<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-GB"
                       href="https://www.itpro.com/uk/feeds/tag/policy-and-legislation"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from ITPro UK in Policy-and-legislation ]]></title>
                <link>https://www.itpro.com/uk/business/policy-and-legislation</link>
        <description><![CDATA[ All the latest policy-and-legislation content from the ITPro  UK team ]]></description>
                                    <lastBuildDate>Tue, 21 Jul 2026 13:55:06 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ AI minister secures cabinet seat as DSIT merged with new business department ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/ai-minister-secures-cabinet-seat-as-dsit-merged-with-new-business-department</link>
                                                                            <description>
                            <![CDATA[ Industry stakeholders have welcomed the move as a sign of the government’s continued support for AI development ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VycEHnbLyooLqsc8T8ELmM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WSbdXBbr3bvKL5SDPmjx6b-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jul 2026 13:55:06 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WSbdXBbr3bvKL5SDPmjx6b-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[UK government AI minister Kanishka Narayan pictured leaving Downing Street following Prime Minister Andy Burnham&#039;s cabinet reshuffle on 20th July, 2026. ]]></media:description>                                                            <media:text><![CDATA[UK government AI minister Kanishka Narayan pictured leaving Downing Street following Prime Minister Andy Burnham&#039;s cabinet reshuffle on 20th July, 2026. ]]></media:text>
                                <media:title type="plain"><![CDATA[UK government AI minister Kanishka Narayan pictured leaving Downing Street following Prime Minister Andy Burnham&#039;s cabinet reshuffle on 20th July, 2026. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WSbdXBbr3bvKL5SDPmjx6b-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>AI minister Kanishka Narayan has been given a seat in incoming prime minister Andy Burnham’s cabinet following a reshuffle. </p><p>Narayan described the move as a sign of Burnham’s “deep commitment to AI’s importance” to the UK economy. </p><p>“AI is likely the most significant technology in human history. Its impact will dwarf other things,” Narayan said in a <a href="https://x.com/KanishkaNarayan/status/2079349690881970365" target="_blank"><u>post on X</u></a>. </p><p>“The best case for it is compelling beyond our dreams: a reindustrialised Britain, stronger national security, public services transformed for the better. The risks, too, are real: it is right that the British public shares those worries, for jobs, for the pace of change.”</p><p>The move comes as the UK's Department for Science, Innovation, and Technology (DSIT), where the AI minister role used to sit, has been <a href="https://www.itpro.com/business/policy-and-legislation/uk-tech-trade-associations-hit-out-amidst-reports-dsit-could-be-scrapped">scrapped in the wake of Burnham’s appointment</a>. </p><p>Under the new setup, DSIT responsibilities will be merged with the freshly minted Department for Business, Innovation, Science, and Trade (DBIST), led by Jonathan Reynolds.</p><p>The role of technology secretary has also been cut. </p><h2 id="ai-focus-welcomed">AI focus welcomed</h2><p>Mark Boost, chief executive of UK-based cloud computing firm, Civo, said retaining and elevating Narayan is a reassuring signal for UK businesses. </p><p>“Giving the AI minister direct access to cabinet decisions demonstrates that the government recognizes AI’s existential importance to our future economy,” he said. </p><p>“Positioned inside a high-powered business and trade department, an AI Minister with Cabinet authority will have real leverage to break down cross-Whitehall silos, accelerate national AI infrastructure, and give British tech companies the proactive backing needed to maintain a competitive global advantage.”</p><p>Andy McLean, CEO of the UK Semiconductor Centre, echoed Boost’s comments, noting that Narayan’s new role is a “positive signal of the importance being placed on AI at the center of government”. </p><p>Boost added, however, that any delays to AI-related initiatives caused by the DSIT shake-up could have a significant impact on global competitiveness. </p><p>“Any Whitehall restructuring brings administrative friction, and because the global tech and AI arms race is moving so quickly, the UK simply cannot afford a pause,” he said. </p><p>“Critical initiatives like the AI Opportunities Action Plan and sovereign infrastructure investments must be ring-fenced from bureaucratic delays.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK tech trade associations hit out amidst reports DSIT could be scrapped ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/uk-tech-trade-associations-hit-out-amidst-reports-dsit-could-be-scrapped</link>
                                                                            <description>
                            <![CDATA[ The move could see the DSIT incorporated within a larger business department ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nCbpcGLaiPCe23SYRSFyA5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xprCkajo3hRXymoms2AZtL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Jul 2026 10:47:43 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xprCkajo3hRXymoms2AZtL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Andy Burnham, MP for Ashton in Makerfield and incoming UK prime minister, pictured on election night. ]]></media:description>                                                            <media:text><![CDATA[Andy Burnham, MP for Ashton in Makerfield and incoming UK prime minister, pictured on election night. ]]></media:text>
                                <media:title type="plain"><![CDATA[Andy Burnham, MP for Ashton in Makerfield and incoming UK prime minister, pictured on election night. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xprCkajo3hRXymoms2AZtL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>UK tech industry stakeholders have hit back at alleged plans to scrap the Department of Science, Innovation and Technology (DSIT). </p><p>TechUK, a trade association for the country’s digital sector, described the rumoured move as a “terrible signal” for a burgeoning industry, which it noted is growing at a rate of 10% per year.</p><p>“Breaking up the work of DSIT endeavours such as the world-leading AI Safety Institute, the Sovereign AI Fund, GDS, and UKRI would slow momentum at a time when pace is essential for both the growth of the economy and our standing on the global stage,” techUK said in an <a href="https://www.linkedin.com/posts/techuk-dsit-uktech-share-7484275907101143040-uJe-/?utm_source=share&utm_medium=member_desktop&rcm=ACoAAB2fu_oBD-NELRF74tAOq8D0G3oxo8O5GqM" target="_blank"><u>open letter</u></a> published on 19 July. </p><p>The backlash comes after the <a href="https://www.ft.com/content/fec8b92e-081f-469f-b1c0-576316c75def?syn-25a6b1a6=1" target="_blank"><u><em>Financial Times</em></u></a><em> </em>reported on 17 July that incoming prime minister Andy Burnham plans to abolish the department. </p><p>Sources told the publication that advisers are creating plans to hand over technology policy to a larger business department, led by former business secretary Jonathan Reynolds. </p><p><em>ITPro </em>approached the DSIT for comment, but did not receive a response by time of publication. </p><p>The move would see a return to a similar setup for science and technology policy prior to the foundation of the department in 2023. </p><p>The DSIT was formed under Rishi Sunak’s premiership and given direct responsibility for policy on these fronts. The department now plays a key role in driving growth in key digital sectors and leading <a href="https://www.itpro.com/strategy/29899/three-reasons-why-digital-transformation-is-essential-for-business-growth">digital transformation</a> across public services. </p><p>According to Dom Hallas, executive director of the Startup Coalition, attempts to incorporate DSIT within a broader business department could dilute its influence and negatively impact the broader technology sector. </p><p>“A mega department would mean British tech competing with British steel for attention. And waste 6 months reorg-ing when time is of the essence. Not good,” Hallas said in a <a href="https://x.com/Dom_Hallas/status/2078132192421576879" target="_blank"><u>post on X</u></a>.</p><p>Matt Clifford, AI adviser to outgoing prime minister Keir Starmer, echoed Hallas’ comments in a <a href="https://x.com/matthewclifford/status/2078136869099868292" target="_blank"><u>post on X</u></a>. </p><p>“This would be a big mistake,” he wrote. “Right now is a critical moment for tech as an economic and national security issue. Tying up our most senior science and tech officials in a reorg wastes time and energy that’s desperately needed for the actual substance.”</p><p>Tim Flagg, CEO of trade association UKAI, took a different view, however, saying that while an overhaul of the department might cause disruption, the creation of a “super-department” could ultimately sharpen the country’s focus on AI. </p><p>“AI has the potential to transform Britain’s economy, our public services, and our security for a generation. Rethinking which department oversees this industry does not necessarily mean Burnham’s Britain is turning its back on that potential,” he said.</p><p>“It could even signal an ambition to go further: AI elevated into a super-department or placed at the very heart of the Cabinet Office. The real danger isn’t the ambition; it’s the distraction and the delay.”</p><h2 id="all-in-on-ai">All-in on AI</h2><p>A recurring theme in the pushback to the proposals lies in the timing and current tech sector trends. </p><p>The UK government has placed a strong focus on supporting the UK’s burgeoning AI sector over the last two years under the premiership of Keir Starmer, with the aim of positioning the country as a leading economy on this front. </p><p>When Downing Street announced the AI Opportunities Action Plan, Starmer <a href="https://www.gov.uk/government/speeches/pm-speech-on-ai-opportunities-action-plan-13-january-2025" target="_blank"><u>described the technology</u></a> as the “defining opportunity of our generation”. </p><p>2025 saw a host of major global tech firms, including <a href="https://www.itpro.com/infrastructure/jensen-huang-uk-ai-potential-infrastructure">Nvidia </a>and <a href="https://www.itpro.com/business/microsoft-ceo-satya-nadella-says-uk-ties-are-stronger-than-ever-as-tech-giant-pledges-usd30bn-investment">Microsoft</a>, pledge billions in support for the UK tech sector, with a particular focus on infrastructure build-outs. </p><p>Additional <a href="https://www.itpro.com/infrastructure/uk-ai-hardware-plan-national-supercomputer-home-grown-semiconductors">hardware and skills-related investment</a> was unveiled by Downing Street at London Tech Week last month. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google DeepMind boss Demis Hassabis issues call to action on AI safety standards ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/google-deepmind-boss-demis-hassabis-issues-call-to-action-on-ai-safety-standards</link>
                                                                            <description>
                            <![CDATA[ The DeepMind co-founder has called for stronger safeguards to tackle AI risks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">N9CHnzo6gHCh4u2mUnVaRf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sRgWXkPhAKNyLRuMvVuzM3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 10:06:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sRgWXkPhAKNyLRuMvVuzM3-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Demis Hassabis, co-founder and CEO of Google DeepMind, pictured during a talk at Day 3 of Cannes Lions 2026 on June 24, 2026 in Cannes, France.]]></media:description>                                                            <media:text><![CDATA[Demis Hassabis, co-founder and CEO of Google DeepMind, pictured during a talk at Day 3 of Cannes Lions 2026 on June 24, 2026 in Cannes, France.]]></media:text>
                                <media:title type="plain"><![CDATA[Demis Hassabis, co-founder and CEO of Google DeepMind, pictured during a talk at Day 3 of Cannes Lions 2026 on June 24, 2026 in Cannes, France.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sRgWXkPhAKNyLRuMvVuzM3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google DeepMind CEO Demis Hassabis says only the United States is up to the task of keeping AI safe – but it's unclear why technology rivals, notably China, would heed an American standards body. </p><p>Hassabis has called for a framework for testing frontier models, on the grounds that he believes progress has been faster than expected and <a href="https://www.itpro.com/technology/artificial-intelligence/openai-says-its-charting-a-path-to-agi-with-its-next-frontier-ai-model">artificial general intelligence (AGI)</a> will arrive imminently. </p><p>He argues that such work should be led by the US because of its technical and economic standing. </p><p>"This US-initiated effort would provide a strong starting point for creating shared international standards on Frontier AI," Hassabis noted in a <a href="https://x.com/demishassabis/status/2076957440109625718" target="_blank"><u>social media post</u></a>. </p><p>"Since this technology is going to affect the entire planet, ideally this framework would spur the international community to reach a consensus on how to manage the most serious risks while ensuring everyone has access to and can benefit from the opportunities that AI brings."</p><p>Hassabis' call for a US-led framework for managing AI follows similar<a href="https://www.cnbc.com/2026/06/17/anthropic-amodei-google-hassabis-us-ai-coalition-g7.html"><u> calls by Anthropic CEO Dario Amode</u></a>i and <a href="https://www.ft.com/content/0c2e1077-f658-4b3d-9040-602615c961ca"><u>OpenAI CEO Sam Altman</u></a>. Following a meeting on the subject last month, <a href="https://qz.com/anthropic-google-deepmind-us-ai-coalition-g7-061826"><u>China called</u></a> for a global AI organization open to all countries, rather than one led by the US. </p><p>The US has pushed for AI developers to submit models a month before release for testing, while the UK has its own testing regime via its AI Security Institute; Hassabis is British, and DeepMind was founded in London before being acquired by Google. </p><p>It's unclear why international AI companies would submit to US approval. The only motivation given by Hassabis is that frontier models would be required to pass this standards body's assessment in order to be deployed in the US. </p><p>Hassabis’ comments come after Anthropic’s Mythos and Fable models were <a href="https://www.itpro.com/technology/artificial-intelligence/why-the-us-imposed-export-controls-on-anthropics-fable-and-mythos-models-and-why-theyve-been-lifted"><u>hit with a temporary export ban</u></a> by the White House amidst security concerns. </p><h2 id="how-would-it-work">How would it work</h2><p>Beyond being US-managed, Hassabis described a standards body that was federally overseen, such as a public-private partnership or self-regulatory organization, pointing to the Financial Industry Regulatory Authority (FINRA). </p><p>"The Standards Body would be responsible for developing assessment protocols and working with appropriate federal agencies and the US National Labs to conduct testing in areas relevant to national security," he said. </p><p>Anyone making a "frontier model" – as defined by a set of benchmarks – would be considered a "frontier lab", and be "encouraged" to adopt certain best practices. </p><p>This would include publishing technical details, ensuring internal security is up to standard, vetting key personnel, and adequate resourcing safety research. </p><p>Non-frontier models, such as those made by startups or academia, would not be expected to take part. </p><p>Hassabis also called for frontier labs to share new modes with the standards body 30 days before release, something the US government has pushed <a href="https://www.reuters.com/world/trump-signed-order-promote-advanced-ai-innovation-security-white-house-says-2026-06-02/"><u>key developers to do with their AI models</u></a>. </p><p>"Once the assessment protocol is shown to be effective and robust, formalisation could quickly follow, meaning that Frontier Models would be required to pass it to be deployed in the US market," Hassabis said. "Labs would also work with the Standards Body to address any critical post-release vulnerabilities."</p><p>Assessments conducted by the standards body would evaluate security, biological, and other threats, and check how well they withstood attempts to dodge guardrails. The tests would be regularly updated. </p><p>"The strength of this approach is it would be technically focused, while at the same time supporting innovation and incentivising responsible behaviour," he said.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FCA recommends expanded powers to boost financial services AI regulation ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/fca-recommends-expanded-powers-to-boost-financial-services-ai-regulation</link>
                                                                            <description>
                            <![CDATA[ The regulator has called for another review about whether AI needs to be regulated ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">EAy6RbbFJtW4kdgsqXDYjf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DMbUEeGtC8v9ZE4MVJneM9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 08 Jul 2026 08:24:19 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DMbUEeGtC8v9ZE4MVJneM9-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Consumer banking concept image showing rows of green credit cards in a digitized environment.]]></media:description>                                                            <media:text><![CDATA[Consumer banking concept image showing rows of green credit cards in a digitized environment.]]></media:text>
                                <media:title type="plain"><![CDATA[Consumer banking concept image showing rows of green credit cards in a digitized environment.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DMbUEeGtC8v9ZE4MVJneM9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Stronger powers could be needed to regulate the use of AI in financial services as consumers flock to the technology for advice, according to the Financial Conduct Authority (FCA).</p><p>Following an investigation into the technology and its impact on consumer finance activities, the regulator has recommended a formal review into how to regulate the use of general-purpose LLMs across the industry. </p><p>The FCA report – known as the Mills Review after its author – noted that companies and consumers are increasingly delegating decisions about finances to AI and AI-powered systems. </p><p>A survey by the regulator found that one-in-five adults were already open to the idea of general-purpose <a href="https://www.itpro.com/technology/artificial-intelligence/amazing-ai-tools-to-try-today">AI tools</a> – such as Claude, <a href="https://www.itpro.com/technology/artificial-intelligence/openai-chatgpt-superapp-overhaul-public-listing">ChatGPT</a>, or Gemini – making financial decisions on their behalf, in particular around debt advice, pensions, and investments. </p><p>While that could help reduce existing challenges such as "advice gaps" and friction around switching services, the FCA warned about risks including fraud and scams, as well as disrupting market structure and competition. </p><p>"AI offers a once-in-a-generation chance to close the information asymmetries and frictions that have long left people making poor financial decisions," said FCA executive director and report author Sheldon Mills in the forward to the review. </p><p>"The right spur, in retail financial services, is ensuring consumers can make healthy ones; regulation, whether supportive or restrictive, should serve that outcome."</p><p>The FCA noted that many consumers may not be aware that they have no formal recourse if something goes wrong, and said some assume they receive equal protection akin to traditional sources of advice. </p><p>Emma Banymandhub, CEO of The Payments Association, agreed that the gap in understanding could cause issues and urged caution on the part of consumers. </p><p>"Consumers may be increasingly comfortable using AI agents for routine tasks such as weekly shopping, but AI-driven savings and investment decisions present a very different set of challenges," Banymandhub commented. </p><p>"While AI can increasingly explain investment concepts and analyse financial information, personalised investment recommendations remain subject to important regulatory constraints."</p><h2 id="ai-gains-traction-in-financial-services">AI gains traction in financial services</h2><p>The financial services sector has rapidly emerged as one of the key growth spaces in terms of the use of AI, with a host of major providers across the UK ramping up adoption of the technology. </p><p>As <em>ITPro </em>previously reported, high street lenders such as <a href="https://www.itpro.com/technology/artificial-intelligence/using-generative-ai-as-a-copilot-is-the-sweet-spot-a-look-at-nationwides-ai-approach">Nationwide</a>, Lloyds Banking Group, and <a href="https://www.itpro.com/business/business-strategy/yorkshire-building-society-touts-customer-service-gains-with-ai-agents">Yorkshire Building Society</a> have all made significant strides on this front over the last six months. </p><p>A <a href="https://publications.parliament.uk/pa/cm5901/cmselect/cmtreasy/684/report.html" target="_blank"><u>parliamentary inquiry</u></a> into the use of AI in financial services, published in January 2026, found that the sector “substantially outpaces” others with regard to AI adoption. </p><p>Indeed, around 75% of UK-based financial services firms are now using the technology, with insurers and large banks among the most aggressive in their pursuit of AI adoption. </p><p>Running parallel to this, the use of AI by consumers is also surging, according to research from Lloyds Banking Group. The firm’s 2025 <a href="https://www.lloydsbankinggroup.com/media/press-releases/2025/lloyds-banking-group-2025/28m-adults-using-ai-to-manage-money.html" target="_blank"><u><em>Consumer Digital Index</em></u></a> found that AI has “rapidly become a financial tool for millions across the UK". </p><p>56% of adults – equivalent to around 28 million people – revealed they’d used AI over the preceding 12 months for financial advice. ChatGPT, for example, was referenced as the most popular platform in this regard, used by six-in-10 consumers. </p><h2 id="what-the-mills-review-recommends">What the Mills Review recommends</h2><p>With this in mind, the Mills Review recommended that the existing "regulatory perimeter" needs to be secured and adapted to take in AI's impact on retail financial services – and that should come via a review within the next six months into how AI is affecting the market. </p><p>"The review should examine how consumers use AI including general purpose LLM tools for personal financial management across savings, investments, pensions, mortgages and debt management, and the implications for competition, innovation and growth," the Mills Review said. </p><p>"It should examine the risks of consumer harm, including how far its usage has or will move along the autonomy spectrum, and any impacts on market integrity and the potential for regulatory arbitrage."</p><p>Based on that review's guidance, the FCA could tweak regulation as necessary, the report said. Beyond that, the review called for the FCA to monitor for evidence of harm and new consumer models, engage with providers for better insight into changes, and be ready with intervention tools and mechanisms as necessary. </p><h2 id="frontier-model-monitoring-in-finance">Frontier model monitoring in finance</h2><p>In the longer term, the Mills Review called for the FCA to keep an eye on frontier model capabilities and AI adoption, considering its impact on its regulatory work, in particular where use of AI falls outside of existing protections and once AI agents start taking more action on behalf of consumers. </p><p>The review also called for stronger powers for the FCA so it can look at these issues more widely. </p><p>"As is clear in the report, we need to keep pace with a rapidly changing environment and the principles-based, outcomes focussed approach we’ve taken on AI – relying on the Consumer Duty and Senior Managers Regime – has been critical to us doing so," said Ashley Alder, chair of the FCA. </p><p>"The recommendations build on work the FCA has been doing – not least allowing firms to test their use of AI with us – and our own use of AI to be a smarter regulator, more efficient and effective."</p><p>Banymandhub<strong> </strong>added that walking that balance between enabling AI and protecting consumers and companies was key.  </p><p>"The FCA’s Mills Review reinforces that firms should treat agentic AI as an accountability and governance issue now, while providing greater confidence to innovate responsibly as AI adoption accelerates," she said. </p><p>"AI has enormous potential for financial services, but realising that potential will depend on strong governance, clear accountability and maintaining consumer trust."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Startup founders lament 'regulatory friction' despite EU simplification efforts ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/startup-founders-lament-regulatory-friction-despite-eu-simplification-efforts</link>
