8% increase over 2022. The US’s total so far of $461.4 billion, however, stands 20.7% over its 2022 figure. The numbers indicate the UK still has a way to go before it can truly declare itself a leader in global AI.</p><p>The report also examined attitudes towards AI and how it intersects with open source.</p><p>For example, although 40% of respondents to the State of Open Survey 2023 said that <a href="https://www.itpro.com/software/28109/what-is-open-source"><u>open source</u></a> software offered a solution to concerns regarding AI ownership, 45% were neutral on the matter.</p><p>Transparency was seen as hugely important to respondents, with 85% of them saying that datasets used to train an AI should be included in the software bill of materials (SBOM), while only 2% disagreed.</p><p>Brock told <em>ITPro</em> she was concerned that AI was in a similar position to other key technologies developed over the last few decades. She said that unless action was taken to “open it up and democratize it” there was every chance it might end up in the hands of a few.</p><p>She said: “The fundamental decision to be made is a simple one”. </p><p>“Will our government’s approach be one of control established through transparency and building trust engendered by openness, or will it be a decision to seek control by closing down innovation, thereby leaving the outputs of this most important of innovations, in a proprietary ‘black box’ without <a href="https://www.itpro.com/technology/artificial-intelligence-ai/355130/why-transparency-is-key-to-promoting-trust-in">transparency</a>?”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ EU Cyber Resilience Act a ‘death knell’ for open source software, critics warn ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/open-source/eu-cyber-resilience-act-a-death-knell-for-open-source-software-critics-warn</link>
                                                                            <description>
                            <![CDATA[ Critics of the act claim that requirements for open source software usage could severely impact the community ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">AAxzxed8nPEVvXrDtfgzo8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZwjLR4hENrgCoR4hQkQPyE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Jul 2023 11:39:50 +0000</pubDate>                                                                                                                                <updated>Thu, 27 Jul 2023 14:51:33 +0000</updated>
                                                                                                                                            <category><![CDATA[Open Source]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZwjLR4hENrgCoR4hQkQPyE-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[EU Cyber Resilience Act: EU flag superimposed on a techybackground which looks liek a motherboard with staggered raised platforms all across it]]></media:description>                                                            <media:text><![CDATA[EU Cyber Resilience Act: EU flag superimposed on a techybackground which looks liek a motherboard with staggered raised platforms all across it]]></media:text>
                                <media:title type="plain"><![CDATA[EU Cyber Resilience Act: EU flag superimposed on a techybackground which looks liek a motherboard with staggered raised platforms all across it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZwjLR4hENrgCoR4hQkQPyE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The EU’s proposed Cyber Resilience Act could spell disaster for the open source community, with critics describing the legislation as a ‘death knell’ for the industry. </p><p>Brian Fox, CTO at Sonatype, said that in its current form, the act risks “severely undermining” open source projects across the union and poses a serious threat to security and sustainability in the ecosystem. </p><p>Fox’s comments come ahead of a crucial EU vote on the future of the act on Wednesday, which could see developers held liable for software vulnerabilities. </p><p>Critics are now calling for lawmakers to caution restraint and have urged MEPs to vote against the bill in its current draft. </p><p>“In its current form, the Cyber Resilience Act risks being a death knell to <a href="https://www.itpro.com/software/28109/what-is-open-source"><u>open source</u></a>, severely undermining both its security and sustainability,” he said. </p><p>“If the current course isn’t changed before the upcoming vote, we are at risk of an open source software crisis in the EU, which would be catastrophic for our digital economy, innovation, and security.</p><p>“We are calling on EU citizens to implore their MEPs to vote against the Act and help fix this mess. It is now the eleventh hour in the race to save open source.”</p><h2 id="punishing-open-source-developers">Punishing open source developers</h2><p>A focal point of the Cyber Resilience Act centers around liability for open source developers. In its current iteration, developers may be held accountable for vulnerabilities in software. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="bX5esErTtRUnpitYAht92M" name="cybercriminals are resilient_listing.jpg" caption="" alt="Cyber Criminals are resilient; whitepaper cover with image of man working at a laptop" src="https://cdn.mos.cms.futurecdn.net/bX5esErTtRUnpitYAht92M.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ServiceNow)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Cybercriminals are resilient. How about you?</strong></p><p class="fancy-box__body-text"><em>Understand how your adversaries operate and establish a clear roadmap for cyber security.</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cybercriminals-are-resilient-how-about-you"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Given that <a href="https://www.itpro.com/open-source/31406/is-open-source-open-for-business"><u>open source software is used by businesses</u></a> across the Union, critics argue that potential penalties and compliance requirements could prompt contributors to back out of projects. And long-term, this could seriously harm the ecosystem. </p><p>This aspect of the bill has led to a long-running dispute between the European open source community and legislators, Fox said, with back-and-forth discussions on the matter resulting in little change. </p><p>Earlier this year, an <a href="https://newsroom.eclipse.org/news/announcements/open-letter-european-commission-cyber-resilience-act" target="_blank"><u>open letter</u></a> signed by several industry stakeholders, including the Linux Foundation Europe, warned that the bill would have a “chilling effect” on open-source development and the community. </p><p>In April, Gabriele Columbro, general manager for the Linux Foundation in Europe, told <em>ITPro </em>that many contributors across Europe were <a href="https://www.itpro.com/software/open-source/eus-cyber-resilience-act-would-benefit-from-us-open-source-approach"><u>worried they could be “slapped with lawsuits”</u></a> and “decide not to put a project in the open” as a result.</p><p>Fox echoed this sentiment, suggesting that EU lawmakers have a “narrow outlook” on the benefits of open source and that they have been unwilling to compromise with the community in recent months. </p><p>“It is hugely worrying that legislators are ignoring the industry’s voice,” he said. “The EU has approached the issue of software security with a narrow outlook and has failed to address the concerns raised”. </p><h2 id="pro-innovation-legislation">Pro-innovation legislation</h2><p>Fox specifically highlighted the US’ Cyber Security Strategy as an example of how legislators can work in closer alignment with the open source community. </p><p>Unveiled in February, the sweeping security legislation excluded liability for open source developers and projects. At the time, this was <a href="https://www.itpro.com/security/370185/us-national-cyber-strategy-allays-fears-liability-for-open-source-vulnerabilities"><u>welcomed by industry stakeholders</u></a> and hailed as a pro-innovation approach. </p><p>“This is in contrast to the attitude of the US government, which has consistently given the open source industry a voice in its cyber security initiatives. Some of us in the industry have been working for more than six months to try to prevent the impending open source disaster in the EU.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ EU-US Data Transfer Framework will be overturned within five years, says expert ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/eu-us-data-transfer-framework-will-be-overturned-within-five-years-says-expert</link>
                                                                            <description>
                            <![CDATA[ Gartner VP analyst dubs the adequacy ruling “Déjà EU”, citing lack of transparency over remediation ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vGtszAeCbgUiawRKKMdAmj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7DZGnbuekvDAXavdUMMp2h-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 11 Jul 2023 11:52:17 +0000</pubDate>                                                                                                                                <updated>Tue, 11 Jul 2023 13:58:29 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7DZGnbuekvDAXavdUMMp2h-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A cross fade between the US flag in the bottom left half of the frame, and the EU flag in the top right of the frame.]]></media:description>                                                            <media:text><![CDATA[A cross fade between the US flag in the bottom left half of the frame, and the EU flag in the top right of the frame.]]></media:text>
                                <media:title type="plain"><![CDATA[A cross fade between the US flag in the bottom left half of the frame, and the EU flag in the top right of the frame.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7DZGnbuekvDAXavdUMMp2h-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The European Commission has adopted the adequacy decision for the EU-US Data Privacy Framework after years of talks, but experts have indicated it will struggle to uphold it in court.</p><p>In its decision announced on 10 July, the Commission found that the US upholds a level of protection comparable to that of the EU when it comes to the transfer of personal data. </p><p>Companies that comply with the extensive requirements of the framework can access a streamlined path for transferring data from the EU to the US without the need for extra data protection measures.</p><p>The framework is likely to face legal action and be overturned, according to Nader Henein, research VP of privacy and data protection at Gartner.</p><p>“It takes one step closer to what the European Court of Justice needs, but it takes one where the Court of Justice needs it to take five, or ten steps,” Henein told <em>ITPro</em>.</p><p>“Maximilian Schrems already said he was going to do it, and if not him someone else will like the EFF or multiple privacy groups. What we’re telling our clients is two to five years, depending on who raises the request, when they raise it, and who they use.”</p><p>A potential legal challenge could move more swiftly if the individual complaint was made against a known entity such as Facebook, which was the subject of the Schrems II verdict that took down the old framework known as <a href="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield"><u>Privacy Shield</u></a>.</p><p>Schrems has posted a series of tweets comparing the new adequacy agreement to Privacy Shield, and vowed to fight it in the courts.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr">The "new" EU-US Data Privacy Framework is sooo much a 1:1 copy of the #PrivacyShield -- they even forgot to rename the link in the footer: https://t.co/SyamOFdpSq https://t.co/K68gkM3XTz pic.twitter.com/yB90jbtPix<a href="https://twitter.com/maxschrems/status/1678038200391016449">July 9, 2023</a></p></blockquote><div class="see-more__filter"></div></div><p>Henein said businesses are being advised to use the next two years to set up plans that are not dependent on the EU-US Data Privacy Framework, and noted that many firms will be approaching suppliers to demand they protect against more expensive disruption.</p><p>The European Commission has stated the framework will be subjected to regular reviews, with a check that the US side of the framework is operating as intended expected within 12 months.</p><p>Unlike the EU, which has the <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know"><u>GDPR</u></a>, the US has no federal data protection scheme. It often leans on the fourth amendment, which protects US citizens from “unreasonable searches and seizures” as a precedent for the conduct of law enforcement, but this does not apply to EU citizens.</p><p>While the framework is in effect, compliant companies will be able to transfer data without the need for costly additional assessments, which could prove especially beneficial for cross-Atlantic collaboration.</p><p>“The EU-US Data Privacy Framework is a positive development in the mission to protect individuals and organizations on both sides of the Atlantic against cyber threats,” said Drew Bagley, VP and counsel, privacy and cyber policy at CrowdStrike.</p><p>“Modern IT infrastructure, cyber security, and privacy compliance programs are dependent upon global data flows.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="7Ho3MxBjFHBxdW56QCzrmU" name="Creating a proactive, risk-aware defence in today's dynamic risk environment_listing.jpg" caption="" alt="Whitepaper cover with green title over image of a glasses-wearing businessman looking at the camera holding a laptop" src="https://cdn.mos.cms.futurecdn.net/7Ho3MxBjFHBxdW56QCzrmU.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ServiceNow)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Creating a proactive, risk-aware defence in today&apos;s dynamic risk environment</strong></p><p class="fancy-box__body-text"><em>Learn how a common risk management language can improve enterprise resilience</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/risk-management/370019/creating-a-proactive-risk-aware-defence-in-todays-dynamic"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>“Data localization is not a substitute for data protection, and the new Framework stands in sharp contrast to some policy and certification proposals that mistakenly prioritize localizing data over protecting would-be victims from breaches. </p><p>“This marks an opportunity to accelerate the G7’s Data Free Flow with Trust initiative and ensure defenders have the tools they need to defend against cyber attacks.”</p><p>From 2016 to 2020, transfers between the EU and US had been covered by the regulatory framework Privacy Shield. This worked as an adequacy agreement between the EU and US, with the US having promised to oversee the deletion of unneeded data.</p><p>In July 2020 the <a href="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism"><u>European Court of Justice invalidated Privacy Shield</u></a>, having ruled that it was not compatible with the rights afforded to non-US citizens regarding surveillance and data collection in the name of national security.</p><p>The EU-US Data Privacy Framework seeks to address these concerns with new safeguards in place for EU citizens. </p><p>President Biden signed an <a href="https://www.whitehouse.gov/briefing-room/statements-releases/2022/10/07/fact-sheet-president-biden-signs-executive-order-to-implement-the-european-union-u-s-data-privacy-framework/" target="_blank"><u>executive order</u></a> in October 2022 which brought in new restrictions and measures of redress for intelligence service activities.</p><p>One of the foremost concerns with transferring EU data to the US has historically been that US intelligence services would be able to access and use sensitive data belonging to EU citizens.</p><p>Under the new agreement, intelligence entities will only be able to access data in a manner proportionate to protecting national security. </p><p>Under the framework, EU citizens will also be given access to an impartial, independent mechanism for redress over the use of data by US intelligence agencies overseen by a new Data Protection Review Court (DPRC).</p><p>Complaints will be free to make, and citizens will not be required to produce evidence that their data was collected by an intelligence agency in order for the complaint to be looked into.</p><p>Ursula von der Leyen, President of the European Commission praised the “unprecedented commitments to establish the new framework” taken by the US.</p><p>But Henein argued that there is nowhere near enough transparency, and argued that as the surveillance redress process appears to happen behind closed doors it is unlikely to satisfy privacy concerns.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Swedish privacy concerns result in fines over Google Analytics ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/google/swedish-privacy-concerns-result-in-fines-over-google-analytics</link>
                                                                            <description>
                            <![CDATA[ Swedish privacy authority ordered companies to stop using the ubiquitous web traffic analysis tool, in line with recent EU rulings ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oMwm4eZJ7eC9YHR8W3EACN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rkVUpVq6DbvTDHqcw4wRDT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Jul 2023 10:42:10 +0000</pubDate>                                                                                                                                <updated>Tue, 04 Jul 2023 11:55:12 +0000</updated>
                                                                                                                                            <category><![CDATA[Google]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ richard.speed@futurenet.com (Richard Speed) ]]></author>                    <dc:creator><![CDATA[ Richard Speed ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9i9jXkpYyoBCECh2PbJBGP.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rkVUpVq6DbvTDHqcw4wRDT-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google Analytics logo displayed on a smartphone]]></media:description>                                                            <media:text><![CDATA[Google Analytics logo displayed on a smartphone]]></media:text>
                                <media:title type="plain"><![CDATA[Google Analytics logo displayed on a smartphone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rkVUpVq6DbvTDHqcw4wRDT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Swedish Authority for Privacy Protection (IMY) has issued fines against companies over the use of Google Analytics.</p><p>Four companies were handed complaints alleging the transfer of personal data to the United States via Google Analytics, a tool for measuring and analyzing traffic on websites.</p><p>The fines issued to the four companies together exceeded $1.1 million after the IMY concluded that their practices violated recent EU privacy rulings.</p><p>Three of the four companies were ordered to stop using Google Analytics for web statistics, while one had recently stopped on its own initiative.</p><p>Coop, Tele2, Dagens Industrie, and CDON were audited by the authority, and while none had technical security measures deemed sufficient, it was Tele2 to which a 12 million SEK ($1.1 million) fine was issued. A 300,000 SEK ($27,700) fine was issued to CDON.</p><p>Coop and Dagens Industrie had taken some protective measures, and Tele2 had already stopped using the tool.</p><p>The action was taken following complaints from the organization None of Your Business (NYOB) and come in light of the <a href="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism"><u>Schrems II ruling</u></a> by the Court of Justice of the European Union (CJEU).</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="j9SfGKiJe4VP7Gb4Ycon6D" name="Top data security trends_listing.jpg" caption="" alt="Whitepaper cover with cartoon character wearing digital armour stood in front of a bar/line graph with mobile phone featuring image of female wearing glasses" src="https://cdn.mos.cms.futurecdn.net/j9SfGKiJe4VP7Gb4Ycon6D.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Salesforce)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Top data security trends</strong></p><p class="fancy-box__body-text"><em>Must-have tools for your data security toolkit</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-protection/top-data-security-trends"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>In the 2020 <a href="https://www.itpro.com/security/privacy-shield/356470/european-court-invalidates-primary-eu-us-data-transfer-mechanism"><u>Schrems II judgement</u></a>, the CJEU declared the European Commission’s <a href="https://www.itpro.com/safe-harbour/34529/what-is-eu-us-privacy-shield"><u>Privacy Shield</u></a> decision invalid on account of what it called invasive US surveillance programs. </p><p>The ruling effectively made the transfer of personal data on the basis of the Privacy Shield illegal.</p><p>It also stipulated stricter requirements for the transfer of personal data on the basis of <a href="https://www.itpro.com/data-insights/data-management/354423/eu-us-data-transfer-tools-used-by-facebook-ruled-legal"><u>standard contract clauses</u></a>, granting a level of protection essentially equivalent to that guaranteed by the General Data Protection Regulation (GDPR).</p><p>In this case, the authority considered that the data transferred to the US via Google Analytics by the audited companies was personal data since it could be linked with other unique data transferred. </p><p>“By the fact that IMY has decided on these cases at the same time, it is made clear what requirements are placed on technical security measures and other measures when transferring personal data to a third country, in this case the United States,” said Sandra Arvidsson, IMY’s legal advisor, who led the audits of the companies.</p><p>“These decisions have implications not only for these four companies, but can also provide guidance for other organizations that use Google Analytics.”</p><p>The audits themselves concern a version of <a href="https://www.itpro.com/business-strategy/30403/how-to-use-google-analytics"><u>Google Analytics</u></a> from 14 August 2020.</p><p>A Google spokesperson said to <em>ITPro: </em>“Google Analytics helps publishers understand how well their sites and apps are working for their visitors – but not by identifying individuals or tracking them across the web”. </p><p>“These organizations, not Google, control what data is collected with these tools, and how it is used. Google helps by providing a range of safeguards, controls, and resources for compliance."</p><p>Google and Microsoft - as well as other tech giants - have taken steps to reassure European users of data sovereignty and privacy in recent years.</p><p>At the beginning of 2023, Microsoft began the phased rollout of the <a href="https://www.itpro.com/cloud/cloud-computing/369720/microsofts-eu-data-boundary-rollout-january-2023"><u>EU Data Boundary for Microsoft Cloud</u></a>, aimed at permitting customers to store and process data within the EU Data Boundary for <a href="https://www.itpro.com/business-operations/productivity/368062/10-best-features-of-microsoft-365-for-small-businesses"><u>Microsoft 365</u></a>, <a href="https://www.itpro.com/microsoft-azure/34048/microsoft-azure-review-competitive-cloud-pricing-takes-a-bite-out-of-aws"><u>Azure</u></a>, Power Platform, and Dynamics 365 services.</p><p>In 2022, Google announced <a href="https://www.itpro.com/policy-legislation/data-protection/367575/google-to-add-more-workspace-data-transfer-controls"><u>Sovereign Controls for Google Workspace</u></a> to control, limit and monitor transfers of data to and from the EU. </p><p>Google Analytics, however, continues to operate <a href="https://www.itpro.com/business/business-strategy/four-trends-influencing-the-future-of-cloud-data-centers-and-edge-infrastructure"><u>data centers</u></a> globally - including the United States - but user IP addresses are anonymized depending on customer configuration. Its latest analytics product, Google Analytics 4, does not store IP addresses.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ EU regulators are digging their heels in despite big tech’s Data Act pushback  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-protection/eu-regulators-are-digging-their-heels-in-despite-big-techs-data-act-pushback</link>
                                                                            <description>
                            <![CDATA[ EU regulators are no strangers to big tech regulatory push back, so why do companies still persist? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nPMZQpRtxGJq9npkSu5zZh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/d63amyUPCZFoGA47cq73qH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 23 Jun 2023 12:20:47 +0000</pubDate>                                                                                                                                <updated>Mon, 26 Jun 2023 14:36:00 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/d63amyUPCZFoGA47cq73qH-1280-80.jpg">
                                                            <media:credit><![CDATA[Santiago Urquijo/Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[European Union flags at Berlaymont building of the European Commission in Brussels, Belgium]]></media:description>                                                            <media:text><![CDATA[European Union flags at Berlaymont building of the European Commission in Brussels, Belgium]]></media:text>