                                                                            <description>
                            <![CDATA[ Entrepreneurs are spending a fortune on compliance, and it’s forcing some to consider relocating ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">af7qTFWabwrvev3mxoG6L3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YfH4YfBJwqGBq5tCEPQ77n-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 01 Jul 2026 09:41:31 +0000</pubDate>                                                                                                                                <updated>Thu, 02 Jul 2026 12:44:12 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YfH4YfBJwqGBq5tCEPQ77n-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Digital sovereignty concept image showing digitized flag of the European Union (EU) imposed over a blue background with binary code. ]]></media:description>                                                            <media:text><![CDATA[Digital sovereignty concept image showing digitized flag of the European Union (EU) imposed over a blue background with binary code. ]]></media:text>
                                <media:title type="plain"><![CDATA[Digital sovereignty concept image showing digitized flag of the European Union (EU) imposed over a blue background with binary code. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YfH4YfBJwqGBq5tCEPQ77n-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Europe’s complex network of overlapping regulations is hitting startup founders hard and holding back business, according to a new research by startup support organization DutchBasecamp. </p><p>Some 79% of tech founders claim they've been hit by regulatory friction over the last year, according to the <a href="https://dutchbasecamp.org/eu-regulations-founders-perspective" target="_blank"><u><em>The Realities of Scaling in Europe</em></u></a> report, which was launched in partnership with the Computer & Communications Industry Association (CCIA).</p><p>More than half (58%) said they'd delayed entering another EU market, 45% have paused or canceled features, and 44% have experienced delayed or lost deals.</p><p>As negotiations on the Digital Omnibus continue, the CCIA warned that many meaningful simplification measures could fall by the wayside, which has the potential to further compound challenges faced by startups. </p><p>Some member states are resisting a proposal allowing businesses to report a <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>incident once, rather than separately under seven overlapping frameworks. </p><p>Meanwhile, a fix that would establish legitimate interest as a legal basis for <a href="https://www.itpro.com/technology/artificial-intelligence/meta-ditching-its-responsible-ai-team-doesnt-bode-well">responsible AI training</a> has been stripped out. </p><p>While postponing certain deadlines has provided some breathing room, many simplifications have been rejected, leaving developers with limited implementation time while essential codes, guidance, and standards are still missing. </p><p>“We warned from the start that the Commission’s proposals to simplify the patchwork of EU tech and digital rules were only the bare minimum. Instead of going further, Parliament and Council are now weakening, rejecting, or delaying even the most basic fixes," said Daniel Friedlaender, senior vice president and head of CCIA Europe. </p><p>“Europe’s innovators have shown remarkable patience in navigating today’s regulatory maze, but that patience is running out. EU institutions and member states need to wake up: 2026 must bring real improvements for tech companies. Europe knows the problems. If we refuse to fix them, we can’t be surprised if our founders look outside the EU for success.”</p><h2 id="growing-regulatory-friction">Growing regulatory friction</h2><p>Nearly a quarter of survey respondents said they'd spent more than 30% of their budgets on compliance costs, while 24% are considering or have already relocated their headquarters due to regulation. </p><p>In January, the European Investment Bank, with the European Commission, found that roughly one-in-ten EU scale-ups have relocated abroad, with around 85% of those moving to the United States.</p><p>The Commission’s Joint Research Center put the headquarters-relocation rate for venture-backed startups at between 3.3% and 4.3%, ten times the rate for comparable non-VC-backed firms.</p><p>More than half of founders said they'd steered clear of an EU country because of regulatory concerns, and only 21% said they'd seen no material impact from EU or national rules. </p><p>"Europe is already losing tech founders, products, and growth," said Masha Moisseyeva, managing director of DutchBasecamp. </p><p>"When 45% of those surveyed have paused or cancelled features, 58% have delayed entering another EU market, and 44% have lost or delayed deals in a single year, the urgent need for regulatory simplification is no longer a theoretical debate about EU competitiveness. The damage is happening now.” </p><h2 id="regulatory-confusion-is-rife">Regulatory confusion is rife</h2><p>Much of the cost, the researchers found, comes not from compliance itself but from not knowing what compliance will require. </p><p>Indeed, founders often cite uncertainty surrounding future EU AI Act obligations before any requirement has formally bound them.</p><p>“Founders are not asking the EU to lower its standards. They are asking for clear, workable rules they can rely on across the Single Market," said Moisseyeva. </p><p>"Instead, uncertainty and overlapping obligations are dictating what they build, who they serve, and how fast they grow.” </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The legislative challenges of cybersecurity ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/the-legislative-challenges-of-cybersecurity</link>
                                                                            <description>
                            <![CDATA[ Technology is constantly evolving at a pace that legislation struggles to keep up with. Is it possible for governments to develop cybersecurity legislation that will not be obsolete before it is enacted? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4BZxphgVGqyWbnnpgbiHiM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/t5zGC2uXPBqGdnfQdHUCeS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 30 Jun 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Peter Ray Allison ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/t5zGC2uXPBqGdnfQdHUCeS-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[IoT cybersecurity concept image showing a digitized padlock sitting on a blue circuit board atop network traffic.]]></media:description>                                                            <media:text><![CDATA[IoT cybersecurity concept image showing a digitized padlock sitting on a blue circuit board atop network traffic.]]></media:text>
                                <media:title type="plain"><![CDATA[IoT cybersecurity concept image showing a digitized padlock sitting on a blue circuit board atop network traffic.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/t5zGC2uXPBqGdnfQdHUCeS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>People in the technology sector often joke that anything new in winter will be obsolete by spring. This is especially the case in cybersecurity, where hacker groups and cybersecurity teams are locked in an ever-escalating war of attrition.</p><p>The speed of obsolescence far outpaces the legislative process: it can take up to two years for government bills to be enacted into law. This is due to the parliamentary process, where various readings, committee hearings and reports are required to ensure that bills are adequately scrutinized.</p><h2 id="an-outdated-system">An outdated system</h2><p>“The legislative process in this country is essentially a Victorian process, in the sense it takes a long time,” says James Morris, chairman of CSBR, who spoke to <em>ITPro </em>earlier this month at InfoSecurity Europe in London. </p><p>“Meanwhile, the world is changing every day. How you deal with that is, I think, a question of not wanting to try and do everything at once.”</p><p>Legislation tends to lag behind technology as the speed of technical innovation far outpaces the law-making process. Therefore, cybersecurity legislation risks becoming redundant before it is enacted.</p><p>Compounding this challenge is the intensification of cyber threats, in particular the problem of state-sponsored hacker teams and organized crime groups repeatedly targeting national infrastructure for financial or political gain.</p><p>“The <a href="https://www.itpro.com/security/uk-government-calls-on-firms-to-sign-cyber-resilience-pledge-as-security-sector-booms"><u>Cyber Security and Resilience Bill</u></a> represents a step change to our national security that will protect the services people rely on every day - reducing the risk of disruption to public services and businesses, and ensuring a faster national response when threats emerge,” said a spokesperson for the government. </p><p>“The Bill gives government powers to update cyber regulations as risks evolve, so our defences can keep pace with evolving threats. But there is also a lot we can do, and are doing, outside legislation. For instance, we're urging organizations across the economy to boost their resilience by signing up to the<a href="https://www.itpro.com/security/uk-government-calls-on-firms-to-sign-cyber-resilience-pledge-as-security-sector-booms"><u> Cyber Resilience Pledge.</u></a>”</p><p>As few politicians have an in-depth understanding of cybersecurity, they hence rely on committee hearings in order to become informed on the subject. However, the expert speakers have purely an advisory capacity, so governments are not bound to abide by their guidance.</p><p>As a consequence, there is often friction between government regulators and private enterprise. The government regulators could perceive emerging technologies as a potential risk to the public, whilst technology companies might consider that regulatory guard rails hamper development and innovation.</p><h2 id="regulation-vs-innovation">Regulation vs innovation</h2><p>“There's a tension between regulation and innovation, and wanting the UK to be a technological cyber power in its own right,” says Morris. </p><p>“That’s a constant tension in policy, and that applies to the Cybersecurity and Resilience Bill as well, because as that regulatory system starts to get embedded, it's going to have an impact on small and medium-sized companies. We don't want to over-regulate markets which present the UK with growth opportunities.”</p><p>Given the rate of progress in technology, acts of law set broad expectations, with associated government regulation intended to give specific minimum expected requirements. Regulations are far easier to revise than government acts, as they often incorporate the so-called Henry VIII powers.</p><p>Henry VIII powers are clauses within government regulation that bestow upon government ministers the authority to change secondary legislation (such as regulations) without oversight from Parliament. However, the lack of transparency in Henry VIII powers means they often have restrictions on the extent of their authority, in order to limit potential abuse.</p><p>In order to ensure accountability for Henry VIII powers, the authorising partner can be cross-examined before a parliamentary committee on the reasoning behind regulatory updates they actioned.</p><p>Organizations can help by engaging with the legislative process, through offering their expertise to parliamentary committees, which regularly seek expert views.</p><p>“Any responsible government needs to be engaging. One of my concerns around the Cybersecurity and Resiliency Bill has been it's a bit top down. It gives government a lot of power and doesn't really talk about consulting with business,” says Morris. </p><p>“I'd like to see more of that because you're not going to make progress in improving standards across the board if you just impose stuff top down.”</p><h2 id="the-role-of-ai">The role of AI</h2><p>AI is one of the key areas of current focus and technological development. It is one of the most rapidly developing fields of technology, and there are growing calls from many sectors for regulation.</p><p>“The challenge is about timescale and the rapidity of innovation, because when the Cybersecurity and Resilience Bill was introduced 16 months ago, AI was being talked about,” says Morris. </p><p>“But in that period, if you think of all the different innovations and things that have happened around AI, it's become much more of a central focus in discussions about resilience and critical national infrastructure.”</p><p>In addition to this, data sovereignty is coming to the fore as one of the key issues surrounding the use of AI. “I think we should be developing more sovereign technological capability, because we are very dependent on US data processing, and so on,” says Morris.</p><p>Many state-run organizations are colossal institutions with massive amounts of data, which could potentially be used to train AI tools to help government departments become more efficient. For example, Microsoft’s Dragon Copilot is being <a href="https://www.itpro.com/technology/artificial-intelligence/how-dragon-copilot-is-helping-clinicians-spend-more-time-with-their-patients-by-peter-ray-allison"><u>trialled</u></a> to transcribe patient consultations with a clinician and automate the associated note-taking and form-filling.</p><p>Also, with current geopolitics, there is a question regarding whether the government and national infrastructure should move towards using systems developed within the UK. The UK government has previously found itself reliant on external technology providers, such as <a href="https://www.itpro.com/mobile/5g/356443/uk-gov-bans-huawei-from-5g-network-in-major-u-turn"><u>Huawei</u></a>, which could potentially cause security concerns and data sovereignty issues.</p><p>“We need to look at how the legislative process could be improved, as it not just affects cybersecurity, but lots of other aspects, particularly around infrastructure development,” Morris adds. </p><p>“In the age we're living in, we need to look at how we can speed up legislation, because parliament is still operating like it was on a very traditional model.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AWS says cloud market gatekeeper designation risks ‘deterring European investment and innovation’ as EU regulators plot competition crackdown ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/aws-says-cloud-market-gatekeeper-designation-risks-deterring-european-investment-and-innovation-as-eu-regulators-plot-competition-crackdown</link>
                                                                            <description>
                            <![CDATA[ Gatekeeper designation under the legislation would force AWS and Microsoft to make concessions ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">CddusqTAFnsE38t8Co9iUW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/i2VUb2oLPjFFkMn6CA4Huj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 26 Jun 2026 16:06:44 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/i2VUb2oLPjFFkMn6CA4Huj-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Amazon Web Services (AWS) logo and branding pictured at the Hannover Messe industrial trade fair for mechanical and electrical engineering and digital industries.]]></media:description>                                                            <media:text><![CDATA[Amazon Web Services (AWS) logo and branding pictured at the Hannover Messe industrial trade fair for mechanical and electrical engineering and digital industries.]]></media:text>
                                <media:title type="plain"><![CDATA[Amazon Web Services (AWS) logo and branding pictured at the Hannover Messe industrial trade fair for mechanical and electrical engineering and digital industries.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/i2VUb2oLPjFFkMn6CA4Huj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Amazon has hit back at EU lawmakers after the European Commission signalled its intent to designate the hyperscaler as a “gatekeeper” under the Digital Markets Act (DMA). </p><p>In a statement on 25 June, the Commission noted that <a href="https://www.itpro.com/amazon-web-services">Amazon Web Services (AWS) </a>and Microsoft “hold an entrenched and durable position” in the EU cloud computing sector, with both potentially harming competition across the region. </p><p>AWS and Microsoft have already been designated as gatekeepers in other business areas, and with cloud computing, lawmakers are equally concerned the duo could stifle competition. </p><p>“Their <a href="https://www.itpro.com/627952/what-is-cloud-computing">cloud computing</a> services AWS and Azure have achieved significant turnover, and their operational capacity and investments seem to have significantly outpaced those of competitors,” the Commission said. </p><p>“They both have vast and entrenched user bases and appear to benefit from lock-in effects and high switching costs, in addition to a large ecosystem.”</p><p>The Commission also highlighted competition concerns regarding the influence of AI services on the broader market, noting that both firms’ <a href="https://www.itpro.com/technology/artificial-intelligence/amazing-ai-tools-to-try-today">AI tools</a> have “become a decisive factor in cloud procurement”. </p><p>“Whilst AI is significantly increasing the demand for cloud-related services, AWS and Azure appear to retain a large proportion of this increased demand within their respective ecosystems.”</p><p>While the Commission noted that this is a “preliminary view”, the statement follows a seven month investigation into the influence of both companies. </p><p>If designated under the legislation, lawmakers could impose a series of obligations on both companies, such as the introduction of new interoperability and data portability features. </p><p>Teresa Ribera, the EU’s executive vice president for Clean, Just, and Competitive Transition, said both companies will have the opportunity to respond before “final decisions are taken”. </p><h2 id="aws-hits-back-at-eu-claims">AWS hits back at EU claims</h2><p>AWS has contested the claims made by the European Commission, with a spokesperson suggesting the preliminary findings “disregard the breadth of cloud services available to European customers”. </p><p>The spokesperson added that designation under the legislation could risk “deterring future European investment and innovation”. </p><p>“AWS faces healthy competition and customers across Europe have more choice, lower prices, and greater flexibility than ever before,” the spokesperson said. </p><p>“The EU already has comprehensive cloud regulation through the Data Act, and adding another heavy layer of overlapping regulation under the DMA undermines European competitiveness and access to cutting-edge information technology.”</p><p>AWS said it intends to work closely with the Commission to “reach the right outcome for customers”. </p><h2 id="long-running-competition-concerns">Long-running competition concerns</h2><p>The move by the Commission comes as relations between US-based tech giants and the EU grow increasingly tense. </p><p>European regulators have made repeated attempts to limit the influence of US firms across the region, having been locked in a series of battles with Microsoft over its dominance in the productivity software market. </p><p>Geopolitical tensions, however, are adding fuel to the fire on this front, particularly with regard to <a href="https://www.itpro.com/security/data-protection/what-businesses-need-to-know-about-data-sovereignty">data sovereignty</a>. </p><p>Critics argue that European organizations have become over reliant on US technology services, prompting calls to seek alternative, home-grown options. </p><p>Earlier this month, the Commission unveiled the <a href="https://www.itpro.com/business/policy-and-legislation/the-eu-is-charting-a-course-to-digital-independence-with-the-technological-sovereignty-package-heres-what-you-need-to-know">technological sovereignty package</a>, a series of measures aimed at strengthening digital sovereignty capabilities across the EU - spanning areas such as AI, cloud computing, and semiconductor manufacturing.</p><p>Speaking at the time, Ursula von der Leyen, president of the European Commission, said the package comes in direct response to concerns about overreliance on foreign technology services.</p><p>“We cannot afford to depend on others for the technologies that keep our hospitals running, our energy grids stable, and our services secure,” she said.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The EU is charting a course to digital independence with the technological sovereignty package – here’s what you need to know ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/the-eu-is-charting-a-course-to-digital-independence-with-the-technological-sovereignty-package-heres-what-you-need-to-know</link>
                                                                            <description>
                            <![CDATA[ New legislation looks to shore up digital sovereignty and reduce reliance on foreign tech ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jxqNQPxZhhn5gY2TaqZetH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YPLAJxoRSrPttgxeZWQkeG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 04 Jun 2026 11:13:21 +0000</pubDate>                                                                                                                                <updated>Thu, 04 Jun 2026 11:54:47 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YPLAJxoRSrPttgxeZWQkeG-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[European Union (EU) concept image showing flag on a digitized background with ripples flowing out from 12 stars.]]></media:description>                                                            <media:text><![CDATA[European Union (EU) concept image showing flag on a digitized background with ripples flowing out from 12 stars.]]></media:text>