                                <media:title type="plain"><![CDATA[European Union flags at Berlaymont building of the European Commission in Brussels, Belgium]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/d63amyUPCZFoGA47cq73qH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>EU regulators have once again hit back at big tech criticism of regulatory changes in what marks the latest tit-for-tat battle ahead of the pending Data Act. </p><p>Amid concerns the legislation could harm tech companies, Thierry Breton, European commissioner for internal markets, will say it’s expected to do the exact opposite. </p><p>Lawmakers won’t shift their stance either despite the mounting opposition from big tech, according to the draft text of a speech set to be delivered in San Francisco this week. </p><p>“Our European data strategy is to unlock a wealth of big data and set out how that data should be shared, stored, and processed. This will benefit all businesses – European, American, and others alike,” he is expected to say, and will add: “Assertiveness is not protectionism.”</p><h2 id="why-tech-companies-are-fighting-the-data-act">Why tech companies are fighting the Data Act</h2><p>The Data Act aims to prevent non-EU governments from accessing data processed by firms operating within the union. Rules outlined in the act will apply to both corporate and consumer data, and are applicable to a range of services and products, such as smart technologies and industrial machinery. </p><p>Some US companies, however, warn the legislation could have a negative impact on international data transfers and create additional cost burdens for companies that operate across borders. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="j9SfGKiJe4VP7Gb4Ycon6D" name="Top data security trends_listing.jpg" caption="" alt="Whitepaper cover with cartoon character wearing digital armour stood in front of a bar/line graph with mobile phone featuring image of female wearing glasses" src="https://cdn.mos.cms.futurecdn.net/j9SfGKiJe4VP7Gb4Ycon6D.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Salesforce)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Top data security trends</strong></p><p class="fancy-box__body-text"><em>Must-have tools for your data security toolkit</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-protection/top-data-security-trends"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>US firms aren’t alone in leveling criticism. Last month, Siemens and SAP suggested the act could <a href="https://www.reuters.com/technology/siemens-sap-say-eu-draft-data-act-puts-trade-secrets-risk-2023-05-07/"><u>compromise “trade secrets”</u></a> due to provisions requiring companies to collaborate with third parties to ensure regulatory compliance. </p><p>In an open letter to Breton, EU antitrust chief Margrethe Vestager, and Commission president Ursula von der Leyen, German companies opposed to the act said it “risks undermining European competitiveness by mandating data sharing”. </p><p>"Effectively, this could mean that EU companies will have to disclose data to third-country competitors, notably those not operating in Europe and against which the Data Act&apos;s safeguards would be ineffective," the letter read.</p><h2 id="pushing-back-against-regulation">Pushing back against regulation</h2><p>This criticism marks the latest in a long-running trend of big tech companies across the world pushing back against pending EU legislative changes.</p><p>Earlier this year, a number of industry stakeholders, most notably OpenAI, slammed the EU’s long-awaiting AI Act, branding it too restrictive and potentially inhibiting operations within the union. </p><p>OpenAI CEO Sam Altman sparked controversy after suggesting the firm could be forced to “leave Europe” if the act was approved as it stood. While Altman <a href="https://www.itpro.com/technology/artificial-intelligence/sam-altman-reverses-threat-to-leave-europe-over-ai-regulations"><u>swiftly reneged on the threat</u></a> and clarified OpenAI’s commitment to Europe, the comments drew harsh criticism from Breton. </p><p>Breton told <em>Reuters </em>at the time the AI rules are aimed specifically to safeguard the “security and well-being of our citizens” and insisted that changes “cannot be bargained”. He stressed the EU has been ahead of the curve in “designing a solid and balanced regulatory framework” in the interests of safety but also so Europe can “become a frontrunner in trustworth AI”.  </p><p><a href="https://www.itpro.com/cloud/367052/data-sovereignty-a-boon-for-msps"><u>Data sovereignty</u></a> rules in the EU have also been in the crosshairs for non-EU firms, with the cyber security labeling rules <a href="https://www.itpro.com/cloud/370204/eu-cloud-proposals-discriminatory-reatliatory-tariffs"><u>described as “discriminatory”</u></a> against international firms in recent months. </p><h2 id="big-tech-resistance-is-futile">Big tech resistance is futile</h2><p>Such pushback has a common theme: time and time again they fall flat. </p><p>The first real acid test for this was prior to the implementation of GDPR, which received a significant degree of resistance from firms within the union and internationally. </p><p>Similarly, cookie legislation and data-sharing rules in the wake of the Schrems cases, which saw companies such as Facebook hint they’d back out of the EU, fizzled out with a whimper. </p><p>It appears tech companies haven’t learned their lesson. EU lawmakers are steadfast in their position and unrelenting in their attempts to implement regulations that benefit member states and citizens. </p><p>For regulators to suddenly u-turn at the slightest hint of pushback would be disastrous from a political perspective. Companies, too, with even the slightest bone to pick would smell blood and pounce on future proposals. </p><p>This raises questions over why organizations continue to try so hard to water down legislation. There are <a href="https://www.itpro.com/technology/artificial-intelligence/why-are-ai-innovators-pushing-so-hard-for-regulation"><u>two differing tactics</u></a> at play – playing tough and cozying up – both of which aim to temper potential regulatory crackdowns.</p><p>Altman’s hardline approach backfired. But around the same time Microsoft president Brad Smith outlined how the organization planned to develop a responsible framework for <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai"><u>generative AI</u></a> development. This approach showed a more measured approach that could curry favor with regulators. </p><p>With the draft Data Act pending, organizations pushing back will likely find their criticism – which sometimes seems more like spitting out the dummy than offering constructive input – will come to no avail. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Oracle unveils ‘sovereign cloud’ region for EU customers amid lingering sovereignty worries ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-management/oracle-unveils-sovereign-cloud-region-for-eu-customers-amid-lingering-sovereignty-worries</link>
                                                                            <description>
                            <![CDATA[ Providers are scrambling to comply with pending data sovereignty regulations in Europe ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iktfKTCPy7vB9xSzCfKPJo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/d63amyUPCZFoGA47cq73qH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 20 Jun 2023 10:37:29 +0000</pubDate>                                                                                                                                <updated>Mon, 24 Jun 2024 14:46:06 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Management]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/d63amyUPCZFoGA47cq73qH-1280-80.jpg">
                                                            <media:credit><![CDATA[Santiago Urquijo/Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Oracle sovereign cloud: European Union flags at Berlaymont building of the European Commission in Brussels, Belgium]]></media:description>                                                            <media:text><![CDATA[Oracle sovereign cloud: European Union flags at Berlaymont building of the European Commission in Brussels, Belgium]]></media:text>
                                <media:title type="plain"><![CDATA[Oracle sovereign cloud: European Union flags at Berlaymont building of the European Commission in Brussels, Belgium]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/d63amyUPCZFoGA47cq73qH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Oracle has announced plans to launch its long-awaited <a href="https://www.itpro.com/cloud/cloud-computing/what-is-a-sovereign-cloud">sovereign cloud</a> region for customers in the European Union (EU). </p><p>The company said its new EU Sovereign Cloud will enable private and public sector organizations across the union to gain “more control over data privacy and sovereignty requirements”.</p><p>Described as one of the first cloud offerings specifically designed to address pending regulatory changes, the new cloud region will be located entirely within the EU, Oracle said. </p><p>Similarly, the region will be supported by EU-based personnel and operated by separate legal entities within the union. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="6WzyXULWqGfc74RXXW3QnH" name="Building for success with off-premises private cloud_listing.jpg" caption="" alt="Purple whitepaper cover with image of sky rise buildings in the background" src="https://cdn.mos.cms.futurecdn.net/6WzyXULWqGfc74RXXW3QnH.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Dell Technologies)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Building for success with off-premises private cloud</strong></p><p class="fancy-box__body-text"><em>Leveraging co-location facilities to execute your cloud strategy</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/368828/building-for-success-with-off-premises-private-cloud"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>As part of the move, sovereign cloud data centers will be located in Frankfurt and Madrid. </p><p>The Frankfurt site will be operated by Equinix while Digital Reality is the host partner for the cloud region in Madrid.</p><p>Richard Smith, executive vice president for technology, EMEA, at Oracle, said the new region comes in direct response to a changing regulatory landscape in the union at present. </p><p>"The European Union technology landscape has changed dramatically due to the growing importance of data protection and localization, leading to increased demand for sovereign cloud solutions that can securely host sensitive customer data and comply with regulations such as GDPR," he said. </p><p>“Our goal is to meet customers wherever they are in their cloud journey and with Oracle EU Sovereign Cloud, customers in highly regulated industries, as well as those subject to certain country-specific legislation, can now accelerate their cloud strategies."</p><h2 id="data-sovereignty-focus">Data sovereignty focus</h2><p>The new sovereign cloud region will operate under a “comprehensive” set of policies and governance that will support OCI’s existing capabilities, Oracle said. </p><p>This will include a framework for data and operational sovereignty focused specifically on regulating how OCI stores and manages access to EU data, as well as how data access from non-EU entities is handled. </p><p>“Oracle EU Sovereign Cloud is designed for data residency and security with an architecture that shares no infrastructure with Oracle&apos;s commercial regions in the EU and that has no backbone network connection to Oracle&apos;s other cloud regions,” the firm said. </p><p>“Customer access to Oracle EU Sovereign Cloud is managed separately from access to Oracle Cloud&apos;s commercial regions.”</p><h2 id="pending-eu-regulations">Pending EU regulations</h2><p>The move from Oracle comes at a time when EU lawmakers are tightening their regulatory approach to <a href="https://www.itpro.com/cloud/367052/data-sovereignty-a-boon-for-msps"><u>data sovereignty</u></a>. </p><p>This has been a contentious talking point in recent months amid plans to implement more stringent rules for non-EU companies processing data within the union. </p><p>In May, the European Union Agency for Cybersecurity (ENISA) revealed <a href="https://www.itpro.com/business/policy-and-legislation/big-three-cloud-providers-face-business-overhaul-to-continue-eu-operations"><u>plans to introduce a ‘cyber security label’</u></a> that will be required for non-EU companies operating in the union. </p><p>These proposals mean that major cloud providers such as Microsoft, Google, and AWS, would be required to enter into a “joint venture” with an EU-based firm for regulatory purposes.</p><p>This forms part of a wider regulatory crackdown via the EU certification scheme (EUCS), which aims to establish a <a href="https://www.itpro.com/cloud/370204/eu-cloud-proposals-discriminatory-reatliatory-tariffs"><u>union-wide certification regime</u></a> for cloud providers and companies handling EU data.</p><p>Oracle isn’t alone in its sovereignty push, either. Earlier this month, IBM confirmed its own plans to <a href="https://www.itpro.com/cloud/cloud-computing/ibm-to-open-first-european-quantum-data-center-promising-access-to-cutting-edge-processing"><u>open a dedicated quantum cloud data center and cloud region</u></a> in Ehningen, Germany. </p><p>IBM said the facility, which is the second of its kind for the firm, is designed specifically to “help clients continue to manage their European data regulation requirements”. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Is the UK falling behind the EU on AI regulation? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/is-the-uk-falling-behind-the-eu-on-ai-regulation</link>
                                                                            <description>
                            <![CDATA[ The UK could be playing catch-up with its innovation-led approach ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">N7KEEeocYHsusd8HHskoeG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KKQFvSdjtRL3vdhDJWmpvD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 15 Jun 2023 15:11:52 +0000</pubDate>                                                                                                                                <updated>Fri, 16 Jun 2023 06:43:15 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KKQFvSdjtRL3vdhDJWmpvD-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[EU AI: Half of the EU flag on the left and half of the UK flag on the right, overlaid onto a semi-transparent view of skyscrapers shot from the ground facing towards the sky.]]></media:description>                                                            <media:text><![CDATA[EU AI: Half of the EU flag on the left and half of the UK flag on the right, overlaid onto a semi-transparent view of skyscrapers shot from the ground facing towards the sky.]]></media:text>
                                <media:title type="plain"><![CDATA[EU AI: Half of the EU flag on the left and half of the UK flag on the right, overlaid onto a semi-transparent view of skyscrapers shot from the ground facing towards the sky.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KKQFvSdjtRL3vdhDJWmpvD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The EU has progressed a key bill seeking to regulate the use of artificial intelligence (AI) to its latter stages, in another move that outpaces the UK’s AI efforts.</p><p>On 14 June, MEPs held a pivotal vote to move the AI Act closer to being signed into law across the region, which was passed by an overwhelming majority.</p><p>The Artificial Intelligence Act (‘AI Act’) is a wide-ranging series of controls for the implementation of AI technology, centered around a risk-based approach.</p><p>UK government officials have become more vocal on the issue of AI in recent weeks, but have not pushed forward any legislation to curb the use of the technology.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LRrgzsXGoa6Lpzkz6LcgbX" name="AI and cyber security_listing.jpg" caption="" alt="Purple whitepaper cover with white text over background image of suited female wearing glasses" src="https://cdn.mos.cms.futurecdn.net/LRrgzsXGoa6Lpzkz6LcgbX.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><strong>AI and cyber security</strong></p><p class="fancy-box__body-text"><em>The promise and truth of the AI security revolution</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-crime/ai-and-cyber-security"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Under the EU’s measures, companies seeking to use AI would be required to provide <a href="https://www.itpro.com/business/policy-and-legislation/eus-ai-legislation-aims-to-protect-businesses-from-ip-theft"><u>transparency around data used to train models</u></a> and to clearly label AI-generated content.</p><p>The draft bill sets out a framework for risk assessment of systems, with high-risk systems defined as those that pose a “high risk to the health and safety or fundamental rights of natural persons”.</p><p>Companies that develop these systems will be required to register them in an EU database for public oversight.</p><p>Those that do not comply with the requirements of the act could be hit with fines of up to 4% of their annual worldwide turnover, or €20 million ($21.6 million).</p><p><em>The Financial Times</em> <a href="https://www.ft.com/content/6cc8a0f3-f2fc-4470-a881-8763451b47ea" target="_blank"><u>reported</u></a> a senior British official as having described the EU’s regulation as “draconian”, and OpenAI’s CEO Sam Altman warned his company could leave the EU over the law before <a href="https://www.itpro.com/technology/artificial-intelligence/sam-altman-reverses-threat-to-leave-europe-over-ai-regulations"><u>walking this threat back</u></a>.</p><p>In contrast to the EU’s strict risk-based approach, the UK whitepaper is based on a framework of five ‘principles’ for AI:</p><ul><li>Safety, security, and robustness</li><li>Appropriate transparency and explainability</li><li>Fairness</li><li>Accountability and governance</li><li>Contestability and redress</li></ul><p>It lays out no corresponding measures that could be taken against non-conforming companies, nor plans for statutory controls over AI.</p><p>The UK whitepaper specifically states that the government will not seek AI regulation on a statutory basis initially due to concerns that this could hinder innovation in the field.</p><p>Some in the industry have hailed this as a positive move for the UK AI landscape, as firms may be more willing to invest in the region if they believe it provides a better environment for profitable development.</p><p>“The key is to strike the balance between ensuring fairness and making AI possible to use and experiment with – which this pro-innovation approach supports,” said Iván de Prado Alonso, head of AI at Freepik Company.</p><p>“I expect a warm welcoming from technology vendors across the UK as the government encourages creating an AI-enabled nation.”</p><h2 id="ai-regulation-clashing-approaches-to-risk">AI regulation: Clashing approaches to risk</h2><p>As with the <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know"><u>GDPR</u></a>, firms seeking to operate within the EU will still need to abide by the AI Act, which could limit the extent to which AI firms feel the freedom that the UK government is at pains to provide.</p><p>Industry consultation indicated that small businesses could face great time and financial burdens by compliance requirements if regulators are “not proportionate and aligned in their regulation of AI”.</p><p>In place of initial legislation, existing regulators, such as Ofcom or the <a href="https://www.itpro.com/business/policy-and-legislation/big-tech-firms-face-10-turnover-fines-under-new-competition-law"><u>Digital Markets Unit</u></a>, will be asked to implement controls in a way seen as proportionate.</p><p>Setting out the exact powers each regulator will have is likely to push the legislation well into the next parliament; the two years it has taken for the Competition and Markets Authority’s (CMA) Digital Markets Unit to get off the ground casts a shadow over these proposals.</p><p>The decentralized approach, based on an evolving framework and tending towards pro-innovation rather than caution, could also allow the UK to adapt to the changing state of the AI market more easily.</p><p>First <a href="https://www.itpro.com/technology/artificial-intelligence-ai/359289/ec-unveils-new-draft-ai-regulations"><u>proposed in April 2021</u></a>, the AI Act has had to be rewritten many times to keep up with the developments in areas such as generative AI since its inception.</p><h2 id="ai-regulation-banned-technologies">AI regulation: Banned technologies</h2><p>The UK whitepaper acknowledged specific risks posed by <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai"><u>generative AI</u></a> and <a href="https://www.itpro.com/technology/artificial-intelligence-ai/370325/intel-facecatcher-eradicate-deepfakes"><u>deepfakes</u></a>, such as the potential for a criminal to generate false compromising images of an individual to damage their reputation, or for large language models (LLM) like <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369965/what-is-chatgpt-and-what-does-it-mean-for-businesses"><u>ChatGPT</u></a> to generate <a href="https://www.itpro.com/marketing-comms/social-media/358088/the-it-pro-podcast-the-power-of-disinformation"><u>disinformation</u></a>.</p><p>It did not go as far as providing risk guidelines with pre-defined uses or technologies in mind, and this could prove vital for its continued relevance as new technologies emerge.</p><p>The <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A52021PC0206" target="_blank"><u>draft document</u></a> for the AI Act, in comparison, includes a list of technologies deemed to carry an unacceptable risk, such as systems that could subliminally influence individuals or the use of AI for real-time biometrics tracking.</p><p>In this regard, it presents more of a complete overview for AI regulation than the UK whitepaper, which businesses can use to inform their business decisions going forward. </p><p>The UK’s approach could give AI developers more freedom to try systems out; it has also left firms guessing when it comes to what regulations they may have to follow down the line. </p><p>While outright bans on some uses of AI may be seen as restrictive, this is an example of the EU having delivered a clear answer to the ethical and regulatory questions that are being asked today while the UK is still in the consultation stage.</p><p>The conservative EPP Group sought to quash the biometrics ban through a last-minute amendment to the bill but failed to muster the votes necessary to have this passed. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="yBSUjgbGRVnAjmSXbqDTWF" name="Leaked today, exploited for life_listing.jpg" caption="" alt="Female looking at her mobile device with graphics of biometric scanning around her face" src="https://cdn.mos.cms.futurecdn.net/yBSUjgbGRVnAjmSXbqDTWF.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Leaked today, exploited for life</strong></p><p class="fancy-box__body-text"><em>How social media biometric patterns affect your future</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/370153/leaked-today-expolited-for-life"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>It remains to be seen whether the ban will stick, and the bill does reference “certain limited exceptions” for the technology that may leave the door open for use by EU nations.</p><p>Police use of real-time biometrics technology such as live facial recognition (LFR) has long been a point of controversy. </p><p>In 2022 a University of Cambridge study <a href="https://www.itpro.com/security/privacy/369423/uk-police-fails-ethical-tests-with-unlawful-facial-recognition"><u>called for the UK to ban the technology in public spaces</u></a>, and cited instances of the Metropolitan Police Service (MPS) using LFR in which “minimum ethical and legal standards” were not met.</p><p>Human rights groups have strongly objected to the use of LFR in recent years, alleging that the technology will entrench racial biases and violate individual privacy to an unacceptable degree.</p><p>“With such a persistently inhospitable environment towards people fleeing wars and conflict or in search of a better life, it is vital that the European Parliament doesn’t dismiss the harms of racist AI systems,” said Mher Hakobyan, advocacy advisor on AI regulation at Amnesty International.</p><p>“Lawmakers must ban racist profiling and risk assessment systems, which label migrants and asylum seekers as ‘threats’; and forecasting technologies to predict border movements and deny people the right to asylum.”</p><p>A <a href="https://www.itpro.com/business/policy-legislation/368426/mps-urge-ban-chinese-cctv-companies-citing-ethics-security-concerns"><u>cross-party group of UK lawmakers</u></a> called for CCTV devices from two Chinese companies to be banned in July 2022, due to alleged links with Uyghur internment camps and reported use of facial-recognition technology to detect Uyghur individuals.</p><p>During a trip to the US in June, UK Prime Minister Rishi Sunak attempted to distance the UK’s approach to AI from that of its closest neighbors.</p><p>Sunak has voiced ambitions for the UK to become a global leader in AI, and the newly announced <a href="https://www.itpro.com/business/policy-and-legislation/atlantic-declaration-expected-to-bring-uk-companies-closer-to-us-economic-sphere"><u>Atlantic Declaration</u></a> will see the UK and US work closely on AI safety.</p><p>The UK is also set to host the first international summit on AI safety later this year.</p><h2 id="ai-regulation-common-ground-on-sandboxes">AI regulation: Common ground on sandboxes</h2><p>Both the EU and UK approaches favor the adoption of trial environments, or ‘sandboxes’, for AI testing and deployment.</p><p>The UK whitepaper committed to providing businesses with a regulatory sandbox for AI, following a recommendation by Sir Patrick Vallance, a measure the EU has also promoted.</p><p>It is hoped that this will allow AI products and services to reach market faster, and highlight any hurdles to innovation, or emerging tools that deserve greater regulatory attention.</p><p>EU digital technology industry organization Digital Europe published a <a href="https://www.digitaleurope.org/resources/sandboxing-the-ai-act-testing-the-ai-act-proposal-with-europes-future-unicorns/" target="_blank"><u>report</u></a> based on results from nine European startups and SMEs. </p><p>A key finding was that respondents supported sandboxes, and would favor a continuous sandboxing process in which to test products.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why are AI innovators pushing so hard for regulation? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence/why-are-ai-innovators-pushing-so-hard-for-regulation</link>