                                <media:title type="plain"><![CDATA[European Union (EU) concept image showing flag on a digitized background with ripples flowing out from 12 stars.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YPLAJxoRSrPttgxeZWQkeG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The European Commission has unveiled a series of measures aimed at strengthening digital sovereignty across the union, in a move that’s sparked mixed reaction from industry stakeholders. </p><p>The European technological sovereignty package will bolster the EU’s capabilities across a range of areas, including AI, cloud, open source, and semiconductor manufacturing. </p><p>Ursula von der Leyen, president of the European Commission, said the move comes in direct response to concerns over long-running reliance on foreign technology services. </p><p>“We cannot afford to depend on others for the technologies that keep our hospitals running, our energy grids stable, and our services secure,” she said. </p><p>“This is about protecting our citizens, defending our interests, and making our own choices. Europe has the talent, the research excellence, the industrial base and the Single Market. Together, we must turn these strengths into technological sovereignty.”</p><p>The technological sovereignty package will focus on four key areas, according to the Commission, and includes two legislative proposals – the Chips Act 2.0 and the Cloud and AI Development Act (CADA).</p><p>A new Open Source Strategy and a Strategic Roadmap for Digitalisation and AI in Energy is also included in the package. </p><p>The first of these is aimed at “securing the semiconductor base for Europe’s AI ambition” and will focus on building capacity for semiconductor manufacturing and investment. </p><p>The CADA legislation, meanwhile, will increase investment for research and development and improve support for data center build-outs across the region. </p><p>Notably, this legislative package will also introduce a single EU-wide framework to help organizations <a href="https://www.itpro.com/security/cispe-sovereign-and-resilient-cloud-services-framework-eu-sovereignty-washing">assess cloud and AI provider sovereignty credentials</a>. </p><p>Jaap Templeman, head of digital business practice in the Simmons & Simmons Amsterdam office, said the package represents a “welcome and necessary boost” to the EU and “ward off a long-term technological dependence” on big tech. </p><p>“Sadly, geopolitical developments show how vulnerable transatlantic dependence can be. The strict sustainability and security framework around the development of data center, AI, and chips capabilities might appear counterproductive to improving the EU's ability to compete but is of course necessary,” he said.</p><h2 id="concerns-over-trusted-partner-elements">Concerns over ‘trusted partner’ elements</h2><p>While industry stakeholders have welcomed moves to bolster European sovereignty efforts, concerns have been raised over certain aspects of the package. </p><p>The CADA legislation outlines a series of trust tiers for cloud services used by public sector organizations. These are based on considerations such as ownership and control of infrastructure, data processing and protection, and <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a>. </p><p><a href="https://digital-strategy.ec.europa.eu/en/policies/cloud-and-ai-development-act" target="_blank"><u>According to the Commission</u></a>, the four trust levels are: </p><ul><li>Level 1: where data is processed and stored in infrastructure located in the Union</li><li>Level 2: where providers must demonstrate independence from third countries and transparency over their software supply chain</li><li>Level 3: where providers must be owned and controlled from the EU and meet additional criteria, such as personnel citizenship. The Commission can recognize third-country providers</li><li>Level 4: where providers have full transparency and control over their software supply chain and no interference from a third country</li></ul><p>Essentially, this aspect of the legislation aims to bolster protection of sensitive public sector and national security-related data. Public sector organizations will be required to use services that meet the requirements of at least Level 1, for example.</p><p>More sensitive areas, such as defense, national security, or law enforcement, meanwhile, will require providers that adhere to higher tiers. </p><p>Trade groups have warned that there is potential for these requirements to limit access for foreign providers. The Computer & Communications Industry Association (CCIA) described the legislation as a “dangerous recipe for progressive market shutdown”. </p><p>“By requiring Member States to assess which use cases demand specific sovereignty levels – levels that non-EU vendors would be unable to meet by default – the CADA relies on an impractical Commission framework that no international provider could possibly satisfy,” the trade group claimed. </p><h2 id="open-source-focus-welcomed">Open source focus welcomed</h2><p>The Commission’s focus on open source is one aspect of the package that has drawn praise. Lawmakers specifically highlighted the region’s burgeoning open source community, which is now home to over three million contributors. </p><p>Under the Open Source Strategy, the Commission aims to capitalize on this growing market to accelerate the development of sovereign solutions. The Commission said it plans to “scale up” open source alternatives in areas such as cloud, AI, and cybersecurity. </p><p>“The strategy will also support greater use of open source in public administrations through procurement guidelines and practical best practice,” the Commission said. “It will encourage uptake of European solutions and support standards and interoperability, including through initiatives such as the Open Internet Stack.”</p><p>Amanda Brock, CEO of OpenUK, said the UK should take note of the Commission’s acknowledgement of open source’s potential. </p><p>"It has taken decades of work, which included many from the UK, to get the EU to the position of recognizing the role of <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> in today’s strategy,” she said. </p><p>“There cannot be <a href="https://www.itpro.com/security/data-protection/lets-talk-about-digital-sovereignty">digital sovereignty</a> today without open source. As Hugging Face have said, open source is the cornerstone of sovereignty. The UK, despite our policy being 15 years old, is way behind today, and we need to build the infrastructure for this,” Brock added. </p><p>“Despite the UK being Europe’s leader in open source software and AI, we still fail to recognize this in our policy.  </p><p>Before adoption and entry into force, the European Commission said the package and legislative proposals will be negotiated by the European Parliament. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google facing massive EU fine as it appeals search suit in US ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/google-facing-massive-eu-fine-as-it-appeals-search-suit-in-us</link>
                                                                            <description>
                            <![CDATA[ The European Union is said to be looking to avoid a big fine, but that may require Google to agree to changes ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bWfswsne4MUpAoRejhoJGN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RZ7UvjBTtZr8WMgy6yjh96-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 26 May 2026 10:15:10 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RZ7UvjBTtZr8WMgy6yjh96-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google logo pictured above the entrance to the company&#039;s King&#039;s Cross office in London, UK. ]]></media:description>                                                            <media:text><![CDATA[Google logo pictured above the entrance to the company&#039;s King&#039;s Cross office in London, UK. ]]></media:text>
                                <media:title type="plain"><![CDATA[Google logo pictured above the entrance to the company&#039;s King&#039;s Cross office in London, UK. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RZ7UvjBTtZr8WMgy6yjh96-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google could be facing a fine from the EU in the high hundreds of millions of euros, according to reports, following an investigation by the European regulator into its search.</p><p>The fine relates to a European Commission (EC) investigation into whether Google breached the Digital Markets Act by favouring its own search engine. Launched last year, the EC sent preliminary findings to the company, accusing it of preferential treatment of Google's own services in its search results, including shopping, hotels, finance, and more. Google was then given a chance to respond and suggest changes to address the problems. </p><p>A report in the German newspaper Handelsblatt reported that the EC is considering fines in the hundreds of millions of euros after failing to come to an agreed solution. </p><h2 id="next-steps">Next steps</h2><p>However, an EC spokesperson told <em>Reuters</em> that the regulator was keen to get Google in line rather than issue a punitive fine, suggesting that the EC was more interested in securing compliance. </p><p>"Even with ‌our ⁠negotiations on future solutions, we will not hesitate to move to the next steps as soon as possible," spokesperson Thomas Regnier told <a href="https://www.reuters.com/world/europe/eu-plans-fine-google-high-triple-digit-million-euro-sum-handelsblatt-reports-2026-05-25/"><em>Reuters</em></a>. </p><p>The EC earlier this month gave Google more time to develop a proposal after its previous efforts to avoid a fine failed to win over the regulator. But Google said in response to <em>Reuters</em> that it had already made too many changes to its search tool. <em>ITPro</em> contacted Google for comment, but has yet to hear back at the time of publishing. </p><p>Last year, Google-owner Alphabet's profit topped $132 billion with revenue over $400bn. While this fine would be the largest under the 2022 <a href="https://www.itpro.com/business/policy-legislation/368435/what-is-the-eus-digital-markets-act-dma">Digital Markets Act</a>, the company has been hit by much bigger fines than that proposed by the EC this time around. In 2017, it was fined €2.4 billion for antitrust complaints related to Google Shopping, and the next year was hit by a €4.3bn over Android and €1.4bn for a case relating to online advertising. Last year, the EC leveled a €‎2.95bn fine following an investigation into adtech, and started a fresh investigation into <a href="https://ec.europa.eu/commission/presscorner/detail/da/ip_25_2964">Google over its use of online content to train its AI</a>. </p><h2 id="appeal-in-the-us">Appeal in the US</h2><p>The reports come days after Google filed an appeal in US courts <a href="https://www.itpro.com/software/google/google-has-a-monopoly-over-the-online-search-market-us-court-rules">against a decision in 2024</a> that saw the company deemed a "monopolist" for its search deals, which included paying billions of dollars annually to rivals, including Apple, to use Google as their default for search. Google was ordered to share some search data with rivals, among other remedies.</p><p>Such an appeal is no surprise, but Google is arguing that the judge in the case made legal errors and that its search engine dominated because it was technically "superior." </p><p>"Competition produces winners and losers," the company said in its filing. "And sometimes a firm – by innovating better, investing more, or just working harder – will leave its rivals behind."</p><p>Last week, Google unveiled <a href="https://www.itpro.com/technology/artificial-intelligence/google-adds-ai-to-the-search-box">significant changes to its search tool</a>, heavily embedding AI into the financially lucrative service. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ European Commission opens public consultation on long-awaited draft for high-risk AI guidelines ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/european-commission-opens-public-consultation-on-long-awaited-draft-for-high-risk-ai-guidelines</link>
                                                                            <description>
                            <![CDATA[ Guidance aims to help organizations and regulators decide whether their AI products and deployments need to conform to tougher rules ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3wo6mFPTKWFyxRVUWbjZLF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qnGSwbfzp9zTsFt2t49oUT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 20 May 2026 11:08:58 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qnGSwbfzp9zTsFt2t49oUT-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[EU flags fly outside the union headquarters in Brussels, Belgium.]]></media:description>                                                            <media:text><![CDATA[EU flags fly outside the union headquarters in Brussels, Belgium.]]></media:text>
                                <media:title type="plain"><![CDATA[EU flags fly outside the union headquarters in Brussels, Belgium.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qnGSwbfzp9zTsFt2t49oUT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The European Commission has published its long-awaited draft guidance on the classification of <a href="https://www.itpro.com/business/policy-and-legislation/this-closes-a-gap-that-has-caused-real-uncertainty-in-the-market-changes-to-eu-ai-act-implementation-deadlines-welcomed-by-industry">high-risk AI systems</a> and has opened a public consultation.</p><p>The <a href="https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems">guidelines</a> aim to help assess whether an AI system should be classified as high-risk; either intended to be used as a safety component of a product, or carrying the potential to endanger health, safety or fundamental rights. If they do, they need different treatment under Article 6 of the <a href="https://www.itpro.com/business/policy-and-legislation/how-the-eu-ai-act-compares-to-other-international-regulatory-approaches">AI Act</a>.</p><p>"The guidelines are intended to support providers, deployers, and other relevant actors in determining whether an AI system falls within the high-risk category," the Commission explained. </p><p>"They offer clarifications on the relevant provisions of the <a href="https://www.itpro.com/technology/artificial-intelligence/eu-ai-act-everything-you-need-to-know-about-the-legislation-including-rules-requirements-and-who-will-be-forced-to-comply">AI Act</a> and include practical examples to illustrate how the classification should be assessed in different areas and use cases."</p><p>The guide comes in two parts, with the first covering AI systems that are themselves products, or safety components of products, under sectoral harmonization legislation, including the Machinery Regulation, the Toys Safety Regulation, the Radio Equipment Directive, medical devices, and the automotive and aviation regimes.</p><p>The second, meanwhile, covers AI systems that can significantly affect people's health, safety, or fundamental rights in specific use cases listed in the AI Act.</p><p>Article 6(3), covering the significant risk of harm to health, safety, or fundamental rights, is where most providers will go wrong, said Patrick Sullivan, VP of Strategy and Innovation at compliance provider A-LIGN.</p><p>There's a carve-out with four conditions – that the AI performs a narrow procedural task, improves the result of a previously completed human activity, detects decision-making patterns or deviations without replacing or influencing the human assessment, and performs a preparatory task to an Annex III assessment.</p><p>But, said Sullivan, hard exception applies, with an Annex III system is always high-risk where it performs profiling of natural persons. "This matters enormously for HR systems, credit decisioning, and any system that builds individual-level predictive profiles," he warned.</p><p>The document has been significantly delayed, having been expected to be published back in February; and following the political agreement on the AI Omnibus, there's a new enforcement timeline. </p><p>Rules for systems used in certain high-risk areas – including biometrics, critical infrastructure, education, employment, migration, asylum and border control – will apply from 2 December 2027, while for systems integrated into products such as robotics and industrial machinery, they'll come into effect on 2 August 2028.</p><p>The Commission is now holding a consultation on the guidelines, aimed at anyone with an interest in the development, deployment, supervision or use of AI systems is invited to contribute. </p><p>"This includes AI providers and developers, organisations using AI systems, public authorities, researchers, civil society organisations, supervisory bodies and members of the public," it explained.</p><p>The consultation is open until 23 June.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft to face UK competition probe over business software practices ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/microsoft-to-face-uk-competition-probe-over-business-software-practices</link>
                                                                            <description>
                            <![CDATA[ The tech giant could be designated with strategic market status, meaning it holds undue sway over the UK software ecosystem ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bSCkiEVLnnXGzp7e4kaXbF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/36AJ5mQDV3HZE6moYvjG2Y-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 15 May 2026 06:46:00 +0000</pubDate>                                                                                                                                <updated>Fri, 15 May 2026 08:21:26 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/36AJ5mQDV3HZE6moYvjG2Y-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft logo and branding pictured on a sign on top of a New York City office building, with clear skies and skyscraper in background.]]></media:description>                                                            <media:text><![CDATA[Microsoft logo and branding pictured on a sign on top of a New York City office building, with clear skies and skyscraper in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft logo and branding pictured on a sign on top of a New York City office building, with clear skies and skyscraper in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/36AJ5mQDV3HZE6moYvjG2Y-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK Competition and Markets Authority (CMA) has launched a strategic market status (SMS) investigation into Microsoft’s software licensing practices.</p><p>The probe, which the regulator <a href="https://www.itpro.com/software/cma-launches-microsoft-probe-amid-software-licensing-concerns"><u>touted in late March</u></a>, aims to establish whether the tech giant’s position in the market has a negative impact on competition and consumer flexibility. </p><p>In a statement announcing the move, the CMA said the probe will primarily focus on business software products used by organisations across the country, including: </p><ul><li>Productivity software</li><li>Personal computer and server operating systems</li><li>Database management systems</li><li>Security software</li></ul><p>Microsoft business products, which include Windows, Word, Excel, Teams, and Copilot, are used by hundreds of thousands of firms and public sector organizations across the country, the CMA noted, with more than 15 million commercial users. </p><p>The regulator highlighted concerns that UK customers “may not always be able to effectively combine software from Microsoft with that of other providers”. This, it said, could limit their ability to access preferred products at competitive prices. </p><p>“The CMA’s investigation will examine whether Microsoft has SMS in business software and consider whether it can use that position to limit customer choice,” the CMA said. </p><p>“It will assess whether bundling of products, limits in interoperability or default settings can prevent customers switching and weaken the competitive constraints Microsoft faces from rivals.”</p><p>Notably, the CMA said its decision to launch the probe comes in the wake of a previous <a href="https://www.itpro.com/business/policy-and-legislation/microsoft-amazon-cloud-practice-changes-spark-mixed-industry-reaction">investigation into the UK cloud services market</a>. </p><p>The regulator’s lengthy probe found the dominance of hyperscalers including Microsoft and Amazon Web Services (AWS) had a negative impact on competition in the UK market. </p><p>Microsoft has repeatedly faced scrutiny over its software licensing practices. Slack, for example, <a href="https://www.itpro.com/software/salesforce-says-microsofts-anticompetitive-tying-of-teams-harmed-business-in-triumphant-response-to-eu-concessions-agreement">filed an EU complaint in 2020</a> amid claims the company had engaged in anticompetitive behavior with Teams bundling practices. </p><p>EU-based trade group, Cloud Infrastructure Services Providers in Europe (CISPE), filed a similar complaint in 2022, alleging that Microsoft imposed higher charges for customers running software on rival cloud platforms. </p><p>Microsoft and <a href="https://www.itpro.com/software/microsoft-and-cispe-make-significant-breakthrough-with-software-licensing-concessions"><u>CISPE agreed to a settlement in mid-2025</u></a>, which was met with criticism by other industry groups. </p><h2 id="cma-seeks-business-feedback">CMA seeks business feedback</h2><p>This latest probe into Microsoft practices must be completed within nine months, according to the regulator. A decision on whether to designate the tech giant with strategic market status is expected by February 2027. </p><p>In the meantime, the CMA said plans to gauge the thoughts of businesses across the country using Microsoft products, as well as challenger companies, over whether product choices may be limited. </p><p>This includes concerns surrounding product bundling, lack of interoperability, and default settings used by the company. </p><p>“Our aim is to understand how these markets are developing, Microsoft’s position within them and to consider what, if any, targeted action may be needed to ensure UK organizations can benefit from choice, innovation and competitive prices,” said Sarah Cardell, chief executive of the CMA.</p><p>A spokesperson for Microsoft told <em>ITPro</em>: "We are committed to working quickly and constructively with the CMA to facilitate its review of the business software market."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘This closes a gap that has caused real uncertainty in the market’: Changes to EU AI Act implementation deadlines welcomed by industry ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/this-closes-a-gap-that-has-caused-real-uncertainty-in-the-market-changes-to-eu-ai-act-implementation-deadlines-welcomed-by-industry</link>
                                                                            <description>
                            <![CDATA[ New implementation deadlines for the EU AI Act could help remove “genuine friction” for European companies ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wTrcGJSwGQ4XAiubLrguKi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YPLAJxoRSrPttgxeZWQkeG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 11 May 2026 14:23:01 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YPLAJxoRSrPttgxeZWQkeG-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[European Union (EU) concept image showing flag on a digitized background with ripples flowing out from 12 stars.]]></media:description>                                                            <media:text><![CDATA[European Union (EU) concept image showing flag on a digitized background with ripples flowing out from 12 stars.]]></media:text>
                                <media:title type="plain"><![CDATA[European Union (EU) concept image showing flag on a digitized background with ripples flowing out from 12 stars.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YPLAJxoRSrPttgxeZWQkeG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Changes made to the <a href="https://www.itpro.com/business/policy-and-legislation/how-the-eu-ai-act-compares-to-other-international-regulatory-approaches">EU AI Act</a> last week have been welcomed by industry stakeholders, but the move doesn’t mean enterprises can take their eye off the ball on AI governance. </p><p>Last week, a <a href="https://www.consilium.europa.eu/en/press/press-releases/2026/05/07/artificial-intelligence-council-and-parliament-agree-to-simplify-and-streamline-rules/" target="_blank">provisional agreement</a> was reached between the European Parliament and EU Council on the Omnibus VII legislative package. This includes proposals which aim to simplify the union’s legislative landscape. </p><p>Under the deal, significant changes to the EU AI Act will be implemented, including a revised compliance timeline for AI systems deemed “high-risk” under the legislation, as well as extended exemptions for small-to-medium sized enterprises. </p><p>As part of the delayed high-risk rules, new application dates will be 2 December 2027 for stand-alone AI systems, and 2 August 2028 for high-risk AI systems embedded in products, according to the EU Council. </p><p>Similarly, agreement reinstates provider obligations to register AI systems in the EU database for high-risk systems. </p><p>Elsewhere, the provisional agreement also postpones the deadline for the implementation of AI regulatory sandboxes at a national level until 2 August 2027.</p><p>Henna Virkkunen, executive vice president for tech sovereignty, security, and democracy at the European Commission, said the changes will help streamline implementation of the legislation. </p><p>“Our businesses and citizens want two things from <a href="https://www.itpro.com/business/policy-and-legislation/the-second-enforcement-deadline-for-the-eu-ai-act-is-approaching-heres-what-businesses-need-to-know-about-the-general-purpose-ai-code-of-practice">AI rules</a>. They want to be able to innovate and feel safe,” she said. </p><p>“Today’s agreement does both. With simpler and innovation-friendly rules, we make it easier to innovate without lowering the bar on safety. We are also making sure the tools supporting EU companies for a smooth implementation of the AI Act are ready. </p><h2 id="meaningful-changes-to-the-eu-ai-act">“Meaningful changes” to the EU AI Act</h2><p>The changes made to the legislation have been welcomed by industry stakeholders as a positive step toward streamlined implementation. </p><p>Mark Weir, regional director for the UK & Ireland at Check Point Software, said the alterations represent a “meaningful evolution in EU <a href="https://www.itpro.com/technology/artificial-intelligence/organizations-face-ticking-timebomb-over-ai-governance">AI governance</a>” that balances stronger protections alongside a practical approach to compliance. </p><p>“By harmonizing implementation across member states and reducing overlapping administrative obligations, the legislation removes genuine friction for organizations operating across Europe,” he said. </p><p>“Without clear guidance, even well-intentioned organisations struggle to translate broad principles into consistent practice,” Weir added. </p><p>“This closes a gap that has caused real uncertainty in the market. Taken together, these changes point toward a regulatory framework that is not just ambitious, but workable."</p><p>Weir noted that provider registration requirements are also a welcome move, and one that will give European legislators “real enforceability” over the EU’s digital sovereignty plans. </p><p>Levent Ergin, chief strategist for <a href="https://www.itpro.com/security/five-eyes-agencies-sound-alarm-over-risky-agentic-ai-deployments">agentic AI</a>, regulatory compliance, and sustainability at Informatica, echoed Weir’s comments but noted that the changes “shouldn’t detract from the need for better AI governance”. </p><p>“Businesses still need to ensure the data feeding their AI systems is governed, explainable, and built on trusted data foundations,” he said. </p><p>“Compliance is only part of the enabler of safe AI. Stronger governance, human oversight, and trusted context will ultimately determine which businesses can scale AI confidently and which struggle to move beyond experimentation.”</p><p>Looking ahead, the European Parliament and EU Council must not formally adopt the agreement. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft, Amazon cloud practice changes spark mixed industry reaction ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/microsoft-amazon-cloud-practice-changes-spark-mixed-industry-reaction</link>