                                                                            <description>
                            <![CDATA[ Tech giants are scrambling to curry favor with lawmakers amid a pending regulatory crackdown ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Nc8J4mkoJARgawxMspTadS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/oPZFhwVpfQoKkTHnrgwqfD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 30 May 2023 11:50:02 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/oPZFhwVpfQoKkTHnrgwqfD-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Imags]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The OpenAI CEO Sam Altman in a darkly lit room]]></media:description>                                                            <media:text><![CDATA[The OpenAI CEO Sam Altman in a darkly lit room]]></media:text>
                                <media:title type="plain"><![CDATA[The OpenAI CEO Sam Altman in a darkly lit room]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/oPZFhwVpfQoKkTHnrgwqfD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>With lawmakers on both sides of the Atlantic circling the wagons, <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai"><u>generative AI</u></a> leaders look ready to commend themselves into the loving arms of regulators – or so they’d have us think. </p><p>OpenAI CEO Sam Altman embarked on a whistlestop public relations tour of Europe last week, meeting with lawmakers and industry figures, and flying the flag for the organization amid heightened regulatory scrutiny. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/369570/can-the-ai-bill-of-rights-shape-global-ai-regulation">Can the AI Bill of Rights shape global AI regulation?</a></p></div></div><p>This tour saw him stop at Downing Street to meet with UK Prime Minister Rishi Sunak alongside several industry execs to discuss the acceleration of generative AI, how <a href="https://www.itpro.com/business/policy-legislation/369570/can-the-ai-bill-of-rights-shape-global-ai-regulation"><u>regulation may shape the evolution of the industry</u></a>, and how AI itself may shape the future of industry. </p><p>The tour bore similarities to a royal visit in many ways. Here, there, and everywhere and a whole lot of schmoozing, yet without the crowds, pomp, and lavish splendor. It was a case of  talking a good game and smiling for the cameras, giving the impression of an industry leader open to discussing the simmering undercurrent of concern over what generative AI means for the future. </p><h2 id="toying-with-pulling-the-plug">Toying with pulling the plug</h2><p>While there’s no denying Altman has been willing to communicate on the issue of AI regulation – after all, he turned up to Congress last month – it’s part of a pattern of cosying up to regulators prior to crackdowns. </p><p>At an event in London last Wednesday, Altman told attendees during a panel session the company could “leave Europe” if it were unable to meet regulatory requirements, describing pending proposals as ‘over-regulating’. </p><p>“Either we’ll be able to solve those requirements or not,” Altman told attendees. “If we can comply, we will, and if we can’t, we’ll cease operating. We will try. But there are technical limits to what’s possible.”</p><p>This pungent whiff of absolutist, childish rhetoric was swiftly snuffed out <a href="https://www.itpro.com/technology/artificial-intelligence/sam-altman-reverses-threat-to-leave-europe-over-ai-regulations"><u>by a u-turn on Friday</u></a> in which Altman declared the firm was “excited to continue to operate here, and of course have no plans to leave”. </p><p>A sigh of relief for many across Europe, no doubt. But the breakneck speed at which Altman was willing to threaten pulling out of Europe and then renege on the statement should raise concerns. Perhaps some industry leaders in the AI space just aren’t too keen on regulation – who would’ve thought?</p><h2 id="another-regulatory-groundhog-day">Another regulatory Groundhog Day</h2><p>We’ve seen this before. In 2020, Meta (then Facebook) spat the dummy out over a potential ban on sharing EU citizens’ data in the US due to <a href="https://www.itpro.com/security/privacy/361785/using-privacy-as-a-business-differentiator-risks-strategies"><u>privacy concerns</u></a>. In a court filing, Facebook’s associate general counsel suggested enforcing a ban on trans-Atlantic data sharing would leave the company unable to operate.</p><p>“In the event that [Facebook] were subject to a complete suspension of the transfer of users’ data to the US,” Yvonne Cunnane wrote, “it is not clear how, in those circumstances, it could continue to provide the Facebook and Instagram services in the EU.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/what-would-pausing-ai-development-actually-achieve">What would pausing AI development actually achieve?</a></p></div></div><p>Meta’s recent spats with EU regulators have also been halted by swift u-turns after bold declarations. Calling EU regulators’ bluff has, historically, been an abysmal tactic. And Altman’s recent outburst highlighted this perfectly, prompting a strongly-worded backlash from lawmakers in the union. </p><p>Thierry Breton, European commissioner for internal markets, hit back at Altman’s comments, stating that rules on AI development “cannot be bargained”. </p><p>“Let’s be clear, our rules are put in place for the security and well-being of our citizens and this cannot be bargained,” he told <em>Reuters</em>. </p><p>“Europe has been ahead of the curve designing a solid and balanced regulatory framework for AI which tackles risks related to fundamental rights or safety, but also enables innovation for Europe to become a frontrunner in trustworthy AI.”</p><h2 id="talking-the-industry-into-the-good-books">Talking the industry into the good books</h2><p>Although aggressive in nature, Altman’s recent statements are an interesting tactic in the cat-and-mouse game innovators play with regulators. </p><p>An outright crackdown from lawmakers would be disastrous and, frankly, counterproductive to the future of the industry. But if the industry keeps them talking and engaged for long enough, they may be able to temper the outcome and reduce the long-term hit. </p><p>While Altman was wrapping up his Eurotrip, Microsoft president Brad Smith outlined the company’s future goals for AI governance, transparency, and responsible use. </p><p>Detailing ‘five key principles’ to ensuring <a href="https://www.itpro.com/technology/artificial-intelligence-ai/359374/taming-the-machine-ai-governance"><u>responsible AI development</u></a> at the tech giant, Smith’s approach appears very much focused on currying favor with regulators on both sides of the Atlantic. </p><p>“We are committed and determined as a company to develop and deploy AI in a safe and responsible way,” he wrote in a blog post. “We also recognize, however, that the guardrails needed for AI require a broadly shared sense of responsibility and should not be left to technology companies alone.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/370416/generative-ai-mark-zuckerberg-metaverse-in-the-dust">Generative AI has left the metaverse in the dust</a></p></div></div><p>A key talking point in this blog post was Smith’s calls to pursue “public-private partnerships to use AI as an effective tool to address the inevitable societal challenges that come with new technology”. </p><p>Smith asserted the “key to success” moving forward will be to develop closer ties between government, “respected companies”, and NGOs to ensure transparency, regulation, and prevent misuse. A bold statement, and one that will likely be welcomed by regulators in both the US and EU. </p><p>At the same time, however, acknowledging the “inevitable societal challenges” that will arise due to AI advances hardly fills one with confidence, and underlines how urgent proper regulations are.</p><p>AI innovators, it seems, have a choice; spit the dummy out and buckle in for a battle, or cozy up to regulators and hope the gamble pays off. Either way, the "move fast and break things" honeymoon period is over, and regulation is coming.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sam Altman reverses threat to ‘leave Europe’ over AI regulations ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence/sam-altman-reverses-threat-to-leave-europe-over-ai-regulations</link>
                                                                            <description>
                            <![CDATA[ Altman’s comments during a panel discussion on Wednesday sparked criticism from EU lawmakers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ECLgkwRjykuhv2j8wtg8ZZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/aCw83Fx6zRpbkrfrBSHxTo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 26 May 2023 10:21:54 +0000</pubDate>                                                                                                                                <updated>Tue, 30 May 2023 13:59:27 +0000</updated>
                                                                                                                                            <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/aCw83Fx6zRpbkrfrBSHxTo-1280-80.jpg">
                                                            <media:credit><![CDATA[Win McNamee/Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Sam Altman, CEO of OpenAI, testifies before the Senate Judiciary Subcommittee on Privacy, Technology, and the Law]]></media:description>                                                            <media:text><![CDATA[Sam Altman, CEO of OpenAI, testifies before the Senate Judiciary Subcommittee on Privacy, Technology, and the Law]]></media:text>
                                <media:title type="plain"><![CDATA[Sam Altman, CEO of OpenAI, testifies before the Senate Judiciary Subcommittee on Privacy, Technology, and the Law]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/aCw83Fx6zRpbkrfrBSHxTo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>OpenAI chief executive Sam Altman has reneged on threats that the generative AI company could “leave Europe” due to an impending regulatory crackdown. </p><p>Earlier this week at an event in London, Altman suggested the company may pull out of Europe if it could not comply with upcoming AI regulations being considered by EU lawmakers.</p><p>While participating in a panel discussion at University College London (UCL), Altman said the company will “try to comply” with the pending regulations. However, he <a href="https://www.reuters.com/technology/openai-may-leave-eu-if-regulations-bite-ceo-2023-05-24/" target="_blank"><u>later told </u><u><em>Reuters</em></u></a> that, in their current state, the proposals would amount to “over regulating”. </p><p>“Either we’ll be able to solve those requirements or not,” Altman told attendees. “If we can comply, we will, and if we can’t, we’ll cease operating. We will try. But there are technical limits to what’s possible.”</p><p>The threat to back out of Europe sparked criticism from lawmakers across the union. Thierry Breton, European commissioner for internal markets, hit back at the comments, stating that rules on AI development “cannot be bargained”. </p><p>“Let’s be clear, our rules are put in place for the security and well-being of our citizens and this cannot be bargained,” he told <a href="https://www.reuters.com/technology/eus-breton-slams-openai-ceos-comments-blocs-draft-ai-rules-2023-05-25/" target="_blank"><u><em>Reuters </em></u></a>on Thursday. </p><p>“Europe has been ahead of the curve designing a solid and balanced regulatory framework for AI which tackles risks related to fundamental rights or safety, but also enables innovation for Europe to become a frontrunner in <a href="https://www.itpro.com/technology/artificial-intelligence-ai/370342/inside-mozillas-mission-to-champion-trustworthy-ai"><u>trustworthy AI</u></a>,” Breton added. </p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr">very productive week of conversations in europe about how to best regulate AI! we are excited to continue to operate here and of course have no plans to leave.<a href="https://twitter.com/sama/status/1661975237280567297">May 26, 2023</a></p></blockquote><div class="see-more__filter"></div></div><p>The backlash appears to have prompted Altman to renege on his comments. In a tweet sent on 26 May, Altman confirmed the company has no plans to leave Europe. </p><p>“Very productive week of conversations in Europe about how to best regulate AI,” he said. “We are excited to continue to operate here, and of course have no plans to leave.”</p><h2 id="what-prompted-the-pull-out-threats">What prompted the pull-out threats?</h2><p>The EU is currently working on a standardized set of rules to govern and regulate the development and use of <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai"><u>generative AI</u></a> technologies. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ZR9iwX5TUsqEDubD7jLykK" name="AI inferencing with AMD_listing.jpg" caption="" alt="Whitepaper cover with title and logo over an image of an iris and pupil of an eye" src="https://cdn.mos.cms.futurecdn.net/ZR9iwX5TUsqEDubD7jLykK.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: AMD)</span></figcaption></figure><p class="fancy-box__body-text"><strong>AI inferencing with AMD EPYC™ processors</strong></p><p class="fancy-box__body-text"><em>Providing an excellent platform for CPU-based AI inferencing</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/ai-inferencing-with-amd-epyctm-processors"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Under the current proposals, the regulations would see OpenAI systems such as <a href="https://www.itpro.com/technology/artificial-intelligence-ai/368288/what-is-gpt-4"><u>GPT-4</u></a> designated as “high risk”, meaning that it would be forced to comply with additional safety requirements. </p><p>Other proposals would require companies such as OpenAI to disclose whether copyrighted materials have been used to train systems such as <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369965/what-is-chatgpt-and-what-does-it-mean-for-businesses">ChatGPT</a>. </p><p>These aspects of the regulations have sparked concern at OpenAI, with critics suggesting that it would severely inhibit innovation and cause significant long-term issues. </p><p>The company has repeatedly argued that systems such as ChatGPT are not inherently high risk. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Big three’ cloud providers face business overhaul to continue EU operations ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/big-three-cloud-providers-face-business-overhaul-to-continue-eu-operations</link>
                                                                            <description>
                            <![CDATA[ New security labeling rules for non-EU cloud providers have been a contentious topic in recent weeks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eGakPYztKRYvASX4kzcN24</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/d63amyUPCZFoGA47cq73qH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 11 May 2023 09:31:00 +0000</pubDate>                                                                                                                                <updated>Mon, 15 May 2023 12:02:03 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/d63amyUPCZFoGA47cq73qH-1280-80.jpg">
                                                            <media:credit><![CDATA[Santiago Urquijo/Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[European Union flags at Berlaymont building of the European Commission in Brussels, Belgium]]></media:description>                                                            <media:text><![CDATA[European Union flags at Berlaymont building of the European Commission in Brussels, Belgium]]></media:text>
                                <media:title type="plain"><![CDATA[European Union flags at Berlaymont building of the European Commission in Brussels, Belgium]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/d63amyUPCZFoGA47cq73qH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>New EU cloud security labeling proposals could force the three major cloud providers to overhaul their business practices in order to continue operating in the region, according to reports.</p><p>Draft documents, not yet officially presented to the public, in their current wording suggest providers will be required to engage in a joint venture with an EU-based firm. </p><p>The documents add that non-EU operators, including US firms, will only receive a ‘minority stake’ in such ventures, which aim to improve security by providing an EU-based point-of-contact for regulatory purposes. </p><p>Employees with access to EU data would also be required to undergo screening processes and be located within one of the EU’s 27 member states.</p><p>The documents, seen by <a href="https://www.reuters.com/technology/eu-draft-rules-propose-tougher-cybersecurity-labelling-rules-amazon-google-2023-05-09/"><u><em>Reuters</em></u></a>, relate to the EU’s plans to introduce a cyber security label that will be required if a company, like Microsoft, Google Cloud, or AWS wishes to handle sensitive data in the EU.</p><p>The latest proposals put forward by the EU cyber security agency, ENISA, form part of the EU certification scheme (EUCS), which aims to establish a union-wide certification regime for cloud providers. </p><p>This, ENISA has said, will “further improve the union’s internal market conditions for cloud services by enhancing and streamlining the services’ cyber security guarantees”. </p><p>“The draft EUCS candidate scheme intends to harmonize the security of cloud services with EU regulations, international standards, industry best practices, as well as with existing certifications in EU member states,” ENISA said.</p><h2 id="eu-data-sovereignty-xa0">EU data sovereignty </h2><p>A key component within the draft documents centers around the requirement that cloud services must be operated and maintained within the EU. </p><p>In addition, the document outlines requirements that customer data stored and processed in the EU will be subject exclusively to EU regulations and take precedence over non-EU laws. </p><p>“Certified cloud services are operated only by companies based in the EU, with no entity from outside the EU having effective control over the CSP (cloud service provider), to mitigate the risk of non-EU interfering powers undermining EU regulations, norms and values,” the document reads.</p><p>“Undertakings whose registered head office or headquarters are not established in a member state of the EU shall not, directly or indirectly, solely or jointly, hold positive or negative effective control of the CSP applying for the certification of a cloud service,” it added.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="fH6a2vHv2sK7hBPF2aUo7k" name="Solving the cloud-native app puzzle with CNAPP_thumb.jpg" caption="" alt="Red whitepaper cover with title and logo" src="https://cdn.mos.cms.futurecdn.net/fH6a2vHv2sK7hBPF2aUo7k.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: TrendMicro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Solving the cloud-native app puzzle with CNAPP</strong></p><p class="fancy-box__body-text"><em>The value of integrating cloud-native application protection into security and development</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/solving-the-cloud-native-app-puzzle-with-cnapp"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>The move could spark concern for non-EU cloud service providers - particularly the <a href="https://www.itpro.com/cloud/370001/hyperscaler-earnigns-highlight-new-era-of-maturity-in-global-cloud-market"><u>three major hyperscalers</u></a>, all of which have a major stake in the union, according to Philip Brining, co-founder and director of Data Protection People. </p><p>"The proposed cyber security labeling rules, which require non-EU cloud providers to establish joint ventures with EU-based firms, may present challenges for providers like Google, Microsoft, and Amazon amongst others,” he told <em>ITPro</em>. </p><p>“Compliance with the requirements would involve significant restructuring and potential delays in obtaining the EU cybersecurity kite mark. These companies, with their extensive customer bases and data management responsibilities, could face a competitive disadvantage compared to EU counterparts.”</p><p>In March, industry stakeholders criticized the EU’s current approach to cloud regulation, noting that its proposals could prove highly inhibitive for non-EU operators. </p><p>A report from the European Centre for International Political Economy (ECIPE) <a href="https://www.itpro.com/cloud/370204/eu-cloud-proposals-discriminatory-reatliatory-tariffs"><u>described the proposed certification scheme as “discriminatory”</u></a> toward non-EU providers. </p><p>A key point of contention highlighted by ECIPE was the requirement that non-EU cloud providers must register their head offices and global headquarters within the region. </p><p>Gavin Millard, Deputy CTO at Tenable echoed Brining’s comments, noting that the current proposals could be highly inhibitive to non-EU-based providers due to the requirement to operate alongside a third party. </p><p>“Whilst the protection of sensitive data from external entities should be paramount, the requirement to have an EU-based third party with a majority stake in the venture could be a ridiculously high barrier for the cloud services providers to do business in Europe,” he said. </p><p>“It could be far more achievable and palatable to mandate and audit the siloing of sensitive data from non-EU employees of the cloud giants, than trying to force a potentially damaging commercial relationship with a third party.”</p><p>Millard added that while larger cloud providers could be impacted by the move, smaller organizations and software vendors may also be seriously affected. </p><p>"The draft proposal could also greatly impact other software vendors and businesses, as they&apos;ve built platforms to be cloud-specific, leveraging services only available on a particular provider,” he said.</p><p>“If providers based outside the EU can&apos;t provide a cloud platform deemed suitable, it&apos;s going to take a significant effort for companies doing business in the EU to reengineer their products to support the ‘EU Cloud’. Implementing could be a huge headache for both US and EU-based organizations, creating unnecessary friction by replacing one risk with another."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ EU's AI legislation aims to protect businesses from IP theft ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/eus-ai-legislation-aims-to-protect-businesses-from-ip-theft</link>
                                                                            <description>
                            <![CDATA[ The AI Act's new bill would also seek to better promote the risks of individual AI models ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9KE54S6hz9hDn6PeNiQexJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DFxSE87P88iW6pX6P92trE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 28 Apr 2023 12:36:19 +0000</pubDate>                                                                                                                                <updated>Tue, 02 May 2023 11:05:42 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DFxSE87P88iW6pX6P92trE-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[EU flag render shown as 12 gold stars hovering and creating a ripple effect in a wave of blue data]]></media:description>                                                            <media:text><![CDATA[EU flag render shown as 12 gold stars hovering and creating a ripple effect in a wave of blue data]]></media:text>