                                                                            <description>
                            <![CDATA[ Concerns have been raised over the voluntary actions agreed to by Microsoft and Amazon ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">JdYDwZ5B9xq2syXqUXKAK4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/P3siyuzwUiqQ8bBAwjUjCV-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 01 Apr 2026 11:15:36 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/P3siyuzwUiqQ8bBAwjUjCV-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cloud computing concept image showing 3D rendering of a cloud in light purple colors hovering over disks. ]]></media:description>                                                            <media:text><![CDATA[Cloud computing concept image showing 3D rendering of a cloud in light purple colors hovering over disks. ]]></media:text>
                                <media:title type="plain"><![CDATA[Cloud computing concept image showing 3D rendering of a cloud in light purple colors hovering over disks. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/P3siyuzwUiqQ8bBAwjUjCV-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft and Amazon have announced changes to cloud practices following a lengthy probe by the Competitions and Markets Authority (CMA), provoking mixed reactions from industry stakeholders. </p><p>While the regulator concluded in 2025 that both hold “positions of significant market power”, neither were given a Strategic Market Status (SMS) designation. </p><p>This is a label given to organizations that hold a disproportionate influence on markets and allows the CMA to impose “conduct requirements or introduce pro-competition interventions” under the Digital Markets, Competition, and Consumer Act (DMCC). </p><p>In the wake of the investigation, both hyperscalers have agreed to take action on key issues such as cloud egress fees, interoperability, and the ability of customers to switch providers. </p><p>In a statement, the CMA said this will “support greater choice” for businesses and public sector organizations across the country. </p><p>“These changes will reduce expense and effort for UK customers when using more than one cloud provider,” the regulator said. </p><p>As part of the announcement, the CMA revealed plans to <a href="https://www.itpro.com/software/cma-launches-microsoft-probe-amid-software-licensing-concerns"><u>launch a separate SMS probe into Microsoft’s software practices</u></a> due to competition concerns. Expected to begin in May, the investigation will see the regulator examine the firm’s business software licensing practices. </p><p>In a <a href="https://blogs.microsoft.com/on-the-issues/2026/03/31/working-constructively-with-the-uk-cma-to-support-customer-choice-and-cloud-competition/" target="_blank"><u>blog post </u></a>reacting to the cloud market decision, Microsoft president Brad Smith said the company is committed to working “quickly and constructively” to address the CMA’s concerns. </p><p>“We appreciate the opportunity we have had for direct and constructive conversations with the CMA and its staff and look forward to an ongoing dialogue in relation to relevant cloud issues in the future,” he wrote. </p><p>Amazon <a href="https://www.aboutamazon.co.uk/news/aws/delivering-good-outcomes-for-uk-customers" target="_blank"><u>said</u></a> it is working toward a “new <a href="https://d1.awsstatic.com/onedam/marketing-channels/website/aws/en_US/legal/approved/aws-uk-customer-switching-addendum.pdf" target="_blank"><u>UK Addendum </u></a>that formalizes our commitment to customer choice through clear, comprehensive rights around <a href="https://www.itpro.com/cloud/34476/what-is-multi-cloud">multicloud </a>adoption, data portability, and switching processes”.</p><h2 id="industry-stakeholders-aren-t-sold">Industry stakeholders aren’t sold</h2><p>Experts have mixed reactions to Amazon and Microsoft’s moves to address issues flagged in the cloud market probe.</p><p>CCIA senior director Matthew Sinclair said the decision will avoid “overly broad and prescriptive interventions” that could harm UK cloud innovation. </p><p>“The regulator can focus its efforts on action to address specific issues, particularly restrictive software licensing terms for legacy software, which are costing UK users a fortune,” Sinclair noted. </p><p>Nicky Stewart, senior advisor at the Open Cloud Coalition, urged the regulator to take “swift action” against both organizations if they fail to meet commitments on egress fees and interoperability. </p><p>“Slow progress on these issues continues to hamper growth, innovation, and resilience in the UK cloud marketplace,” Stewart commented. “Decisive action will set a benchmark for competition authorities across Europe and beyond.”</p><p>In contrast, Mark Boost, CEO at UK-based cloud provider Civo, questioned whether the voluntary actions by both firms will deliver changes called for by industry stakeholders. </p><p>“Voluntary arrangements made with parties outside of the SMS framework will not provide real impact, and by delaying its final decision regarding Microsoft and excluding AWS altogether, there is a risk for CMA to unnecessarily prolong uncertainty and miss an opportunity to future-proof the UK’s digital infrastructure,” he said. </p><p>Boost added that the CMA’s decision does not provide “adequate solutions” to solve lingering concerns over the dominance of both hyperscalers in the UK market. Last year, the regulator found Amazon and Microsoft controlled a share of the market ranging between 30-40%.</p><p>“There needs to be a fair digital market in which domestic innovation is encouraged, alongside continuing to help build opportunities for international collaboration and trade,” he said. </p><p>“If the CMA is serious about delivering on this, it will need to adopt an integrated approach as opposed to only partially regulating these hyperscalers. If the same standards are not applied to both parties, the UK will jeopardize its objectives related to digital sovereignty and economic stability.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How the Cybersecurity and Resilience Bill could impact MSPs ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/how-the-cybersecurity-and-resilience-bill-could-impact-msps</link>
                                                                            <description>
                            <![CDATA[ With the Cybersecurity and Resilience Bill now in Parliament, how should MSPs prepare for heightened regulatory scrutiny? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">WHrhZcdb4awMip2ikuyKYa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nYogShbW5e32t3rySKZUg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 19 Feb 2026 08:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Gemma Blake ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pKcnhWn69jhSZfdbR4f9xC.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nYogShbW5e32t3rySKZUg-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[House of Parliament at Westminster pictured at dawn with Big Ben clock tower and Thames River in foreground.]]></media:description>                                                            <media:text><![CDATA[House of Parliament at Westminster pictured at dawn with Big Ben clock tower and Thames River in foreground.]]></media:text>
                                <media:title type="plain"><![CDATA[House of Parliament at Westminster pictured at dawn with Big Ben clock tower and Thames River in foreground.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nYogShbW5e32t3rySKZUg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK government’s much-anticipated Cybersecurity and Resilience Bill (CSRB) had its first and second reading in Parliament and is now progressing through the necessary next stages to become law. </p><p>Designed to improve the cybersecurity and resilience of the UK’s most important services, while taking into account the evolving challenges impacting today’s increasingly interconnected digital world, the new legislation makes crucial updates to the 2018 Network and Information Systems (NIS) Directive.</p><p>It mandates stricter controls around cyber best practices, reinforces the importance of supply chain security, and brings more organizations into the scope of government oversight, including Managed Service Providers (MSPs).</p><h2 id="msps-under-the-csrb"> MSPs under the CSRB</h2><p>MSPs have largely remained free from government oversight and were not included in the 2018 NIS regulation.</p><p>NIS covered Operators of Essential Services (OES) and Relevant Digital Service Providers (RDSPs), and while the government did announce plans to include MSPs in its update to the regulation in 2022, this was never enforced.</p><p>However, under the CSRB, MSPs will also soon be mandated and obligated to meet strict new compliance requirements.</p><p>According to the regulation’s proposal, MSPs will soon be required to abide by the same requirements placed on RDSPs under the NIS 2018 regulation. The government also recently <a href="https://assets.publishing.service.gov.uk/media/691331835dec0071ce496374/Research_on_the_managed_service_providers_market_2025.pdf"><u>confirmed</u></a> that MSPs who employ at least 50 people and have a turnover exceeding €10 million will be regulated under the bill, potentially placing approximately 1,100 MSPs within its scope.  </p><p>When it comes to the requirements placed on MSPs, these include:</p><ul><li>Registering with the ICO</li><li>Having appropriate and proportionate security measures in place to manage risks to the network and information systems that support their service</li><li>Notifying incidents to the ICO, where those incidents have a substantial impact on the provision of their service</li></ul><h2 id="understanding-the-cyber-risk-to-msps">Understanding the cyber risk to MSPs</h2><p>The inclusion of MSPs in the CSRB is an important step in improving cyber resilience across the UK, and it is essential given the important role they play in today’s digital landscape.</p><p>Over the last seven years, MSPs have evolved from providing IT and communications services into providers that form the digital backbone of a significant part of the UK’s economy.</p><p>MSPs are now integral to thousands of organizations across the country, delivering everything from connectivity to IT to cybersecurity. </p><p>However, this concentration has turned them into major targets for threat actors.</p><p>Today, MSPs are routinely targeted by threat actors to launch supply chain attacks, where they gain access to one MSP and then pivot across to customer environments, launching widespread breaches.</p><p>This was demonstrated in the recent attack on Ingram Micro, when the IT distributor suffered a ransomware attack at the hands of SafePay, and customer data was reportedly compromised.</p><p>These attacks can be highly dangerous, impacting hundreds of organizations at once, while causing mass financial damage and operational disruption.</p><p>These are some of the key reasons why MSPs will soon be covered by the CSRB. </p><p>The government clearly wants to mitigate this potentially systemic risk.</p><p>However, considering many MSPs don’t have the in-house skills required to meet the new requirements, the forthcoming regulation will be a concern.</p><p>So, how can they prepare for the legislation today, before it officially comes into force?</p><h2 id="adopting-cyber-best-practices-within-msps">Adopting cyber best practices within MSPs</h2><p>Despite delivering security services to their clients, many MSPs are not experts in the field of cyber defense. </p><p>The requirements for delivering security have largely escalated due to customer demand, rather than an increase in in-house expertise.</p><p>However, with the CSRB, MSPs are suddenly under pressure to not only enhance their internal security, but also the security of their clients. </p><p>This means many MSPs will want to know what they can do to meet these new requirements, but without having to build out entirely new functions of business. </p><p>Fortunately, this can be achieved by collaborating with vendors that are dedicated to supporting MSPs.</p><p>Vendors can offer support to MSPs through their expertise in cybersecurity, alleviating the burden on their own resources, while also improving internal and customer defenses.</p><p>Delivering platforms that offer market-leading defenses, vendors can enhance cyber resilience for both MSPs and their customers. </p><p>However, MSPs should look for partners that support them with this new opportunity without looking to override their relationships with their clients. </p><p>Ideally, MSPs should look to partner with vendors that can not only support security across their own environments, but ones that can also enable them to deliver new and advanced capabilities to their clients without significant resourcing overhead or financial investment. </p><p>The inclusion of MSPs in the CSRB will likely come as a concern for the sector.</p><p>Suddenly, these organizations that have largely remained free from government oversight are under the spotlight.</p><p>This adjustment will undoubtedly be challenging, but the MSPs that take action today will be ready to meet the new requirements they face tomorrow, enhancing resilience across both their internal and customer environments. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ European Commission approves data flows with UK for another six years ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/european-commission-approves-data-flows-with-uk-for-another-six-years</link>
                                                                            <description>
                            <![CDATA[ The European Commission says the UK can have seamless data flows for another six years despite recent rule changes ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Dg2XD2EjDvXVebwCQorX26</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YPLAJxoRSrPttgxeZWQkeG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 24 Dec 2025 08:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YPLAJxoRSrPttgxeZWQkeG-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[European Union (EU) concept image showing flag on a digitized background with ripples flowing out from 12 stars.]]></media:description>                                                            <media:text><![CDATA[European Union (EU) concept image showing flag on a digitized background with ripples flowing out from 12 stars.]]></media:text>
                                <media:title type="plain"><![CDATA[European Union (EU) concept image showing flag on a digitized background with ripples flowing out from 12 stars.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YPLAJxoRSrPttgxeZWQkeG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The European Commission (EC) has renewed a pair of rules that will allow data to continue flowing between the European Economic Area and the UK. </p><p>The adequacy decisions were agreed after the UK left the EU via "Brexit" in 2020 on the grounds that the UK legal framework for data protections were as good as those in Europe. </p><p>While that was welcome news for British companies dependent on the flow of data, the former government still complained that the decision should have been <a href="https://www.itpro.com/policy-legislation/data-protection/358674/eu-grants-the-uk-provisional-data-adequacy-status"><u>taken before the official Brexit withdrawal date.</u></a></p><p>That agreement ran out in June 2025, but was given a technical extension of six months to give the EC time to consider the impact of changes brought in via <a href="https://www.itpro.com/security/data-protection/data-use-and-access-act-comes-into-force"><u>Labour's Data (Use and Access) Act</u></a>. </p><p>This loosened up some data controls for research and charitable fundraising, while requiring companies to have a data protection complaints procedure. </p><p>The aim, said then technology secretary Peter Kyle, was to enable the government to make use of the "goldmine of data" it holds for policing, admin and more. </p><p>In particular, the EC was considering the impact of those changes on the General Data Protection Regulation (GDPR) and the Law Enforcement Directive. </p><h2 id="six-year-renewal">Six-year renewal </h2><p>Now, the EC has announced that the adequacy decisions have been given another six years until 2031, with the possibility of renewal again, with the Commission and European Data Protection Board reviewing the system and any changes in four years.</p><p>"The decisions ensure that personal data can continue flowing freely and safely between the European Economic Area (EEA) and the United Kingdom, as the UK legal framework contains data protection safeguards that are essentially equivalent to those provided by the EU," the EC said in a statement.</p><p>The renewal means data will be able to continue to flow between the UK and Europe, avoiding serious disruption for businesses if that were to stop. </p><h2 id="adequacy-agreements">Adequacy agreements</h2><p>The EC's first adequacy decision with a non-EU country following the introduction of GDPR was with Japan, coming into force in 2019, though the European body had similar agreements in place for other countries including Canada before the regulation was introduced. </p><p>Other countries with adequacy decisions in place include the US, Switzerland, Argentina, and Korea. </p><p>"The European Commission has the competence to determine, on the basis of the General Data Protection Regulation, whether a country or international organisation outside the EU ensures an adequate level of data protection," the EC explained. </p><p>"Following this, the Commission might initiate the process for the adoption of an adequacy decision, which allows the free flow of personal data from the EU and the European Economic Area (EEA) to a third country or international organisation without further obstacles."</p><p>For the UK renewal, a wide range of opinions were sought. "The adoption of the renewal decisions follows the European Data Protection Board's opinion and the Member States' green light in the so-called comitology procedure," the EC said in a statement, referring to a system that enables the EC to implement rules under the review of national representatives from member states.</p><p>The UK adequacy agreement was approved despite the changes introduced by the Data (Use and Access) Act introduced by the Labour government – which were <a href="https://www.theregister.com/2025/12/22/eu_uk_data_adequacy/"><u>more limited than a data overhaul</u></a> initially <a href="https://www.itpro.com/policy-legislation/368448/government-replace-gdpr-with-data-reform-bill"><u>planned by the last Conservative government</u></a> that may not have been seen in such a positive light by the EC and member states. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK’s ‘Tech Prosperity Deal' with US hits rocky ground ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/uks-tech-prosperity-deal-with-us-hits-rocky-ground</link>
                                                                            <description>
                            <![CDATA[ The US has reportedly threatened to pull out of the deal over the Digital Services Tax and broader economic disagreements ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4Wn6EqNwJkC7hfi89ZXCs</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WBcDikq5VTmBzh9w4HJzkL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 17 Dec 2025 11:20:35 +0000</pubDate>                                                                                                                                <updated>Wed, 17 Dec 2025 11:38:43 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WBcDikq5VTmBzh9w4HJzkL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[US President Donald Trump and UK Prime Minister Kier Starmer signing the UK-US Tech Prosperity Deal at Chequers, in Aylesbury, UK.]]></media:description>                                                            <media:text><![CDATA[US President Donald Trump and UK Prime Minister Kier Starmer signing the UK-US Tech Prosperity Deal at Chequers, in Aylesbury, UK.]]></media:text>
                                <media:title type="plain"><![CDATA[US President Donald Trump and UK Prime Minister Kier Starmer signing the UK-US Tech Prosperity Deal at Chequers, in Aylesbury, UK.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WBcDikq5VTmBzh9w4HJzkL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>There's huge uncertainty over the UK-US Tech Prosperity Deal, with reports that the US has pulled out.</p><p>The deal, signed in September, saw the two countries agreeing to establish joint R&D, and advance "pro-innovation AI policy frameworks". The plan also called for cooperation on quantum computing and nuclear energy.</p><p>At the time, US president Donald Trump said it would "ensure our countries lead the next great technological revolution side by side".</p><p>However, reports from the <a href="https://www.nytimes.com/2025/12/13/business/economy/trump-uk-trade-deal-tariffs.html" target="_blank"><u><em>New York Times</em></u></a> suggest that talks have stalled due to “broader disagreements”. </p><p>This is believed to be in part a reference to the UK's Digital Services Tax, levied at 2% on US tech giants including Google, Amazon, and Apple, and raising around £800 million per year. </p><p> Trump is reportedly not a fan of the Online Safety Act, which requires tech companies to protect users from harmful content.</p><p>According to the <em>NYT</em>, the US is also concerned about the Economic Prosperity Deal between the two countries. The MOU for the Technology Prosperity Deal made it dependent on “substantive progress” towards the Economic Prosperity Deal signed in May. </p><p>The US is reportedly unhappy with perceived trade barriers in sectors such as cars, pharmaceuticals, and steel.</p><p>The stalled talks on the deal may just be a tactic to put pressure on the UK, as implied by a statement on X by Trump's science adviser Michael Kratsios. </p><p>"In line with Section III of the US-UK Technology Prosperity Deal, we hope to resume work with the United Kingdom once the UK has made substantial progress in implementing its commitments under the Economic Prosperity Deal," he said.</p><p>"We look forward to continuing our productive collaboration across AI, quantum, nuclear, and other critical technology areas under the Deal."</p><p>Reports from the <a href="https://www.bbc.co.uk/news/articles/c79x54dprngo"><u><em>BBC </em></u></a>on Tuesday noted that the deal is still very much alive and kicking. According to the broadcaster, the prime minister’s office said the UK remains in “active conversations with US counterparts at all levels of the government” on the deal. </p><h2 id="who-benefits-from-the-tech-prosperity-deal">Who benefits from the Tech Prosperity Deal?</h2><p>The Tech Prosperity Deal has been widely seen as <a href="https://www.itpro.com/business/policy-and-legislation/its-a-strikingly-unequal-partnership-how-the-us-comes-out-on-top-in-the-tech-prosperity-deal-despite-some-significant-benefits-to-uk-businesses"><u>favorable to the US</u></a>, Last month, experts told ITPro the agreement was a “strikingly unequal partnership” that allows big tech to expand its presence in the UK unchecked. </p><p>According to campaign group Global Justice Now, the UK should be wary of making any more concessions.</p><p>"For Trump, collaboration on trade and investment only appears possible if other countries give US corporate giants free reign over their economies – and give up their democratic right to regulate and tax them," said policy and campaigns manager Tim Bierley.</p><p>"The news that the US is seeking even more concessions should be a wake-up call for those in government who think we can appease our way out of tariff wars with Trump – the more we concede, the more corporate America will demand."</p><p>Broadly speaking, the tech industry is more favorable toward the deal. The Computer & Communications Industry Association (CCIA), which has called for the Digital Services Tax to be repealed, pointed out that other nations are scrapping similar taxes. </p><p>“The technology deal was good news for investment and innovation in both countries, and it is unfortunate that lack of progress in broader trade issues resulted in its implementation being suspended," said CCIA senior director Matthew Sinclair.</p><p>"The UK should do more to address barriers to trade in digital services, whether that is taxes that single out US multinationals or regulators wielding unprecedented powers without the guardrails that should protect companies against disproportionate or simply misguided attacks on their businesses.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Trump's AI executive order could leave US in a 'regulatory vacuum' ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/trumps-ai-executive-order-could-leave-us-in-a-regulatory-vacuum</link>