                                <media:title type="plain"><![CDATA[EU flag render shown as 12 gold stars hovering and creating a ripple effect in a wave of blue data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DFxSE87P88iW6pX6P92trE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new draft of EU artificial intelligence (AI) legislation could better protect business IP from being secretly scraped by AI firms, with developers facing new transparency obligations on copyrighted content.</p><p>The long-awaited AI Act could force developers to disclose when they collect and use copyrighted material to train large language models (LLMs). </p><p>The aim is to protect firms from having information such as source code used without their permission.</p><p>In addition to protection from unauthorized uses of data, the bill would offer companies legal grounds to establish the degree to which AI firms they work with are using ethically sourced, non-copyrighted data.</p><p>This could save businesses from costly legal battles over the use of tools that, unbeknown to them, contain stolen intellectual property (IP). </p><p>The bill is also expected to categorize <a href="https://www.itpro.com/strategy/28181/what-is-ai"><u>AI</u></a> models by their risk factor, from ‘minimal’ to ‘unacceptable’. </p><p>It aims to provide clear criteria that organizations can use to assess whether an AI tool’s risks outweigh its use cases.</p><p>High-risk AI systems have been <a href="https://artificialintelligenceact.eu/the-act/" target="_blank"><u>defined</u></a> as those that present “significant risks to the health and safety or fundamental rights of persons”, such as <a href="https://www.itpro.com/security/privacy/369423/uk-police-fails-ethical-tests-with-unlawful-facial-recognition"><u>live facial recognition</u></a>, and will be subject to additional transparency obligations.</p><h2 id="eu-x2019-s-ai-act-and-wider-industry-data-scraping">EU’s AI Act and wider industry data scraping</h2><p>At present, many developers of large language models (LLMs), the <a href="https://www.itpro.com/data-insights/30212/what-is-an-algorithm"><u>algorithms</u></a> behind <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai"><u>generative AI</u></a>, use a great deal of data harvested from the internet for training purposes. </p><p>Lawmakers from across the EU’s political divide have come to a provisional agreement for the bill, which will now be pushed to the EU trilogue for further debate.</p><p>Previous drafts of the bill, <a href="https://www.itpro.com/technology/artificial-intelligence-ai/359289/ec-unveils-new-draft-ai-regulations"><u>first proposed in 2021</u></a>, stated that transparency obligations “will not disproportionately affect the right to protection of intellectual property”.</p><p>The current bill states that non-compliant firms could face fines totaling up to 4% of their annual worldwide turnover, or €20 million ($22 million), whichever is higher.</p><p>Alistair Dent, chief strategy officer at data company Profusion, said that the requirement “raises the question of why AI should be treated differently from other platforms, such as social media or search engines”.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LRrgzsXGoa6Lpzkz6LcgbX" name="AI and cyber security_listing.jpg" caption="" alt="Purple whitepaper cover with white text over background image of suited female wearing glasses" src="https://cdn.mos.cms.futurecdn.net/LRrgzsXGoa6Lpzkz6LcgbX.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><strong>AI and cyber security</strong></p><p class="fancy-box__body-text"><em>The promise and truth of the AI security revolution</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-crime/ai-and-cyber-security"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>“These platforms index or use a huge amount of copyrighted material often without citation - should they be forced to adhere to the same standards as AI?” he added.</p><p>Examples of this can be found in historical examples of wide-scale data scraping. </p><p>Earlier this year, Meta <a href="https://www.itpro.com/policy-legislation/data-protection/369861/meta-sues-data-scraping-for-hire-service-600k-users"><u>sued a ‘data scraping for hire’ firm Voyager Labs</u></a> for its practices, alleging the firm had collected data on 600,000 Facebook users in a hidden campaign utilizing fake accounts.</p><p>Meta itself also attracted a <a href="https://www.itpro.com/business/policy-legislation/369609/unacceptable-data-scraping-lands-meta-228m-fine"><u>€265 million ($291 million) fine for “unacceptable” data scraping</u></a> from the Irish Data Protection Commission (DPC) in November 2022.</p><p>At present, firms face a confusing regulatory landscape over the permittance of data scraping. </p><p>A case in the US last year, <a href="https://www.itpro.com/policy-legislation/data-governance/359879/linkedin-granted-permission-to-go-after-hiq-labs"><u>between hiQ Labs and LinkedIn</u></a>, concluded that web scraping was not in violation of federal law.</p><p>However, the court was not convened to directly rule on the practice of web scraping, nor did it offer judgment on how the legality of the practice could be impacted by claims of IP theft.</p><p>The EU, in contrast, has protections against the use of data that could infringe on the rights of citizens such as for biometric identification, and has issued fines on the subject as seen with the Irish DPC’s decision on Meta.</p><p>Like <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know"><u>GDPR</u></a>, the EU’s AI Act is expected to have widespread implications for the market. </p><p>Those firms looking to sell or deploy their models in the EU will have to comply with the terms of the bill, which will require a market-wide homogenized approach to risk and ethics criteria for AI products.</p><p>Researchers from the University of Oxford have created a tool called capAI, which they <a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4064091" target="_blank"><u>describe</u></a> as “an independent, comparable, quantifiable, and accountable assessment of AI systems that conforms with the proposed AIA regulation”.</p><p>Within the paper, a proposal for internal review protocols is given as well as a suggestion that firms could provide stakeholders and customers with a scorecard for their AI system.</p><p>This could alleviate the concerns of some experts such as Dent.</p><p>"A risk-based approach, which seeks to categorize different uses of AI and then add rules based on the perceived &apos;risk&apos; of the solution causing harm, has the drawback of being unable to anticipate how AI will develop and the impact new tools will have on society,” he stated.</p><p>“Put simply, if you can&apos;t know what form a new AI solution will take and how it will be used, it&apos;s very hard to predetermine what category it should go in and apply the compliance burden accordingly.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What cracking open the App Store means for the future of iOS ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/what-cracking-open-the-app-store-means-for-the-future-of-ios</link>
                                                                            <description>
                            <![CDATA[ Fears begin to mount over whether the EU's Digital Markets Act (DMA) will backfire ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zd2aw8VU5o8zW7pVJQ5R3Z</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dJh9fkXv9aBJHUkBvhmoKA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Apr 2023 07:00:00 +0000</pubDate>                                                                                                                                <updated>Tue, 18 Apr 2023 10:43:15 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ James O&#039;Malley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dJh9fkXv9aBJHUkBvhmoKA-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The App Store icon listed on an iPhone screen home page, zoomed in]]></media:description>                                                            <media:text><![CDATA[The App Store icon listed on an iPhone screen home page, zoomed in]]></media:text>
                                <media:title type="plain"><![CDATA[The App Store icon listed on an iPhone screen home page, zoomed in]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dJh9fkXv9aBJHUkBvhmoKA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>When you buy an Apple product, it can often feel like making a deal with the devil. On the one hand, you can be confident your new device will be slick, intuitive, and powerful. But on the other, you’re acquiescing to Apple’s locked-down ecosystem of apps and services. Want to run an unapproved app on your <a href="https://www.itpro.co.uk/mobile/mobile-phones/369417/apple-iphone-14-pro-review-a-dynamic-phone-from-top-to-bottom"><u>new iPhone</u></a>? Forget it.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/mobile-phones/369417/apple-iphone-14-pro-review-a-dynamic-phone-from-top-to-bottom">Apple iPhone 14 Pro review: A dynamic phone from top to bottom</a></p></div></div><p>This is how it’s been since 2008 when the App Store first launched. Since then, apps have turned into an almost unfathomably lucrative business for Apple. In the year prior to Apple’s most recent financial statement, the store raked in a staggering $78 billion of services revenue, most of which is derived from the App Store.</p><p>If rumors are true, though, the gold rush could soon be coming to an end. According to well-connected business journalist Mark Gurman of <em>Bloomberg News</em>, developers are hard at work updating iOS so it can support third-party app stores and apps that have been “side-loaded” onto the device. Such a move would dramatically upend years of Apple’s uncompromising policy – and shake the foundations of the iPhone’s security model, too. </p><h2 id="the-digital-markets-act-dma-spells-trouble-for-big-tech">The Digital Markets Act (DMA) spells trouble for big tech</h2><p>The EU’s <a href="https://www.itpro.co.uk/business/policy-legislation/368435/what-is-the-eus-digital-markets-act-dma"><u>Digital Markets Act (DMA)</u></a> was signed into law in September last year. This sprawling piece of legislation had been crafted with only one goal in mind.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="v6qpB3H5c5CDXmxDPnhdVd" name="Build modern applications on AWS_thumb.jpg" caption="" alt="Purple whitepaper cover with image of smiling female worker wearing glasses and carrying a folder and smartphone" src="https://cdn.mos.cms.futurecdn.net/v6qpB3H5c5CDXmxDPnhdVd.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: AWS)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Build modern applications on AWS</strong></p><p class="fancy-box__body-text"><em>Manage less. Build fast. Innovate more.</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.co.uk/software/business-apps/361280/build-modern-applications-on-aws"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>“We&apos;ve gone through several decades where a lot of these companies have been allowed to kind of grow globally unchecked,” says professor Vince Manzerolle, who studies the political economy of digital media at the University of Windsor in Canada. “This legislation is almost crafted to take down some of these big companies.”</p><p>When the DMA comes into force, many expect it’ll require Apple to allow third-party app stores on its devices. “If Apple is actually forced to comply with the letter of this new kind of legislation it will, I think, transform its operations in some fairly profound ways,” says Manzerolle. “Allowing sideloading and third-party app stores is a pretty significant change.”</p><p>One major point of contention between Apple and the EU is the 30% fee Apple charges for every transaction in the App Store – and most in-app purchases too. “I think the EU is just interested in lower prices and allowing more competition,” says Dr Kathryn McMahon, associate professor of competition law at Warwick University. “They say the 30% is an excessive fee. It&apos;s in no way related to the cost. It&apos;s also discriminatory because it&apos;s not charged across the board.”</p><h2 id="scrapping-the-x2018-apple-tax-x2019">Scrapping the ‘Apple Tax’</h2><p>The fee – often referred to as the &apos;Apple Tax&apos; – has long been unpopular with developers, as Apple imposes draconian rules on how apps can take payments. Under the current rules, all in-app purchases of digital goods must use Apple&apos;s own payment system.</p><div  class="fancy-box"><div class="fancy_box-title">Apple vs Epic Games</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="2bii3R3L7HjQ2WTgMBpt7D" name="Fortnite - GettyImages-1394259860.jpg" caption="" alt="Somebody playing Fortnite on a laptop using a games controller" src="https://cdn.mos.cms.futurecdn.net/2bii3R3L7HjQ2WTgMBpt7D.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><em>The &apos;Apple Tax&apos; row escalated in August 2020, when Fortnite developers Epic Games built a version of the game that used its own payment system. Apple called Epic’s bluff, and as a result, Fortnite wasn&apos;t available on iPhone or iPad until the lawsuit was settled this year. With the DMA, though, the EU has taken Epic’s side. Under the new model, Epic could get the game onto iPhones by using its own Epic Games store.</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.co.uk/business/business-strategy/360795/what-apples-epic-battle-could-mean-for-the-app-business">What Apple&apos;s Epic battle could mean for the app business</a></p></div></div><p>Apps aren’t even allowed to signpost alternative payment methods, such as by linking users to a website. It means that, for example, you can download the Netflix app and log in – but if you want to sign up for a new account, you&apos;ll need to figure out how to do it yourself because the company doesn’t want to give Apple a cut of its revenue.