                                                                            <description>
                            <![CDATA[ Citing a "patchwork of 50 different regulatory regimes" and "ideological bias", President Trump wants rules to be set at a federal level ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LW52ognn8BgBsGPv2SJbxf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NxRaHTALgf2eofocif77kU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 12 Dec 2025 17:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NxRaHTALgf2eofocif77kU-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[President Donald Trump signs an executive order in the Oval Office at the White House on September 19, which introduced a new $100,000 fee for H-1B visa applications. ]]></media:description>                                                            <media:text><![CDATA[President Donald Trump signs an executive order in the Oval Office at the White House on September 19, which introduced a new $100,000 fee for H-1B visa applications. ]]></media:text>
                                <media:title type="plain"><![CDATA[President Donald Trump signs an executive order in the Oval Office at the White House on September 19, which introduced a new $100,000 fee for H-1B visa applications. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NxRaHTALgf2eofocif77kU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>US president Donald Trump has signed an executive order aimed at banning individual states from regulating AI in a move one expert said could create a “regulatory vacuum” in the country. </p><p>In a move welcomed by a host of AI companies, Trump said he plans to create a federal AI Litigation Task Force responsible for challenging states’ AI laws.</p><p>"State-by-state regulation, by definition, creates a patchwork of 50 different regulatory regimes that makes compliance more challenging, particularly for start-ups. Second, state laws are increasingly responsible for requiring entities to embed ideological bias within models," he said. </p><p>"My administration must act with the Congress to ensure that there is a minimally burdensome national standard — not 50 discordant state ones." </p><p>The order also calls for the Secretary of Commerce to publish an evaluation of state AI laws that conflict with national AI policy priorities - and withhold non-deployment Broadband Equity Access and Deployment (BEAD) funding from any offenders.</p><p>Trump is of course keen to encourage <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>firms to invest in the US - something he believes state-by-state regulation will hamper. </p><p>States including Colorado and New York have already passed laws regulating AI, with California set to require the biggest <a href="https://www.itpro.com/business/policy-and-legislation/california-ai-safety-law-signed-what-it-means">AI firms to publish plans for limiting the risks</a>.  </p><p>The move has been welcomed by the National Association of Manufacturers.</p><p>"As the president demonstrates his commitment to both advancing American technological dominance and bolstering investment in manufacturing, he is rightly recognizing that winning the global race for AI hinges on getting AI policy right, which means avoiding a cumbersome 50-state patchwork of laws and regulations that would throttle interstate commerce, stifle innovation, limit AI adoption and erode America’s competitive edge," said president and CEO Jay Timmons.</p><p>However, the American Civil Liberties Union (ACLU) begs to differ.</p><p>"Although AI might bring substantial benefits, it also carries substantial risks, and America will not win the AI ‘race’ if the AI used by the government, employers, schools, and health care providers is hallucinatory, unreliable, and dangerous," said And, said ACLU senior policy counsel Cody Venzke.</p><p>The executive order doesn't allow for a complete free-for-all, with states still allowed to introduce AI regulations aimed at protecting children, addressing concerns around data centers, and governing states' own procurement and use of AI.</p><p>However, California governor Gavin Newsom said the plan is self-serving and will endanger the public.</p><p>"Today, President Trump continued his ongoing grift in the White House, attempting to enrich himself and his associates," he said. "President Trump and Davis Sacks aren’t making policy — they’re running a con. And every day, they push the limits to see how far they can take it."</p><h2 id="move-could-create-a-regulatory-vacuum">Move could create a “regulatory vacuum”</h2><p>Ilia Kolochenko, CEO at ImmuniWeb, said the executive order and subsequent disruption to state-level efforts to regulate the technology could risk leaving the country in a “regulatory vacuum”. </p><p>“While President Trump's Executive Order may prevent some US states from enacting or enforcing complex and sometimes contradicting AI state laws and regulations – thereby considerably simplifying business for tech companies in America – it might also have a possible drawback by leaving America in a regulatory vacuum,” Kolochenko commented.</p><p>Enterprises operating on both sides of the Atlantic already face a fractured regulatory landscape. The EU, for example, has taken a far more robust approach to legislation, marking a contrast to the US' approach. </p><p>Enforcement of the order may prove tricky, and attempts are already underway to push back against limitations to state-level regulation. A first shot at limiting state AI laws has been defeated in a landslide 99-1 vote in the Senate. </p><p>Similarly, some Democratic lawmakers have said they are planning legislative action against the White House.  </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/business/policy-and-legislation/big-tech-looks-set-to-swerve-ai-regulations-at-least-for-now">Big tech looks set to swerve AI regulations – at least for now</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/the-tech-industry-reacts-to-the-uks-ai-growth-lab">The tech industry reacts to the UK’s AI Growth Lab</a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/responsibility-innovation-aws-alignment-on-ai-regulation">AWS thinks global alignment on AI regulation is possible but must be risk-based</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Technical standards bodies hope to deliver AI success with ethical development practices ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/technical-standards-bodies-hope-to-deliver-ai-success-with-ethical-development-practices</link>
                                                                            <description>
                            <![CDATA[ The ISO, IEC, and ITU are working together to develop standards that can support the development and deployment of trustworthy AI systems ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">WopCrDN6jaZ6aFsDHxAwaV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Qqk6pii9EWCwxVWtKiWkhY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 08 Dec 2025 12:08:29 +0000</pubDate>                                                                                                                                <updated>Mon, 08 Dec 2025 12:09:17 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Qqk6pii9EWCwxVWtKiWkhY-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Open source AI concept image showing artificial human brain imposed over a background showing glowing data points.]]></media:description>                                                            <media:text><![CDATA[Open source AI concept image showing artificial human brain imposed over a background showing glowing data points.]]></media:text>
                                <media:title type="plain"><![CDATA[Open source AI concept image showing artificial human brain imposed over a background showing glowing data points.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Qqk6pii9EWCwxVWtKiWkhY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Three major international technical standardization bodies are working to introduce <a href="https://www.itpro.com/technology/30736/what-is-ethical-ai">ethical considerations</a> into their standards, with the release of four guiding principles.</p><p>The International Organization for Standardization (ISO), the International Electrotechnical Commission (IEC), and the International Telecommunication Union (ITU) last week launched the Seoul Statement at an event in South Korea.</p><p>This statement is aimed at advancing the development of safe, inclusive, and effective international standards for AI. These standards, the bodies revealed, should reflect global needs, support regulatory alignment, and foster interoperability, trust and inclusion.</p><p>"It places international standards at the heart of <a href="https://www.itpro.com/technology/artificial-intelligence/organizations-face-ticking-timebomb-over-ai-governance">AI governance</a>," said Sung Hwan Cho, president of the ISO. </p><p>"We must systematically include social and human rights considerations into our standards work. We must collaborate across government, industry and civil society and academia to ensure all voices are heard."</p><h2 id="the-guiding-principles-for-trustworthy-ai">The guiding principles for trustworthy AI</h2><p>The statement is based on four core principles covering key areas spanning development, deployment, and long-term maintenance of AI systems. </p><p>Standards should actively incorporate sociological dimensions as well as technical ones, for example. They should deepen the understanding of the interplay between international standards and human rights, recognizing both their importance and universality throughout the <a href="https://www.itpro.com/technology/artificial-intelligence/what-would-pausing-ai-development-actually-achieve">AI development</a> lifecycle.</p><p>They should also help strengthen an inclusive, multi-stakeholder community to develop and apply international standards for the design, deployment, and governance of AI. Elsewhere, the organizations encouraged closer collaboration between public and private sector entities on <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>capacity building.</p><p>"Standards are technical tools to uphold the principles we want to live by,” said Seizo Onoe, director of the ITU telecommunication standardization Bureau. </p><p>"The vision set out by this joint statement calls for diverse expertise and global commitment to collaboration and consensus – exactly what drives our standards work and exactly the spirit needed to create the future we want.”</p><p>Any regulatory framework will need to be forward-thinking and adaptable, the bodies noted, largely due to the rapid evolution of the AI landscape moving forward. </p><p>Ethical specifications will have to reflect related issues such as the poor provision of energy supply in developing countries for example, as well as the lack of compute power.</p><p>Research highlighted by the standards bodies indicates that the developing world houses less than 1% of global data center capacity, underlining the need for greater investment to broaden compute capacity. </p><p>These nations are also struggling with a shortage of chipsets and AI components, a lack of public-private data sharing, and a severe shortage of training.</p><h2 id="tackling-ai-safety-concerns">Tackling AI safety concerns</h2><p>Next steps for the organizations include the drafting of standards on the storage of sensitive data. </p><p>The trio are also planning to look at the issues of election interference, deepfakes, and misinformation. The latter of these areas is of particular interest, they noted, with most current deepfake detectors failing to adequately deliver. </p><p>Threat actors are already using deepfakes to dupe unsuspecting enterprise workers, with a recent study from Ironscales showing that <a href="https://www.itpro.com/security/organizations-lag-on-deepfake-protection"><u>85% of cybersecurity and IT leaders have experienced at least one deepfake attack in the last year</u></a>, marking a 10% increase on 2024 statistics. </p><p>"How is a deepfake coming about, and how do we give the technical tools to make detecting it easier?" asked Philippe Metziger, CEO and secretary general of the IEC. </p><p>"Our role is making things more transparent from a technical point of view." </p><p>The statement was created following a UN recommendation last year, with the hope  that standards convergence can help reduce fragmentation and lower compliance burdens, while focusing on responsible AI development and deployment.  </p><p>"Standards don't solve everything," said Metziger. "But we see ourselves as major contributors to AI governance."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/business/careers-and-training/enterprises-are-concerned-about-critical-shortages-of-staff-with-ai-ethics-and-security-expertise">Enterprises are concerned about ‘critical shortages’ of staff with AI ethics and security expertise</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/how-do-we-make-ai-ethical">How do we make AI ethical?</a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/it-professionals-are-the-new-guardians-of-ethical-tech-but-which-global-model-should-you-follow">IT professionals are the new guardians of ethical tech</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ "Responsibility and innovation are not opposites" – AWS thinks global alignment on AI regulation is possible but must be risk-based ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/responsibility-innovation-aws-alignment-on-ai-regulation</link>
                                                                            <description>
                            <![CDATA[ Serious discussions over global AI alignment will be needed in coming years to ensure no regions or nations are left behind ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iibbGj7Pm5AQA3D29BFNtL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9aQwxiukp6GVPAL4WhkNkX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 04 Dec 2025 12:53:46 +0000</pubDate>                                                                                                                                <updated>Fri, 05 Dec 2025 08:41:22 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9aQwxiukp6GVPAL4WhkNkX-1280-80.jpg">
                                                            <media:credit><![CDATA[ITPro/Ross Kelly]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Amazon Web Services (AWS) logo pictured above an escalator at the Venetian Hotel conference center ahead of AWS re:Invent 2025 with conference attendees walking in foyer below. ]]></media:description>                                                            <media:text><![CDATA[Amazon Web Services (AWS) logo pictured above an escalator at the Venetian Hotel conference center ahead of AWS re:Invent 2025 with conference attendees walking in foyer below. ]]></media:text>
                                <media:title type="plain"><![CDATA[Amazon Web Services (AWS) logo pictured above an escalator at the Venetian Hotel conference center ahead of AWS re:Invent 2025 with conference attendees walking in foyer below. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9aQwxiukp6GVPAL4WhkNkX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>With the advent of early automobiles in the 19th century, the UK introduced legislation to protect existing transport industries such as rail networks and stagecoaches. </p><p>One of the most notorious of these laws was the ‘Red Flags Act’, restricted the speed of ‘horse-less’ vehicles to just 2mph in built-up areas and 4mph in the countryside. Worse still, the legislation required three vehicle operators: two in the vehicle itself, and another walking ahead carrying a red flag to inform oncoming traffic that an automobile was coming. </p><p>The result of this, according to Sasha Rubel, head of public AI policy at AWS, was a hammer blow to an industry during its critical embryonic stages. </p><p>Speaking to <em>ITPro </em>at <a href="https://www.itpro.com/cloud/live/aws-re-invent-2025-all-the-news-updates-and-announcements-live-from-las-vegas"><u>AWS re:Invent 2025</u></a>, held in Las Vegas, Rubel says this is a perfect analogy to describe the current challenge industry and governments alike face with generative AI. </p><p>Driving growth of the industry and delivering on the potential of the technology will require a delicate balancing act in the coming years. Yet conflicting regulatory positions on both sides of the Atlantic pose a serious risk to progress and often leave businesses confused. </p><p>“For me, this is a really important lesson from history, because it shows that we not only need to have a shared understanding of what risk and misuse of the technology is, but if you overregulate a technology mitigating for every single possible misuse, you actually miss out on the benefits that this technology represents,” she tells <em>ITPro</em>.</p><p>“We need to focus not only on the risks of misuse of the technology, we also need to focus on what it means if we miss out – the <em>missed use</em> of the technology – if we miss out on what this opportunity represents, not only in terms of the economic benefits to GDP and European competitiveness, but more fundamentally to the beneficial use of what this technology represents for everyday life of people in Europe,” Rubel adds. </p><p>Rubel says discussions on AI regulation, particularly in Europe in recent months, show there’s now a “growing consciousness” that a more aligned international approach to the technology will be needed. </p><p>Robust regulatory frameworks may have noble intentions, but there’s a risk that without clear communication some regions globally may be left behind in the ongoing AI race.</p><p>“We see that in the policy conversations that are happening that we need to simplify rules, and we need to align internationally on what those rules look like in order to make sure that Europe and the United Kingdom remain competitive in this space.”</p><h2 id="misalignment-is-costing-businesses-big">Misalignment is costing businesses big</h2><p>The impact of this misaligned approach to AI regulation is already being felt by both providers and enterprises alike, Rubel says. In a <a href="https://www.unlockingeuropesaipotential.com/"><u>study conducted by Strand Partners</u></a> on behalf of AWS, more than two-thirds (68%) of organizations in the EU don’t understand their obligations under the <a href="https://www.itpro.com/business/policy-and-legislation/the-second-enforcement-deadline-for-the-eu-ai-act-is-approaching-heres-what-businesses-need-to-know-about-the-general-purpose-ai-code-of-practice"><u>EU AI Act</u></a>. </p><p>Further, the study found companies that aren’t sure about <a href="https://www.itpro.com/business/policy-and-legislation/governance-risk-and-compliance-is-a-major-growth-opportunity-but-how-will-the-market-develop"><u>compliance</u></a> typically invest up to 30% less in technology year on year. To add insult to injury, the sheer complexity of compliance means the function ends up accounting for around 40% of overall IT spend at some enterprises. </p><p>“They’re afraid that they don’t understand the rules and that they’ll be fined because of the complexity of rules,” she says. “I hear every day from customers saying, ‘can you explain to us the interplay between the EU AI Act and the GDPR and the EU Copyright Directive’.”</p><p>Ultimately, reducing complexity in this regard will have a positive downstream effect on compliance costs, Rubel says. When businesses know they’re compliant and operating within established rules, this is conducive to innovation. </p><p>“Reducing those compliance costs by mainstreaming rules is really essential,” she says. “It allows startups to be competitive at the global level, but it also allows for an approach that’s globally aligned.”</p><h2 id="responsibility-builds-trust-trust-drives-innovation">Responsibility builds trust; trust drives innovation</h2><p>“Responsibility and innovation need to go hand in hand,” Rubel tells <em>ITPro</em>. This is a point AWS has been keen to emphasize and promote in recent years, and is a longstanding mantra at the company. </p><p>Development policies that are responsible at heart ultimately reduce risk, Rubel says. First and foremost, acknowledging the risks associated with the technology will be critical. </p><p>“Responsibility and innovation are not opposites,” she adds. “Responsibility drives trust, which is one of the biggest blockers to AI adoption beyond regulatory uncertainty. That trust drives adoption, and that adoption drives innovation.”</p><p>Secondly, bringing together relevant stakeholders from various domains to tackle these risks collectively will be equally crucial. In doing so, Rubel believes this will be the first key step toward fostering broader global alignment.  </p><p>Going forward, she calls for a risk-based approach developed by industry, academia, government, and civil society to ensure alignment and enable innovation.</p><iframe allow="" height="200px" width="100%" id="" style="" data-lazy-priority="high" data-lazy-src="https://player.captivate.fm/episode/7b2774d8-c5b2-4912-a6aa-6dc1788dea4d/"></iframe><h2 id="is-regulatory-alignment-a-pipe-dream">Is regulatory alignment a pipe dream?</h2><p>Achieving global alignment is easier said than done, however. There are economic, social, and geopolitical considerations on both sides of the Atlantic. </p><p>The lack of alignment between the United Kingdom, United States, and European Union highlights this, with the latter pursuing a harder approach to the <a href="https://www.itpro.com/business/policy-and-legislation/does-the-us-ai-action-plan-add-up-and-how-will-it-change-the-global-ai-landscape"><u>laissez faire style across the pond</u></a>. </p><p>Discussions about AI legislation in the US have proved controversial in recent months, with a rift emerging over federal and state-based approaches to regulating the technology. </p><p>Business leaders themselves also appear conscious of geopolitical factors at present, particularly with regard to issues like data sovereignty and reliance on foreign infrastructure providers. </p><p>In a survey conducted by Civo, <a href="https://www.itpro.com/cloud/cloud-computing/reliance-on-us-tech-providers-is-making-it-leaders-skittish"><u>UK-based IT leaders voiced serious concerns about the influence of US cloud providers</u></a> in the wake of tariffs imposed by the Trump administration. More than half (60%) of respondents said the UK government should go so far as to cut its use of US cloud services.</p><p>While that research came specifically in response to economic strategy in the US, it does point toward a growing sentiment of isolationist-style, <a href="https://www.itpro.com/infrastructure/ai-infrastructure-global-divide"><u>sovereign AI</u></a> approaches. Political unions like the EU want their data kept in-region, governments want their data kept in-country, and so do the enterprises operating in those individual regions and nations. </p><p>If an aligned approach on data storage is being called into account, it's even more important that industry and public bodies come together to define clear, reproducible standards that lock in safety and innovation.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Big tech looks set to swerve AI regulations – at least for now ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/big-tech-looks-set-to-swerve-ai-regulations-at-least-for-now</link>
                                                                            <description>
                            <![CDATA[ President Trump may be planning an executive order against AI regulation as the European Commission delays some aspects of AI Act ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5r69ntKub3zirkcso2BjsA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qnGSwbfzp9zTsFt2t49oUT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Nov 2025 13:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qnGSwbfzp9zTsFt2t49oUT-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[EU flags fly outside the union headquarters in Brussels, Belgium.]]></media:description>                                                            <media:text><![CDATA[EU flags fly outside the union headquarters in Brussels, Belgium.]]></media:text>
                                <media:title type="plain"><![CDATA[EU flags fly outside the union headquarters in Brussels, Belgium.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qnGSwbfzp9zTsFt2t49oUT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Laws to regulate AI have hit a hurdle following pushback from big tech and US President Donald Trump. </p><p>In the US, Trump is considering using an executive order to ban regulations to rein in AI, according to <a href="https://www.reuters.com/business/urgent-trump-considering-executive-order-preempt-state-ai-laws-2025-11-19/" target="_blank"><u><em>Reuters</em></u></a>, while in Europe, the European Commission said it wants to delay some aspects of the AI Act in response to complaints from big tech over bureaucracy. </p><p>With no federal laws regulating AI forthcoming in the US, some states have pushed to enact their own local legislation, including recent laws in California and Colorado. </p><p>The Trump administration has previously attempted to block such state-level AI laws by <a href="https://www.itpro.com/business/policy-and-legislation/a-decade-long-ban-on-ai-laws-is-a-terrible-idea-for-everyone-but-big-tech-critics-claim"><u>including a 10-year moratorium</u></a> on local regulation in his "big, beautiful bill" over the summer, though that was thwarted by the Senate. Earlier this week, Trump backed plans to add a similar ban in the National Defense Authorization Act. </p><p>Now, the president is considering using an executive order in an attempt to discourage any state-level AI laws by threatening lawsuits or withholding federal funding, according to a draft of the document seen by <em>Reuters</em>. </p><p>As drafted, the order would establish an "AI Litigation Task Force" led by Attorney General Pam Bondi to challenge in court any state that implements AI regulation, on the grounds that "such laws unconstitutionally regulate interstate commerce" and are preempted by existing federal rules. </p><p>The order would also see the Department of Commerce refuse to allocate funding for broadband to states that don't comply. </p><p>Colorado recently approved a rule designed to <a href="https://www.itpro.com/business/policy-and-legislation/does-the-us-ai-action-plan-add-up-and-how-will-it-change-the-global-ai-landscape"><u>prevent algorithmic discrimination</u></a> – highlighting a long-running issue of bias in large-language models (LLMs), which the draft order seen by <a href="https://www.reuters.com/business/urgent-trump-considering-executive-order-preempt-state-ai-laws-2025-11-19/" target="_blank"><u><em>Reuters</em></u></a><em> </em>noted may force "AI models to embed DEI in their programming". </p><p>California has also wrangled with a series of AI laws, and <a href="https://www.itpro.com/business/policy-and-legislation/california-ai-safety-law-signed-what-it-means"><u>recently passed a law around disclosure</u></a> that would require companies tell the government how they plan to avoid serious risks and fess up to any critical safety incidents. </p><p>A White House official did not confirm the order to <em>Reuters</em>, and said it was speculation. </p><h2 id="european-regulation-delays">European regulation delays</h2><p>Over in Europe, the European Commission has suggested delaying some aspects of the <a href="https://www.itpro.com/business/policy-and-legislation/the-second-enforcement-deadline-for-the-eu-ai-act-is-approaching-heres-what-businesses-need-to-know-about-the-general-purpose-ai-code-of-practice">EU AI Act</a> for 16 months and tweaking others as part of a move which sparked concerns it's responding to criticism from American tech giants. </p><p>The commission <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_25_2718" target="_blank"><u>said</u></a> the move was part of wider efforts to "simplify existing rules" on AI, cybersecurity, and data in its Digital Omnibus, which aims to streamline technology-focused laws to make them easier to manage for companies. </p><p>The EU’s economy commissioner, Valdis Dombrovskis, said the measures would save businesses and consumers alike €5bn in red-tape related costs by 2029. </p><p>He added: "Europe has not so far reaped the full benefits of the digital revolution and we cannot afford to continue to pay the price for failing to keep up with a changing world."</p><h2 id="criticism-of-delay">Criticism of delay</h2><p>Critics disagreed on the value, however. Blue Duangdjai Tiyavorabun, Policy Advisor at European Digital Rights (EDRi), suggated the Digital Omnibus is a “full-on betrayal of Europe’s promise”.</p><p>"They are trading the protection of people from harmful AI systems for hollow promises of ‘innovation’. This is no shocker: when tech money flows like water in Brussels, guess who is steering the ship?"</p><p>A Commission official said during a briefing: "Simplification is not deregulation. Simplification means that we are taking a critical look at our regulatory landscape."</p><p>Alongside delaying the timeline for implementing "high-risk rules" by 16 months to December 2027 from August 2026, the Commission said it would extend some rule simplifications for small businesses and small mid-cap companies. </p><p>Elsewhere, it plans to extend compliance measures so more companies can use regulator sandboxes in core industries like automotive and centralize oversight on AI systems to help reduce governance fragmentation. </p><p>"Efficient implementation of the AI Act will have a positive impact on society, safety and fundamental rights," the EC said in a statement. "Guidance and support are essential for the roll-out of any new law, and this is no different for the AI Act."</p><p>Thierry Breton, former European commissioner for the internal market and digital affairs, wrote in the <a href="https://www.theguardian.com/commentisfree/2025/nov/18/europe-digital-us-online-safety-laws" target="_blank"><u><em>Guardian,</em></u></a> that Europe should be proud of its AI laws. </p><p>"We should resist any attempt to unravel these laws, through 'omnibus' bills or otherwise, mere months after they have entered into force, under the pretext of simplification or remedying an alleged 'anti-innovation' bias," he said. </p><p>"No one is fooled over the transatlantic origin of these attempts. So let’s not be useful idiots."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/business/policy-and-legislation/is-the-uk-falling-behind-the-eu-on-ai-regulation">Is the UK falling behind the EU on AI regulation?</a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/the-fractured-regulatory-landscape-tech-companies-face-in-2025">The fractured regulatory landscape tech companies face in 2025</a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/three-things-you-need-to-know-about-the-eu-data-act-ahead-of-this-weeks-big-compliance-deadline">Three things you need to know about the EU Data Act</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'It’s a strikingly unequal partnership': How the US comes out on top in the Tech Prosperity Deal despite some significant benefits to UK businesses ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/its-a-strikingly-unequal-partnership-how-the-us-comes-out-on-top-in-the-tech-prosperity-deal-despite-some-significant-benefits-to-uk-businesses</link>
                                                                            <description>
                            <![CDATA[ What does the future hold for US and UK businesses after the two nations agree on a landmark technology deal? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XLAbhKsuPvkQpVo4hD8Lpc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GkgiARgcodg65hhxrBhygX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Nov 2025 12:57:57 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ keumars.afifi-sabet@futurenet.com (Keumars Afifi-Sabet) ]]></author>                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GkgiARgcodg65hhxrBhygX-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A photograph of US President Donald Trump, on the left, and UK prime minister Keir Starmer, on the right, signing the Tech Prosperity Deal. The pair are sat at a ceremonial table, flanked by UK and US flags. Behind them, a blue wall bears the white words &#039;TECH PROSPERITY DEAL&#039;, with the UK and US flags shown beneath.]]></media:description>                                                            <media:text><![CDATA[A photograph of US President Donald Trump, on the left, and UK prime minister Keir Starmer, on the right, signing the Tech Prosperity Deal. The pair are sat at a ceremonial table, flanked by UK and US flags. Behind them, a blue wall bears the white words &#039;TECH PROSPERITY DEAL&#039;, with the UK and US flags shown beneath.]]></media:text>
                                <media:title type="plain"><![CDATA[A photograph of US President Donald Trump, on the left, and UK prime minister Keir Starmer, on the right, signing the Tech Prosperity Deal. The pair are sat at a ceremonial table, flanked by UK and US flags. Behind them, a blue wall bears the white words &#039;TECH PROSPERITY DEAL&#039;, with the UK and US flags shown beneath.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GkgiARgcodg65hhxrBhygX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In September, the UK welcomed the US president Donald Trump with open arms ahead of the signature of the landmark US-UK Technology Prosperity Deal. This $42 billion agreement, the UK government believes, will strengthen the strategic relationship between the two countries in a variety of key areas – including quantum computing, nuclear energy and, most eye-catching of all, AI.</p><p>There's no doubting the US as an unmatchable force when it comes to tech innovation, with its biggest companies ploughing headfirst into a turbocharged AI summer. This agreement represents a chance for the UK to carve out a slice of that action, with the <a href="https://www.gov.uk/government/news/memorandum-of-understanding-between-the-government-of-the-united-states-of-america-and-the-government-of-the-united-kingdom-of-great-britain-and-north"><u>memorandum of understanding (MOU)</u></a> laying out a framework for co-operation. In short, UK organizations should, over time, be given access to critical technology and research, while US companies will get the chance to invest billions of dollars into new initiatives – and reap the eventual rewards. </p><p>The reaction to the broad and far-reaching agreement has been overwhelmingly positive, for the most part. It is, however, not a treaty but a non-binding MOU, with plenty of details still to be ironed out. Over time, what will it mean for the long-term prospects of technology sectors in the two nations and their respective businesses? </p><h2 id="the-prospects-on-both-sides-of-the-atlantic">The prospects on both sides of the Atlantic </h2><p>Although much of the UK press lauded the agreement, it overwhelmingly favors the US, says John Bates, CEO at SER Group and a former Cambridge University computer science and deep learning academic. In reality, he says, "this deal may not be the win it's being sold as" because hyperscalers get to expand their presence on UK soil while strengthening their footprint. </p><p>"We’re expected to applaud America’s <a href="https://www.itpro.com/infrastructure/uk-to-host-largest-european-gpu-cluster-under-gbp11-billion-nvidia-investment-plans"><u>generosity on chips</u></a>, AI models, and <a href="https://www.itpro.com/business/business-strategy/google-opens-doors-on-uk-data-center-ahead-of-trump-visit"><u>data centers</u></a>, yet the UK risks becoming little more than an outsourcing hub for hyperscalers and <a href="https://www.itpro.com/business/business-strategy/everything-you-need-to-know-about-nvidia"><u>Nvidia</u></a> rather than a genuine AI power in its own right," Bates tells <em>ITPro</em>. "True innovation remains concentrated in the US, while the UK still struggles to define its own AI ambitions. Instead of relying on access to American technology, Britain should be doubling down on backing local innovators and developing <a href="https://www.itpro.com/business/careers-and-training/rampant-skills-gaps-should-be-a-wake-up-call-for-every-leader-as-ai-tech-talent-shortages-hamper-growth"><u>homegrown AI capabilities</u></a>."</p><p>That isn't to say there are no benefits at all for UK businesses. Bates suggests the UK remains more attractive than the EU as a global hub for AI innovation, for example. There's also a real upside for businesses seeking to tap into emerging technologies much faster than they could have done previously, explains Adnan Masood, chief AI architect at UST and an AI researcher. </p><p>"This shrinks a decade of infrastructure build-out into a couple of years – if power and permitting cooperate," he says, but echoes Bates' views that it's a lop-sided deal. "Let’s be honest, the CapEx is overwhelmingly American. That concentrates leverage with US vendors and raises long-term <a href="https://www.itpro.com/infrastructure/can-the-uk-achieve-ai-sovereignty">sovereignty</a> and switching cost questions for UK buyers."</p><p>Much of this comes from the fact the US heavily outspends the UK in terms of AI investment. Last year, US private investments hit $109.1 billion, which was nearly 24 times higher than the UK's $4.5 billion, according to <a href="https://hai.stanford.edu/ai-index/2025-ai-index-report/economy" target="_blank"><u>Stanford University research</u></a>. </p><p>Given the head start, it's no doubt that perhaps the path of least resistance for UK firms is a deal that would allow them to tap into the technological progress that counterparts across the pond have already forged ahead with. It’s an alternative to spending the necessary time and money – which could take a great many number of years – to reach anywhere close to the proficiency that US firms already boast with the tech that's needed.  </p><h2 id="charting-a-long-term-albeit-turbulent-path-for-ai-growth">Charting a long-term, albeit turbulent, path for AI growth</h2><p>Bates is not necessarily an advocate for this agreement, suggesting it diminishes the UK as a true factor in the global equation. "For a nation that pioneered computing, it’s a strikingly unequal partnership," he says. "I’m pro-US, but this investment doesn’t make the UK a true player. And the <a href="https://www.itpro.com/infrastructure/data-centres/data-center-carbon-emissions-are-set-to-skyrocket-by-2030-with-hyperscalers-producing-2-5-billion-tons-of-carbon-and-power-hungry-generative-ai-is-the-culprit"><u>environmental cost of these AI factories</u></a> – from potential near-permanent data center hosepipe bans to local infrastructure strain – feels a high price to pay for becoming a kind of AI Airstrip One for America."</p><p>Other downsides to consider, Masood explains, include the fact that it opens up UK businesses to US vendor lock-in and potentially stifles the prospects for a true UK rival to emerge. "The model assumes a US tech stack for chips, cloud, and tooling. That’s efficient – but it’s also a lock-in risk for the UK and reduces bargaining power for local suppliers. The UK gets capacity; the U.S. gets the standard." </p><p>There are also very genuine concerns over the technology, whether a growing bubble around the AI industry could pop, creating massive ripples in its wake. The Bank of England, for example, <a href="https://www.itpro.com/technology/artificial-intelligence/is-an-ai-bubble-about-to-pop"><u>warned in October</u></a> that there is a growing risk of the bubble bursting, with a "sudden correction" resulting in a drying up of funds. Even Sundar Pichai, CEO at Alphabet and a huge proponent for adoption of AI such as Google’s Gemini, <a href="https://www.itpro.com/technology/artificial-intelligence/google-ceo-sundar-pichai-sounds-worried-about-a-looming-ai-bubble-i-think-no-company-is-going-to-be-immune-including-us"><u>has warned</u></a> that “irrationality” in AI hype could harm the markets over the long term.</p><p>Over time, says Jim Piazza, VP of AI and machine learning at Ensono, the agreement should pave the way for a much healthier environment in the UK where businesses can pursue the integration of various advanced US technologies. </p><p>"With shared standards in place, it’s easier for vendors to demonstrate <a href="https://www.itpro.com/business/policy-and-legislation/governance-risk-and-compliance-is-a-major-growth-opportunity-but-how-will-the-market-develop">compliance</a> and for buyers to evaluate offerings," he says. "That kind of clarity creates more confidence, especially at the enterprise level. If you can document and pass these new standards, you’ll have stronger access to funding, markets, and customers. That’s true on both sides of the pond.</p><p>"Longer term, I see this as a standardization flywheel that should mature over time. As vendors begin to pass these shared tests and document their results, they’ll unlock access to enterprise buyers and funding. Over time, that creates momentum and the more standardized and validated the ecosystem becomes, the faster adoption can happen. Once we get the teeth in place, we’ll see more clarity post."</p><iframe allow="" height="200px" width="100%" id="" style="" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/814a62de-a843-4d55-a14e-038b845861d2/"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cyber Security and Resilience Bill: Security experts question practicality, scope of new legislation ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/cyber-security-and-resilience-bill-security-experts-question-practicality-scope-of-new-legislation</link>
                                                                            <description>
                            <![CDATA[ The new legislation aims to shore up critical infrastructure defenses, but questions remain over compliance and scope ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GBg76cgtWeiJ2PSA5XrXdY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nYogShbW5e32t3rySKZUg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Nov 2025 11:38:18 +0000</pubDate>                                                                                                                                <updated>Wed, 12 Nov 2025 13:49:35 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nYogShbW5e32t3rySKZUg-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[House of Parliament at Westminster pictured at dawn with Big Ben clock tower and Thames River in foreground.]]></media:description>                                                            <media:text><![CDATA[House of Parliament at Westminster pictured at dawn with Big Ben clock tower and Thames River in foreground.]]></media:text>
                                <media:title type="plain"><![CDATA[House of Parliament at Westminster pictured at dawn with Big Ben clock tower and Thames River in foreground.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nYogShbW5e32t3rySKZUg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Legislation aimed at shoring up the UK’s national <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>capabilities is set to be introduced in parliament today – but some security experts have questioned the scope and practicality of new rules. </p><p>The <a href="https://www.itpro.com/security/msps-face-scrutiny-in-cyber-security-and-resilience-bill">Cyber Security and Resilience Bill</a> comes in direct response to growing cyber threats faced by private and public sector organizations, targeting stronger defenses in areas such as healthcare, energy, and transport networks. </p><p>The bill also comes at a critical time, with figures from the Office for Budget Responsibility (OBR) showing <a href="https://www.itpro.com/security/cyber-attacks/why-attacks-against-critical-national-infrastructure-cni-are-such-a-threat">attacks on critical infrastructure</a> could have a massive impact on the economy. </p><div class="product"><a data-dimension112="7e64aec3-cfa1-4792-86f2-a25c58423984" data-action="Deal Block" data-label="Protect your networks with NordLayer and save 28% using the code BLACKLAYER-28." data-dimension48="Protect your networks with NordLayer and save 28% using the code BLACKLAYER-28." href="https://go.nordlayer.net/aff_c?offer_id=563&aff_id=3013" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="agnbx7fUi9TXvZ2mGtHsof" name="01-Ad-image-SoMe-Black-friday-1080x1080" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/agnbx7fUi9TXvZ2mGtHsof.png" mos="" align="middle" fullscreen="" width="1200" height="1200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p>Your easiest cybersecurity win this year.</p><p><a href="https://go.nordlayer.net/aff_c?offer_id=563&aff_id=3013" target="_blank" data-dimension112="7e64aec3-cfa1-4792-86f2-a25c58423984" data-action="Deal Block" data-label="Protect your networks with NordLayer and save 28% using the code BLACKLAYER-28." data-dimension48="Protect your networks with NordLayer and save 28% using the code BLACKLAYER-28." data-dimension25="">Protect your networks with NordLayer and save 28% using the code BLACKLAYER-28.</a><a class="view-deal button" href="https://go.nordlayer.net/aff_c?offer_id=563&aff_id=3013" target="_blank" rel="nofollow" data-dimension112="7e64aec3-cfa1-4792-86f2-a25c58423984" data-action="Deal Block" data-label="Protect your networks with NordLayer and save 28% using the code BLACKLAYER-28." data-dimension48="Protect your networks with NordLayer and save 28% using the code BLACKLAYER-28." data-dimension25="">View Deal</a></p></div><p>Analysis from the OBR found a major attack could result in a temporary increase in borrowing by over £30 billion, or equivalent to around 1.1% of GDP. </p><p>Elsewhere, the financial impact of attacks across both the public and private sectors has been growing. <a href="https://www.gov.uk/government/publications/independent-research-on-the-economic-impact-of-cyber-attacks-on-the-uk" target="_blank"><u>Research</u></a> published this week shows the average cost of a “significant cyber attack” on the UK now stands at over £190,000. </p><p>“Cybersecurity is national security,” said technology secretary Liz Kendall. “This legislation will enable us to confront those who would disrupt our way of life. I’m sending them a clear message: the UK is no easy target.”</p><p>So what can we expect from the bill?</p><h2 id="what-s-covered-under-the-bill">What’s covered under the bill?</h2><p>Under the legislation, digital and essential services such as <a href="https://www.itpro.com/business-operations/business-management/367834/best-it-management-tools">IT management</a> for critical sectors will be regulated for the first time and subject to robust minimum security standards. </p><p>“Because they hold trusted access across government, critical national infrastructure, and business networks, they will need to meet clear security duties,” the government said in a statement. </p><p>“This includes reporting significant or potentially significant cyber incidents promptly to government and their customers, as well as having robust plans in place to deal with the consequences.”</p><p>Elsewhere, regulators and government ministers will be given sweeping new powers to ensure organizations meet these base requirements. </p><p>“The technology secretary gets new powers to instruct regulators and the organizations they oversee, like <a href="https://www.itpro.com/security/cyber-attacks/two-more-nhs-trusts-have-been-hit-with-cyber-attacks-heres-what-we-know-so-far">NHS trusts</a> and <a href="https://www.itpro.com/digital-transformation/33332/thames-water-splashes-1bn-on-digital-transformation-dive">Thames Water</a>, to take specific, proportionate steps to prevent cyber attacks where there is a threat to UK national security,” the government added. </p><h2 id="does-the-bill-go-far-enough">Does the bill go far enough?</h2><p>The introduction of the bill has, by and large, been welcomed by security industry stakeholders as a positive step toward limiting the impact of <a href="https://www.itpro.com/security/cyber-attacks">cyber attacks</a> on critical infrastructure. </p><p>In particular, new rules around incident reporting will play a vital role in bolstering collective defense against growing threats, according to Trevor Dearing, director of critical infrastructure at Illumio.</p><p>“The shift from reporting only successful breaches to <a href="https://www.itpro.com/security/cyber-attacks/m-and-s-chair-calls-for-mandatory-reporting-of-cyber-attacks-after-traumatic-ransomware-incident-but-will-it-do-more-harm-than-good">reporting all cyber incidents</a> is long overdue and will drive rapid improvements in how organizations protect their most critical assets and respond to attacks,” he said. </p><p>“Granting the technology secretary new powers to ensure that regulators and organizations monitor or isolate high-risk systems is a smart move,” Dearing added. </p><p>However, some industry stakeholders have questioned the scope of the legislation, arguing that it fails to address lingering issues in some key areas. </p><p>Chris Dimitriadis, chief global strategy officer at ISACA, suggested the sharpened focus on critical infrastructure fails to address the reality of the modern digital economy. </p><p>Moreover, omitting particular sectors, such as retail, is an oversight on the part of the government given the <a href="https://www.itpro.com/security/cyber-attacks/cyber-attacks-have-rocked-uk-retailers-heres-how-you-can-stay-safe">spate of attacks waged against high street brands</a> this year. </p><iframe allow="" height="200px" width="100%" id="" style="" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/9ef7f02f-466f-4466-ae02-cbd718efa275/"></iframe><p>“The era when cyber regulation could focus solely on critical national infrastructure is over,” he said. “Today, every major employer is part of the digital economy - and therefore part of the threat landscape.”</p><p>“Yet many remain outside the scope of meaningful legislative protections. Recent <a href="https://www.itpro.com/security/cyber-attacks/cyber-attacks-on-uk-retailers-financial-impact">attacks on major retailers such as M&S and Co-op</a> are perfect examples of how vulnerable our digital ecosystem is and the urgent need to take action.”</p><p>Matt Houlihan, VP of government affairs at Cisco, also questioned the practicality of compliance for organizations that fall under the scope of the legislation. </p><p>"The success of this bill will rely on clarity and practical timelines to help organizations implement necessary measures effectively,” he said. </p><p>“We'd also urge the government not to miss an important opportunity to tackle the growing risks from unsupported, end-of-life equipment – a persistent weak point in UK infrastructure that too often leaves organizations exposed.”</p><p>Dearing echoed Houlihan’s comments on reporting, again noting that support for organizations will be crucial. </p><p>“Whilst it is understandable that the government is introducing tougher penalties for poor security practices, it is equally important that sufficient support is provided to help organizations achieve compliance,” he said. </p><p>“The government must ensure that investment is made in supporting organizations, particularly those with limited budgets.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/business/policy-and-legislation/what-the-uks-online-safety-act-means-for-it-companies">What the UK’s Online Safety Act means for IT companies</a></li><li><a href="https://www.itpro.com/security/ransomware/ransomware-payments-are-banned-in-the-public-sector-should-businesses-still-pay">Ransomware payments are banned in the public sector: should businesses still pay?</a></li><li><a href="https://www.itpro.com/security/why-the-uks-outdated-cybersecurity-legislation-needs-an-urgent-refresh">Why the UK's "outdated" cybersecurity legislation needs an urgent refresh</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Empowered employees strengthen financial sector digital resilience  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/empowered-employees-strengthen-financial-sector-digital-resilience</link>