</p><p>The option to use alternative app stores could be of huge benefit to developers across the board. “There are lots of rules and restrictions on what you can and can&apos;t do,” says Dr Greig Paul, an electrical engineer and security researcher at Strathclyde University. “You&apos;re playing in someone else&apos;s walled garden, so to speak.”</p><p>“If you give people the option to build apps [without approval], who knows what we will see?” he adds, arguing that it could ultimately be good for innovation if iPhone users could use a different way to download a <a href="https://www.itpro.co.uk/web-browsers/24796/best-browser-chrome-vs-edge-vs-firefox"><u>web browser</u></a> that hasn’t been forced to use Apple’s own web rendering engine, for example. “You might get the Firefox browser, using Firefox&apos;s engine on an iPhone, and that might push Safari to up its performance, or it might give you more extensions.”</p><h2 id="unpicking-the-ios-security-concerns">Unpicking the iOS security concerns</h2><p>Cracking open Apple’s app store monopoly could be good news for consumers, who would have more choice and control over the apps on their phones. But there could also be unintended consequences for iOS security.</p><p>“If you&apos;ve been selling people on &apos;you don&apos;t need to think about security, you don&apos;t need to think about privacy&apos;, and then all of a sudden there are new [threats], maybe users are not prepared for that,” says Manzerolle. “I certainly think that&apos;s a possibility.”</p><p><br></p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.co.uk/security/cyber-security/367989/the-eus-apple-app-store-crackdown-will-fuel-cyber-attacks">The EU’s Apple App Store crackdown ‘will fuel cyber attacks’</a></p></div></div><p>Allowing other app stores or sideloading would put iOS policies broadly in line with Android, which has always been more open and flexible than Apple’s super-locked down operating system, but also more open to attack. “You&apos;re adding more complexity as you&apos;re opening up the platform,” said Manzerolle. “And there&apos;s all sorts of smart hackers and cyber criminals out there. They&apos;re probably looking for an opportunity to get into the Apple ecosystem and exploit people&apos;s trust in the platform.”</p><h2 id="will-the-eu-x2019-s-measures-backfire">Will the EU’s measures backfire?</h2><p>Of course, even if Apple does bend to the EU’s will, and alternative app stores do emerge on iOS, it doesn’t necessarily mean that consumers will follow. McMahon wonders if the EU could find itself in a similar position to the one it found itself in 2005 when it tried to rein in Microsoft’s ability to use Windows to push its own media playback software to consumers.</p><p>“Microsoft, as a result of the EU case, had to ship Windows without Windows Media Player,” says McMahon, who explains that when Microsoft later released a new version of Windows XP without Media Player alongside the bundled version, it died a lonely death.</p><iframe width="100%" height="350px" frameborder="0" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=49504615&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true&color=ffe019"></iframe><p>“Nobody bought it. Nobody wanted to get it separately,” says McMahon. “The whole point of the antitrust case was to separate it out to allow much more competition in music browsers and streaming, but it didn&apos;t really have that effect. Because people just preferred [the bundle] and they just purchased the entire package.”</p><p>Will history repeat itself for iOS? Or will this be the beginning of a dramatic new era for the iPhone? If the rumors are true, we’re about to find out.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft's EU Data Boundary will begin staggered rollout in January 2023 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-computing/369720/microsofts-eu-data-boundary-rollout-january-2023</link>
                                                                            <description>
                            <![CDATA[ Public sector and commercial customers will be the first to benefit when the rollout begins on 1 January across all of Microsoft's core services ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6X2G6gVntb3FTbmW1cCLSM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xvXroFtTUCHD5xPk6iQzdD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 15 Dec 2022 12:24:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xvXroFtTUCHD5xPk6iQzdD-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[View of a Microsoft building]]></media:description>                                                            <media:text><![CDATA[View of a Microsoft building]]></media:text>
                                <media:title type="plain"><![CDATA[View of a Microsoft building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xvXroFtTUCHD5xPk6iQzdD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has announced the staggered rollout of its long-awaited EU Data Boundary solution will begin in January 2023.</p><p>The solution is expected to roll out first to public sector and commercial customers and aims to allow businesses to store and process their customer's data within the European Union (EU).</p><p>First <a href="https://blogs.microsoft.com/eupolicy/2021/05/06/eu-data-boundary">announced</a> last year, the data boundary builds on Microsoft’s existing EU data storage commitments. The data residency solution means that customer data will only be processed and accessed from the jurisdiction in which it originates. </p><p>Microsoft said this was developed using extensive customer feedback over the last 18 months. Engineering work to support the implementation of the solution began shortly after the announcement in May 2021. </p><p>When introduced on 1 January, the change will apply to all core services, including Azure, Microsoft 365, Power BI, and Dynamics 365. </p><p>“Beginning on 1 January 2023, Microsoft will offer customers the ability to store and process their customer data within the EU Data Boundary for Microsoft 365, Azure, Power Platform, and Dynamics 365,” the company said in a <a href="https://blogs.microsoft.com/eupolicy/2022/12/15/eu-data-boundary-cloud-rollout">statement</a>. </p><p>“With this release, Microsoft expands on local storage and processing commitments, greatly reducing data flows out of Europe, and building on our industry-leading data residency solutions.” </p><p>In later phases of its rollout, Microsoft also outlined plans to expand the solution to include the storage and processing of “additional categories of personal data”, including data provided when receiving technical support. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="3AqyMeTacWD2fDQGnUCXJh" name="3AqyMeTacWD2fDQGnUCXJh.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/3AqyMeTacWD2fDQGnUCXJh.png" mos="https://cdn.mos.cms.futurecdn.net/3AqyMeTacWD2fDQGnUCXJh.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>An end-to-end roadmap for SMB cloud migration</strong></p><p class="fancy-box__body-text">Future-proofing transformation</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/smb/369666/an-end-to-end-roadmap-for-smb-cloud-migration" data-original-url="/business-strategy/smb/369666/an-end-to-end-roadmap-for-smb-cloud-migration">FREE DOWNLOAD</a></p></div></div><p>At present, Microsoft provides <a href="https://www.itpro.com/cloud/367935/best-cloud-computing-services-in-2022" data-original-url="https://www.itpro.com/cloud/367935/best-cloud-computing-services-in-2022">cloud services</a> to customers in nearly every country in the world. In Europe specifically, the company has opened – and is currently building – <a href="https://www.itpro.com/strategy/29134/what-is-a-datacentre" data-original-url="https://www.itpro.com/strategy/29134/what-is-a-datacentre">data centres</a> in 17 data centre regions. The tech giant plans to build nine new additional regions in the coming years. </p><p>The rollout of the EU data boundary solution aims to support the regulatory requirements of customers across the EU and European Free Trade Association (EFTA), and follows long-running concerns over the <a href="https://www.itpro.com/policy-legislation/data-protection/356087/eu-fires-warning-shot-to-uk-over-post-brexit-us-data" data-original-url="https://www.itpro.com/policy-legislation/data-protection/356087/eu-fires-warning-shot-to-uk-over-post-brexit-us-data">flow of customer data</a> across international boundaries. </p><p>Julie Brill, Microsoft’s chief privacy officer told <em><a href="https://www.reuters.com/technology">Reuters</a></em> the data boundary solution will “make our customers feel more confident” and enable them to have “clear conversations with regulators on where their data is being processed as well as stored”. </p><h2 id="international-data-flows">International data flows </h2><p>Since the introduction of the <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR</a> in 2018, businesses globally have become increasingly concerned about the legality of international data flows, and operating across a wide variety of regulatory frameworks has presented challenges with regard to compliance. </p><p>The European Commission has been vocal in its intent to enforce regulatory requirements and is currently developing proposals to protect European user data during transferrals to the United States. </p><p>Similarly, in May 2021 the EU's data protection supervisor (EDPS) authority launched a probe into the European Commission’s use of <a href="https://www.reuters.com/technology">Microsoft 365</a> products amid concerns over <a href="https://www.itpro.com/general-data-protection-regulation-gdpr/31065/gdpr-compliance-checklist-is-your-organisation-gdpr" data-original-url="https://www.itpro.com/general-data-protection-regulation-gdpr/31065/gdpr-compliance-checklist-is-your-organisation-gdpr">GDPR compliance</a>. </p><p>Mike Kiersey, EMEA head of sales engineering at Boomi, told <em>IT Pro</em> that ensuring the seamless flow of data is critical to business operations globally. As such, support for organisations to ensure compliance is a welcomed move. </p><p>“Data movement is happening more often in real-time and it has become crucial to successful business operations,” he said. “Therefore, the ability to have iniquitous access to data at speed is key for providers.” </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" data-original-url="/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">What is GDPR? Everything you need to know, from requirements to fines</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/369580/ico-public-sector-not-getting-easier-ride-gdpr-penalties" data-original-url="/policy-legislation/369580/ico-public-sector-not-getting-easier-ride-gdpr-penalties">ICO: The public sector isn’t getting 'an easier ride' with GDPR penalties</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/369227/government-to-replace-gdpr-with-bespoke-british-system" data-original-url="/business/policy-legislation/369227/government-to-replace-gdpr-with-bespoke-british-system">Government reveals fresh replacement for GDPR will be a ‘bespoke, British’ system</a></p></div></div><p>Caroline Carruthers, CEO and co-founder at data consultancy Carruthers and Jackson, warned that the introduction of the EU data boundary “fundamentally makes data flow less efficient” and will not fully prevent personal information from being accessed in different jurisdictions.</p><p>“Data does not respect geography, and attempting to ringfence it will never give 100% protection to customers,” she said.</p><p>“Putting up data boundaries and restricting free flow of data is a regressive step for wider data transformation. Instead of trying to pull up the castle moat on European data, governments and multinationals should be pushing for global data standards to ensure enhanced security does not stifle data innovation.“</p><p>Microsoft said its cloud services “already comply with or exceed EU requirements”, adding that the introduction of the new <a href="https://www.itpro.com/policy-legislation/data-protection/359453/microsoft-to-give-eu-business-customers-greater-control" data-original-url="https://www.itpro.com/policy-legislation/data-protection/359453/microsoft-to-give-eu-business-customers-greater-control">data boundary</a> will provide future benefits for the <a href="https://www.itpro.com/business-strategy/public-sector/361729/the-it-pro-podcast-whats-so-hard-about-public-sector-it" data-original-url="https://www.itpro.com/business-strategy/public-sector/361729/the-it-pro-podcast-whats-so-hard-about-public-sector-it">public sector</a> and commercial customers operating within the EU and EFTA, helping them to remain compliant. </p><p>In addition, as part of the rollout, the tech giant revealed plans to publish new data flow documentation to provide “transparent data insights” for customers whose services will be included in the boundary. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>