                                                                            <description>
                            <![CDATA[ Intelligent, bespoke employee cybersecurity training and awareness is critical for DORA compliance ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TPb2LonqEWGDJnqK2BjUEN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zY3UeEvLTfczgZYTQY6hh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 Oct 2025 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Saj Mohidin ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/tvgqQ5ezrHbvEeNjVvazaT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zY3UeEvLTfczgZYTQY6hh-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Identity security concept image showing a fingerprint placed on top of a digital interface.]]></media:description>                                                            <media:text><![CDATA[Identity security concept image showing a fingerprint placed on top of a digital interface.]]></media:text>
                                <media:title type="plain"><![CDATA[Identity security concept image showing a fingerprint placed on top of a digital interface.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zY3UeEvLTfczgZYTQY6hh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Ensuring that any organization can withstand, respond effectively to, and recover quickly from IT disruptions is a strategic imperative. This is particularly true within the financial sector. </p><p>The <a href="https://www.itpro.com/business/policy-and-legislation/a-csos-perspective-on-dora-compliance-and-where-to-go-from-here"><u>Digital Operational Resilience Act (DORA)</u></a>, which became mandatory on 17 January this year, was put in place to serve as a robust standard for resilience. It doesn’t just need organizations in scope to implement sophisticated technological defences; it needs them to have a proactive, well-informed workforce that is ready to tackle cyber threats.</p><p>At its core, DORA is a five-pillar framework. These cover ICT risk management, incident reporting, digital operational resilience testing, third-party risk management, and information sharing. Technology is a critical component of all of these pillars; however, the human element is equally important. This is hardly surprising when you consider that various sources cite human errors as being responsible for between 70% and 95% of all cyber incidents. This means that even when the most robust technological safeguards are in place, the human element will be a significant source of vulnerability. </p><p>Regardless of the source of the incident, employees can also be the difference between a controlled breach and a full-scale disruption. </p><p>What is needed is highly targeted training and simulation exercises that help organizations ensure that their staff are equipped to identify emerging threats, report incidents promptly, and engage in effective remediation efforts.</p><h2 id="digital-operational-resilience-testing-and-human-risk">Digital operational resilience testing and human risk</h2><p>Digital operational resilience testing under DORA goes beyond merely identifying what the vulnerabilities are. It also involves actively testing the human layer. </p><p>Simulated phishing attacks and other real-world-based cyber threat exercises serve multiple purposes. They not only provide a practical measure of employee readiness, but they also help to build essential knowledge and skills for identifying genuine communications from deceptive ones. </p><p>By exposing staff to realistic threat scenarios, organizations are cultivating a security-first mindset. This is vital for mitigating risks before they escalate and disrupt business operations.</p><h2 id="awareness-enhances-incident-reporting">Awareness enhances incident reporting</h2><p>The quick reporting of incidents is a cornerstone of DORA compliance. It mandates strict timelines, for example, notifying relevant authorities within four hours of classifying a major incident, as well as following up with detailed reports within set timeframes. </p><p>It is important to ensure employees are aware of this, so they are equipped to act as the eyes and ears of the organization and support compliance. Their ability and readiness to spot and report anomalies will help to reduce the time to containment and ensure that incidents are managed efficiently and effectively. This not only supports DORA compliance, but it also safeguards both financial and reputational assets.</p><h2 id="establishing-a-sharing-culture">Establishing a sharing culture </h2><p>In addition to ensuring individual preparedness, training, and awareness initiatives will also help establish an environment where information is able to flow freely. By encouraging employees to share all of their observations on suspicious activities or emerging threats, an organization will get stronger collective intelligence. </p><p>Staff need to be able to actively participate in the reporting process through easy-to-use tools and transparent processes. This will enable them to contribute to a dynamic, organization-wide threat intelligence network. Not only does this type of collaborative approach support internal decision-making, but it will also help to enhance the overall resilience of the financial ecosystem when these insights are shared across the industry.</p><h2 id="a-more-resilient-organizational-culture">A more resilient organizational culture</h2><p>Ultimately, investing in employee training and awareness is far more than a tick-box DORA compliance exercise. It is a strategic investment in any financial sector organisation’s future. Building a culture that prioritizes cybersecurity will ensure that every member of the team understands their critical role in safeguarding the organization and the financial industry as a whole. </p><p>The nature of cyber threats will always be evolving, so a well-informed and agile workforce is the most important line of defence because it can adapt to and mitigate risks before they get a chance to occur.</p><p>Organizations should also look at additional innovative strategies, such as cross-sector workshops, inter-company threat simulations, or advanced behavioral analytics, as next steps toward deepening their digital resilience. These initiatives not only further empower employees but also help build genuine expertise, creating a ripple effect that will improve security standards across the industry.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ California has finally adopted its AI safety law – here's what it means ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/california-ai-safety-law-signed-what-it-means</link>
                                                                            <description>
                            <![CDATA[ The new legislation covering AI safety and innovation directly counter federal efforts to ban state-level AI regulation ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LsxefDwzu4abTJ2zf2R2C5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/stJXNhifrEUUqEMmr7kFb3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 30 Sep 2025 12:25:26 +0000</pubDate>                                                                                                                                <updated>Tue, 30 Sep 2025 12:39:11 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/stJXNhifrEUUqEMmr7kFb3-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A telephoto shot of Gavin Newsom, governor of California, stood against the backdrop of the San Francisco–Oakland Bay Bridge with a bright blue sky visible in the background.]]></media:description>                                                            <media:text><![CDATA[A telephoto shot of Gavin Newsom, governor of California, stood against the backdrop of the San Francisco–Oakland Bay Bridge with a bright blue sky visible in the background.]]></media:text>
                                <media:title type="plain"><![CDATA[A telephoto shot of Gavin Newsom, governor of California, stood against the backdrop of the San Francisco–Oakland Bay Bridge with a bright blue sky visible in the background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/stJXNhifrEUUqEMmr7kFb3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>California has officially adopted a law requiring AI companies to disclose how they plan to avoid serious risks stemming from their models and admit any critical safety incidents. </p><p>The Transparency in Frontier Artificial Intelligence Act (TFAIA), previously known as Senate Bill 53 (SB53), is focused on <a href="https://www.itpro.com/technology/artificial-intelligence/ai-safety-tests-inadequate-says-ada-lovelace-institute">AI safety</a>.</p><p>It includes whistleblower protections, requirements to meet international standards, and a mechanism to report safety incidents. It will also establish a consortium that will work on a new <a href="https://www.itpro.com/infrastructure/cluster-computing-and-how-it-can-help-your-enterprise">computing cluster </a> accessible in the <a href="https://www.itpro.com/cloud/370407/what-is-the-future-of-public-cloud">public cloud</a> to develop safe, sustainable, and <a href="https://www.itpro.com/technology/30736/what-is-ethical-ai">ethical AI</a>. </p><p>California is of course home to many of the companies developing these technologies, meaning local regulations could have an impact. Anthropic has<a href="https://www.anthropic.com/news/anthropic-is-endorsing-sb-53"><u> publicly supported this version of the bill</u></a>, though has also called for a federal law. </p><p>In adopting the new law, California becomes the first US state to legislate on AI safety, ahead of New York which has its own plan in the works. The move comes amid a wider failure to legislate around AI, with <a href="https://www.whitecase.com/insight-our-thinking/ai-watch-global-regulatory-tracker-united-states"><u>no federal AI laws as yet in place</u></a>.</p><p>Indeed, California governor Gavin Newsom signed this new bill into law a year after <a href="https://www.itpro.com/business/policy-and-legislation/californias-ai-bill-is-dead-in-the-water-and-big-tech-can-breathe-a-sigh-of-relief"><u>vetoing a previous AI legislative attempt</u></a> that was widely opposed and <a href="https://www.itpro.com/business/policy-and-legislation/california-lawmakers-approve-sweeping-ai-legislation-but-not-everyone-is-happy"><u>included safety testing for large models</u></a> and the requirement for a kill-switch to be included in AI systems. </p><p>"California has proven that we can establish regulations to protect our communities while also ensuring that the growing AI industry continues to thrive," Governor Newsom said in a <a href="https://www.gov.ca.gov/2025/09/29/governor-newsom-signs-sb-53-advancing-californias-world-leading-artificial-intelligence-industry/"><u>statement</u></a>. "This legislation strikes that balance."</p><p>Newsom added: "AI is the new frontier in innovation, and California is not only here for it – but stands strong as a national leader by enacting the first-in-the-nation frontier AI safety legislation that builds public trust as this emerging technology rapidly evolves."</p><h2 id="what-the-law-includes">What the law includes</h2><p>The TFAIA was written by Democratic Senator Scott Wiener, who also wrote last year's vetoed version. </p><p>To encourage transparency, the law requires large frontier developers to publish a framework describing how it incorporates national and international standards, in effect sharing their safety plans. </p><p>The law also sets up a new mechanism for companies and the public to report critical safety incidents to California’s Office of Emergency Services and creates protection for whistleblowers who disclose significant health and safety risks of frontier models, with a civil penalty for noncompliance. </p><p>However, it only requires reports in case of physical harm, with the <em>San Francisco Public Press </em><a href="https://www.sfpublicpress.org/californias-ai-safety-law-beats-new-yorks-to-finish-line-but-trades-away-safety-and-liability-provisions/" target="_blank"><u>stating</u></a> that's been watered down from last year's bill which required all incidents to be reported. The TFAIA also comes ahead of one planned by New York, which requires reporting of any potential risk of serious harm, even before an incident happens. Under the TFAIA, California will fine companies that injure or "contribute to the death of" more than 50 people, or cause $1bn in damage. </p><p>But the fine has been slashed from $10m to $1m for a company's first violation, with the larger amount now reserved only for subsequent infractions. New York plans to fine up to $30m for repeated offenses, the <em>San Francisco Public Press </em>report added. </p><p>The newly signed regulation also means California will support development of safe AI: first it has established a consortium called CalCompute within the state's Government Operations Agency to develop its own framework for creating a public computing cluster to "advance the development and deployment" of AI that is safe, ethical, equitable and sustainable, the statement from the governor's office said. </p><p>To enable the law to keep up with innovation, the California Department of Technology can annually recommend updates based on stakeholder feedback, changes to international standards, or tech developments. </p><p>"As artificial intelligence continues its long journey of development, more frontier breakthroughs will occur," said a trio of AI leaders who helped lead a report into AI for Newsom, in a statement released alongside the governor’s. </p><p>The trio consists of Fei-Fei Li, co-director at the Stanford Institute for Human-Centered Artificial Intelligence; Jennifer Tour Chayes, dean of the College of Computing, Data Science, and Society at UC Berkeley; and Mariano-Florentino Cuéllar, former California supreme court justice and former member of the National Academy of Sciences Committee on the Social and Ethical Implications of Computing Research.</p><p>"AI policy should continue emphasizing thoughtful scientific review and keeping America at the forefront of technology," the trio added.</p><h2 id="california-counters-trump-administration-moves-on-ai">California counters Trump administration moves on AI</h2><p>The move puts Newsom further at odds with President Trump, who widely supports unfettered development of the technology.</p><p>The government attempted to force into an unrelated bill a provision to <a href="https://www.itpro.com/business/policy-and-legislation/a-decade-long-ban-on-ai-laws-is-a-terrible-idea-for-everyone-but-big-tech-critics-claim"><u>ban state-level AI legislation for ten years</u></a>, though it was <a href="https://www.reuters.com/legal/government/us-senate-strikes-ai-regulation-ban-trump-megabill-2025-07-01/"><u>removed by Senate amendment in July</u></a>. In January, President Trump issued an executive order "removing barriers to American leadership in AI" that ended a Biden order on developing safe and secure AI and followed this in July with the US <a href="https://www.itpro.com/business/policy-and-legislation/does-the-us-ai-action-plan-add-up-and-how-will-it-change-the-global-ai-landscape"><u>AI Action Plan</u></a> which aims to heavily deregulate AI.</p><p>A statement released from the governor's office notes: "This legislation is particularly important given the failure of the federal government to enact comprehensive, sensible AI policy. SB 53 fills this gap and presents a model for the nation to follow."</p><iframe allow="" height="200px" width="100%" id="" style="" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/e72e3adf-5bdc-4be4-bfe8-51510b6b9843/"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Three things you need to know about the EU Data Act ahead of this week's big compliance deadline ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/three-things-you-need-to-know-about-the-eu-data-act-ahead-of-this-weeks-big-compliance-deadline</link>
                                                                            <description>
                            <![CDATA[ A host of key provisions in the EU Data Act will come into effect on 12 September, and there’s a lot for businesses to unpack. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">RLXZuY9bCm8EwcWY4Xc4q5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YPLAJxoRSrPttgxeZWQkeG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 11 Sep 2025 12:02:00 +0000</pubDate>                                                                                                                                <updated>Thu, 11 Sep 2025 12:02:32 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YPLAJxoRSrPttgxeZWQkeG-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[European Union (EU) concept image showing flag on a digitized background with ripples flowing out from 12 stars.]]></media:description>                                                            <media:text><![CDATA[European Union (EU) concept image showing flag on a digitized background with ripples flowing out from 12 stars.]]></media:text>
                                <media:title type="plain"><![CDATA[European Union (EU) concept image showing flag on a digitized background with ripples flowing out from 12 stars.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YPLAJxoRSrPttgxeZWQkeG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A host of key provisions in the EU Data Act will come into effect on 12 September, and there’s a lot for businesses to unpack. </p><p>The regulation came into force on 11 January 2024 and while a grace period has been running to ensure implementation, rules under the legislation will be applicable across the European Union (EU) from here onward. </p><p>At its core, the EU Data Act will introduce sweeping changes with regard to how data from connected devices and cloud services is accessed, managed, and shared across the union. This includes new rules on data access, service portability for organizations, and contractual fairness. </p><p>The potential long-term impact of the legislation cannot be understated, according to Soniya Bopache, VP and general manager for data compliance at Arctera. </p><p>“The EU Data Act has the potential to foster a more competitive and equitable data economy – largely thanks to its provisions on data access, fair contractual terms, and cloud switching,” she said. </p><p>“For businesses governed by the Act, this isn’t just a matter of compliance, it’s an opportunity to build a more transparent, efficient, and innovative digital ecosystem.”</p><p>So what can businesses expect with the EU Data Act?</p><h2 id="what-industries-fall-under-the-eu-data-act">What industries fall under the EU Data Act?</h2><p>The legislation applies to a broad range of sectors, spanning areas such as manufacturing, <a href="https://www.itpro.com/627952/what-is-cloud-computing">cloud computing</a>, transport, and consumer goods. </p><p>Moreover, it’s not limited to the private sector, with public sector organizations also expected to benefit from the legislation, according to Peter Grimmond, VP and head of technology at <a href="https://www.itpro.com/cloud/cloud-security/cohesity-expands-partnership-with-google-cloud-to-drive-generative-ai-data-insights">Cohesity</a>.</p><p>“The EU Data Act has huge potential to deliver acceleration of both public and private sector innovation, through increased <a href="https://www.itpro.com/business/data-and-insights/what-is-data-democratization">data democratization</a> and access,” he said. </p><p>“For all enterprise and public sector organisations that have a robust, compliant, data classification processes already in place, the act will create an environment of collaboration and innovation where innovation can thrive without compromising corporate resilience or individual rights”</p><h2 id="data-access-and-transparency">Data Access and Transparency</h2><p>Data access and transparency is a key focus of the legislation, according to official EU <a href="https://digital-strategy.ec.europa.eu/en/factpages/data-act-explained" target="_blank"><u>materials </u></a>on the Act. </p><p>Fundamentally, the regulations are designed to “enhance the EU’s data economy and foster a competitive data market” by making data more accessible and usable. </p><p>The move comes in the wake of an explosion of connected devices across the union in recent years. These IoT products collect vast volumes of data, which the legislation aims to capitalize on for reuse across the region. </p><p>To achieve this, new rules under the act will give users of connected devices - including businesses and individuals - greater control over the data they produce. </p><p>Similarly, the Act also includes rules on how enterprises can share data with other businesses. According to Grimmond, this aspect of the legislation could deliver positive long-term benefits for both businesses and consumers alike. </p><p>“It will speed the ability for data to be shared from more devices across more organisations, and opens the door for the development of new products, services, and ways of doing business,” he explained. </p><p>“Crucially, it does this without undermining the robust privacy standards that are the EU’s hallmark regulatory framework: building on <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR’s </a>global standard for privacy and aligning with <a href="https://www.itpro.com/business/policy-legislation/368414/eu-digital-operational-resilience-act-dora">DORA’s </a>focus on digital operational resilience.”</p><h2 id="cloud-service-flexibility">Cloud service flexibility</h2><p>As mentioned, another core aspect of the legislation centers around data portability, particularly with regard to cloud services. The Act aims to provide enterprises more flexibility in how they engage with cloud providers and, crucially, switching or opting for multiple options. </p><p>This aspect of the legislation comes in direct response to growing calls for a more fluid and competitive cloud computing industry in the EU, with enterprises having contended with “<a href="https://www.itpro.com/cloud/362542/vendor-lock-in-is-it-worth-worrying-about-in-the-cloud">vendor lock-in</a>” for several years now. </p><p>Running parallel to this frustration has been the rise of <a href="https://www.itpro.com/cloud/34476/what-is-multi-cloud">multi-cloud</a> and <a href="https://www.itpro.com/hybrid-cloud/29668/what-is-hybrid-cloud">hybrid cloud</a> strategies, whereby enterprises host data on multiple providers, or through a combination of on-prem and cloud-based services. </p><p>Yet businesses with one particular cloud provider aiming to switch to another have faced significant costs transferring data. These “egress fees” have become a recurring point of contention and even prompted legal action against major industry providers. </p><p>With this in mind, the EU Data Act includes measures that ensure customers can switch from one data processing service to another in a more efficient manner. </p><p>Notably, the Act doesn’t specifically rule out vendors charging fees for data transfers. However, it obliges cloud providers to pass on these costs to the customer rather than charging excessive payments. </p><p>Some providers have taken steps to adhere to the new legislation. Google Cloud, for example, recently announced it would <a href="https://www.itpro.com/cloud/cloud-computing/google-cloud-introduces-no-cost-data-transfers-for-uk-eu-businesses">waive data transfer fees for customers switching to another provider</a>. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/business/policy-and-legislation/dora-and-why-resilience-once-again-matters-to-the-board">DORA and why resilience (once again) matters to the board</a></li><li><a href="https://www.itpro.com/business/policy-legislation/370403/what-is-the-network-and-information-security-2-nis2-directive">Everything you need to know about the NIS2 Directive</a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/the-second-enforcement-deadline-for-the-eu-ai-act-is-approaching-heres-what-businesses-need-to-know-about-the-general-purpose-ai-code-of-practice">What businesses need to know about the General-Purpose AI Code of Practice</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Does the US AI Action Plan add up and how will it change the global AI landscape? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/does-the-us-ai-action-plan-add-up-and-how-will-it-change-the-global-ai-landscape</link>
                                                                            <description>
                            <![CDATA[ Businesses should expect to feel benefits in the short term, especially AI developers with potential to land government contracts – but experts warn of risks on the horizon ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3kAG2gSYNdWdWMYFatma25</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PoxYYUyR7HNMj3jjB29374-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 25 Aug 2025 08:00:00 +0000</pubDate>                                                                                                                                <updated>Tue, 02 Dec 2025 13:53:30 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ keumars.afifi-sabet@futurenet.com (Keumars Afifi-Sabet) ]]></author>                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PoxYYUyR7HNMj3jjB29374-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[US President Donald Trump speaking at a podium during the &quot;Winning the AI Race&quot; summit, flanked by the slogans &quot;Winning The AI Race&quot; and &quot;ALL-IN&quot; on boards.]]></media:description>                                                            <media:text><![CDATA[US President Donald Trump speaking at a podium during the &quot;Winning the AI Race&quot; summit, flanked by the slogans &quot;Winning The AI Race&quot; and &quot;ALL-IN&quot; on boards.]]></media:text>
                                <media:title type="plain"><![CDATA[US President Donald Trump speaking at a podium during the &quot;Winning the AI Race&quot; summit, flanked by the slogans &quot;Winning The AI Race&quot; and &quot;ALL-IN&quot; on boards.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PoxYYUyR7HNMj3jjB29374-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US has injected fuel into the AI arms race with an <a href="https://www.whitehouse.gov/wp-content/uploads/2025/07/Americas-AI-Action-Plan.pdf"><u>Action Plan</u></a> — a sweeping set of aggressively deregulatory and integrative measures that collectively aim to cement American dominance in the technology. </p><p>"Whoever has the largest AI ecosystem will set global AI standards and reap broad economic and military benefits. Just like we won the space race, it is imperative that the United States and its allies win this race," wrote Michael J Kratsios, assistant to the President for science and technology; David O Sacks, special advisor for AI and crypto; and Marco Rubio, assistant to the President for national security affairs, in the policy.</p><p>The plan itself is focused on three core pillars: accelerating AI innovation, building American AI infrastructure, and leading in international AI diplomacy and security. Beyond the age-old adage of cutting metaphorical "rad tape", the measures also include plans to strip out perceived pro-liberal bias from AI systems and remove <a href="https://www.itpro.com/technology/artificial-intelligence/the-risks-of-open-source-ai-models"><u>guardrails from AI development</u></a>. Adnan Masood, chief AI architect at UST, tells <em>ITPro</em> this is a "win the race" blueprint that is significant for its "pivot to permissionless innovation".</p><p>There will undoubtedly be repercussions for those domestically and abroad, as the plan pledges to change the global economic and trade outlook. That said, it is important to remember that this is merely a plan – not a self-effectuating document, according to Cobun Zweifel-Keegan, managing director, DC at the International Association of Privacy Professionals (IAPP).</p><p>"Some of the actions outlined in the plan have already seen progress through executive orders, but many remain just ideas on a page. Nevertheless, it is a very helpful document toward understanding the Administration’s full slate of expected actions on AI and it’s the first real preview we have had into the current thinking on AI policy within the White House."</p><p>But how exactly should businesses expect to adapt to the new framework?</p><h2 id="what-s-the-point-of-the-ai-action-plan">What's the point of the AI Action Plan?</h2><p>The AI Action Plan rolls back on the capacity for various bodies in the US to regulate AI or add core safeguards while the technology is being developed. It contains more than 90 policy recommendations focusing on innovation, infrastructure, and protecting national security. If implemented, the plan has the potential to significantly change what AI developers should expect to do from a compliance standpoint. In other words, it's a ‘shoot first, ask questions later’ approach to AI development. But the gamble may well pay off, according to experts. </p><p>"At its core, the plan treats AI not as just another tech sector, but as <a href="https://www.itpro.com/infrastructure/data-centres/data-centers-finally-get-critical-national-infrastructure-designation-in-the-uk">critical national infrastructure</a> similar to energy or defense," Angeli Patel, executive director from UC Berkeley Law and Business and a practicing attorney, tells <em>ITPro</em>. "Its top priority is ensuring America, not authoritarian regimes, sets the global course for AI by doubling down on domestic strength and production while embedding democratic values of free speech into the systems shaping our future."</p><p>The Action Plan also elevates AI development by giving it the same importance as national infrastructure – positioning AI as 'protected' against foreign adversaries and domestic regulation. "That means more money, faster deployment, and a clear win for Big AI."</p><p>]Masood agrees that the thrust of the plan is around deregulating early, building fast and exporting American AI end-to-end, adding that it seems substantive enough to achieve these core aims both on paper and in its early implementation. "The plan is dense with agency tasks and the GSA [General Services Administration] vendor list is already live, signaling procurement intent. The crux is execution on permitting, grid, and <a href="https://www.itpro.com/business/policy-and-legislation/what-the-us-china-chip-war-means-for-the-tech-industry">fabs</a>."  </p><h2 id="big-tech-companies-are-big-winners">Big Tech companies are big winners </h2><p>AI developers stand to gain vastly from the new measures, experts tell<em> ITPro</em>. With better access to compute, <a href="https://www.itpro.com/business/careers-and-training/ai-skills-shortages-exacerbated-by-surging-salary-demands">talent</a>, and a mergers and acquisitions market that is heating up. Patel expects booms in privacy tech, cybersecurity and AI education: "For businesses generally, AI adoption will spread rapidly if it hasn't already – from backend ops to customer-facing products."</p><p>Masood believes the industry has plenty to look forward to, as an AI architect and practitioner himself. Promoting <a href="https://www.itpro.com/technology/artificial-intelligence/just-how-open-are-the-leading-open-source-ai-platforms">open-weight model development</a>, where internal parameters used in the training of large language models (LLMs) are made public, is an exciting proposition in particular. This, combined with standardized evaluations and testbeds, as well as easier federal access and richer public scientific databases, will directly translate into faster time-to-pilot for new systems, more deployment options and clearer acceptance criteria in regulated industries.</p><p>The fact that the administration supports the rights of AI developers to use <a href="https://www.itpro.com/technology/artificial-intelligence/government-consults-on-controversial-ai-training-rules">copyrighted materials in training AI models</a>, under "fair use" conditions, is also a nod to developers, with some early district court decisions being favorable to AI developers, according to <a href="https://www.arnoldporter.com/en/perspectives/advisories/2025/07/americas-ai-action-plan" target="_blank"><u>Arnold&Porter legal analysis</u></a>. There are, however, some hesitations on whether these decisions will hold considering the Supreme Court has not weighed in, nor has Congress on deciding definitively which way the fair use question will fall.   </p><p>"It’s been clear since <a href="https://www.itpro.com/technology/artificial-intelligence/uk-and-us-reject-paris-ai-summit-agreement-as-atlantic-rift-on-regulation-grows">February’s AI Summit in Paris</a> – that also focused on Action – that the Trump administration was going to enable AI in an unencumbered way. So the copyright decision is no surprise," says Amanda Brock, CEO of the open source trade organization OpenUK.</p><p>"The content creators shouldn’t be too upset," Brock tells <em>ITPro. </em>"They haven’t won licensing fees for AI training but the reality is that supporting them is a long-term challenge, created by the digital age. This is not purely a consequence of AI and would never really be resolved by copyright. More appropriate long-term solutions are needed."</p><p>Meanwhile, the investment picture is looking particularly rosy as a result of the new AI policy recommendations. Masood highlights that, for the likes of <a href="https://www.itpro.com/cloud/cloud-computing/openai-oracle-cloud-deal-stargate">Oracle</a> and <a href="https://www.itpro.com/business/digital-transformation/uk-government-inks-five-year-cloud-and-ai-deal-with-microsoft">Microsoft</a>, who are big government players, there will be higher public sector workloads. For chip makers, meanwhile, there will be a strong demand and a boost in sales toward allied and US markets, in light of export control tightening. The emphasis on domestic fabrication, too, supports long-term supply security.</p><p>Patel says that Oracle, Microsoft, <a href="https://www.itpro.com/business/business-strategy/everything-you-need-to-know-about-nvidia">Nvidia</a> and data center providers like Equinix "stand to gain from expanded government procurement and strong policy tailwinds". She adds: "At minimum, they’ll benefit from favorable regulatory treatment. At best, they'd be able to bid for direct federal investment. One of the most significant benefits for these AI infrastructure giants is the streamlining, or outright removal, of <a href="https://www.itpro.com/infrastructure/data-centres/nuclear-data-centers-are-a-waste-of-time">environmental permitting for AI-related infrastructure</a>."  </p><h2 id="what-risks-does-the-new-approach-to-ai-open-up">What risks does the new approach to AI open up?</h2><p>The biggest concern the experts have with the Action Plan is the additional risk that it might add. The Biden administration focused its AI policy on mitigating the risks of disinformation, among other areas. But the National Institute of Standards and Technology (NIST) will now remove any references to diversity, equity and inclusion (DEI) and climate change, as well as misinformation, from its <a href="https://www.nist.gov/itl/ai-risk-management-framework"><u>AI risk management framework (RMF)</u></a>.</p><p>Patel notes that such <a href="https://www.itpro.com/business/business-strategy/dei-recruitment-strategy-ai-skills">disregard for issues like DEI risks narrowing the innovation pipeline</a> in the long term. "The plan <a href="https://www.itpro.com/business/business-strategy/did-we-all-just-forget-diverse-tech-teams-are-successful-ones">sidelines DEI-focused research</a>, which is critical for addressing <a href="https://www.itpro.com/technology/artificial-intelligence/organizations-face-ticking-timebomb-over-ai-governance">bias and underrepresentation in LLMs</a> and threatens to withhold support from states or organizations that don’t align politically. That’s not just bad for equity; it’s bad for innovation. By rewarding compliance over creativity, the plan may accelerate dominance at the cost of resilience."</p><p>She adds that the biggest downside of the plan is its shortsightedness. "Investing in AI infrastructure while cutting corners on environmental protection and workforce development may help scale the technology over the next five to ten years, but at the cost of hollowing out our core," she explains.</p><p>"Job displacement is already underway, and misinformation is already costing billions. This plan accelerates both, with no meaningful guardrails in place. It’s also combative by design. By framing AI as an arms race with China, the plan treats AI as a geopolitical weapon rather than a global system that demands multilateral stewardship. It misses the opportunity to use interdependence as a tool for de-escalation and collective resilience."</p><p>Masood focuses on the possible risks in enterprise safety as well as the nightmare of dual compliance, where enterprises will have to invest resources into <a href="https://www.itpro.com/business/policy-and-legislation/governance-risk-and-compliance-is-a-major-growth-opportunity-but-how-will-the-market-develop">complying with both US policies as well as EU regulations</a>. With fewer ex-ante rules, regulations devised to prevent disasters before they happen, there will be an uptick in policing failures, including critical bias, safety incidents and privacy breaches, after they occur through existing laws and torts.  </p><p>In the coming months and years, states will react to the recommendations within the plan and act accordingly. The Trump administration has threatened to divert AI-related federal funding from states with "burdensome AI regulations" and this could have an effect on businesses within those states.</p><p>Though <a href="https://www.itpro.com/business/policy-and-legislation/californias-ai-bill-is-dead-in-the-water-and-big-tech-can-breathe-a-sigh-of-relief">California's AI bill was quashed</a> by state governor Gabin Newsom in 2024, Colorado's own AI bill targeting algorithmic discrimination comes into force from February 2026. Other states looking to introduce AI transparency legislation include New York – and IT leaders will need to closely follow how legislation develops in any state they operate within.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The second enforcement deadline for the EU AI Act is approaching – here’s what businesses need to know about the General-Purpose AI Code of Practice ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/the-second-enforcement-deadline-for-the-eu-ai-act-is-approaching-heres-what-businesses-need-to-know-about-the-general-purpose-ai-code-of-practice</link>
                                                                            <description>
                            <![CDATA[ General-purpose AI model providers will face heightened scrutiny ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">a8ZtL4J6csok6tvrb68aoh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YPLAJxoRSrPttgxeZWQkeG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 31 Jul 2025 09:26:10 +0000</pubDate>                                                                                                                                <updated>Thu, 31 Jul 2025 09:26:31 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YPLAJxoRSrPttgxeZWQkeG-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[European Union (EU) concept image showing flag on a digitized background with ripples flowing out from 12 stars.]]></media:description>                                                            <media:text><![CDATA[European Union (EU) concept image showing flag on a digitized background with ripples flowing out from 12 stars.]]></media:text>
                                <media:title type="plain"><![CDATA[European Union (EU) concept image showing flag on a digitized background with ripples flowing out from 12 stars.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YPLAJxoRSrPttgxeZWQkeG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The second major enforcement deadline for the EU AI Act is approaching, meaning big tech firms will face a greater degree of scrutiny over AI model safety. </p><p>From August 2nd, new governance rules for general-purpose AI (GPAI) models will be introduced through a <a href="https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai#:~:text=The%20General%2DPurpose%20AI%20(GPAI,drafting%20process%20of%20the%20code." target="_blank"><u>voluntary Code of Practice</u></a>. </p><p>The deadline represents the second major enforcement date for the landmark legislation this year, following on from a <a href="https://www.itpro.com/technology/artificial-intelligence/a-big-enforcement-deadline-for-the-eu-ai-act-is-just-around-the-corner">February deadline which focused primarily on prohibited use cases</a>. </p><p>Enza Iannopollo, VP principal analyst at Forrester, said that while the onus will be placed on providers, enterprise end-users will also likely feel the impact of the new rules. </p><p>“Whilst the first regulatory milestone on 2nd February focused on requirements, including those on prohibited use cases, this second deadline expands accountability and enforcement as it introduces critical provisions regarding general-purpose AI (GPAI) models,” she explained.</p><p>“Providers of <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai">generative AI</a> models are directly responsible for meeting these new rules, however it’s worth noting that any company using genAI models and systems — those directly purchased from genAI providers or embedded in other technologies — will feel the impact of these requirements on their value chain and on their third-party <a href="https://www.itpro.com/security/do-risk-awareness-and-risk-management-strategies-actually-make-a-difference">risk management</a> practices.”  </p><h2 id="what-the-gpai-code-of-practice-means-for-businesses">What the GPAI code of practice means for businesses</h2><p>The GPAI code of practice will enforce more robust guardrails for training AI models, according to EU lawmakers, and is based on three key pillars. </p><p>This includes greater transparency, meaning AI model providers are required to document and disclose training processes and share information on models with regulators. </p><p>Safety and security are a key focus of the code, again focusing on whether GPAI models pose risks to the public or enterprises. Under the new rules, providers are required to assess and document potential harms and take appropriate action to reduce any risks. </p><p>Dirk Schrader, resident CISO (EMEA) and VP of security research at Netwrix, said security considerations in the act are welcomed and help create a more aligned approach to AI-related security risks. </p><p>“One of the most significant anticipated successes of the Act is the standardization of AI security across the European Union, creating a harmonized, EU-wide security baseline,” he said. </p><p>“A key strength of the proposed regulations is their emphasis on a security-by-design ethos, mandating a lifecycle approach that integrates security considerations from the outset and throughout an <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>system's operational life.”</p><p>Security considerations do raise questions over compliance, however. Simply put, there isn’t a solid baseline for enterprises to work from with regard to <a href="https://www.itpro.com/technology/artificial-intelligence/majority-firms-using-generative-ai-related-security-incidents">AI-related security risks</a> at this stage. </p><p>“The Act is the first major law to call out protections against data poisoning, model poisoning, adversarial examples, confidentiality attacks, and model flaws,” he said. </p><p>“The real compliance burden will be determined by technical specifications that don't yet exist, as these will define the practical meaning of 'appropriate level of <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a>' and may evolve rapidly as AI threats mature.”</p><p>Elsewhere, rules pertaining to copyright are also outlined in the code of practice, and this has been a major point of contention in recent months. For example, under the code, signatories must ensure training data is sourced lawfully. </p><p>A host of major tech companies have agreed to the code of practice, most recently Google and OpenAI. Some, however, have taken a harder stance. </p><p>Earlier this month, <a href="https://www.itpro.com/business/policy-and-legislation/meta-isnt-playing-ball-with-the-eu-on-the-ai-act">Meta revealed it won’t sign up for the code of practice</a> amid what it described as concerns over “legal uncertainties”. </p><p>In a LinkedIn post clarifying the company’s stance on the code, Meta’s chief global affairs officer Joel Kaplan said the code will introduce measures which “go far beyond the scope of the AI Act”. </p><p>"Europe is heading down the wrong path on AI. We have carefully reviewed the European Commission’s Code of Practice for general-purpose AI (GPAI) models and Meta won’t be signing it," he said. </p><h2 id="the-risks-of-non-compliance">The risks of non-compliance</h2><p>Organizations that fail to comply with the EU AI Act face serious repercussions, and while the new code of practice is voluntary, Iannopollo said it’s crucial that enterprises operating in the region pay close attention to the enforcement deadline. </p><p>“Like it or not, the <a href="https://www.itpro.com/business/policy-and-legislation/unraveling-the-eu-ai-act">EU AI Act</a> will contribute to shape AI risk management and AI governance practices of most global companies,” she said. “Its requirements may not be perfect, but they are the only binding set of rules on AI with global reach, and it represents the only realistic option of <a href="https://www.itpro.com/technology/artificial-intelligence-ai/370342/inside-mozillas-mission-to-champion-trustworthy-ai">trustworthy AI</a> and responsible innovation. </p><p>“It’s crucial that companies operating AI technology in the EU, or using AI-generated insights within the EU market, pay attention to this enforcement milestone.”</p><p>The EU AI Act contains “significant fines” for non-compliance, including up to 7% of a company’s global turnover. Iannopollo noted that not all the authorities responsible for enforcement are up and running yet, but others are, including the <a href="https://www.itpro.com/business/policy-and-legislation/the-clock-is-ticking-for-firms-to-comply-with-the-eu-ai-act-heres-what-you-need-to-know">EU AI Office</a>. </p><p>“Companies, make no mistake: there will be action in the next few months,” she said. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/business/policy-and-legislation/the-eu-just-shelved-its-ai-liability-directive">The EU just shelved its AI liability directive</a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/how-the-eu-ai-act-compares-to-other-international-regulatory-approaches">How the EU AI Act compares to other international regulatory approaches</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/eu-ai-act-everything-you-need-to-know-about-the-legislation-including-rules-requirements-and-who-will-be-forced-to-comply">Everything you need to know about the EU AI Act</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NIS2: Why are firms struggling to comply? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/nis2-why-are-firms-struggling-to-comply</link>
                                                                            <description>
                            <![CDATA[ The Network and Information Systems 2 (NIS2) Directive continues to trip up organizations in critical industries, as leaders grapple with complex supply chains ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">UibKDRJMMgZ6XCpfvCRJLb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kJWLC66k6EEzELDxJmAGeK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Jul 2025 16:04:35 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kJWLC66k6EEzELDxJmAGeK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A shot of the empty European parliament, with concentric desks arranged around a central point off camera to the left.]]></media:description>                                                            <media:text><![CDATA[A shot of the empty European parliament, with concentric desks arranged around a central point off camera to the left.]]></media:text>
                                <media:title type="plain"><![CDATA[A shot of the empty European parliament, with concentric desks arranged around a central point off camera to the left.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kJWLC66k6EEzELDxJmAGeK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>It’s been some time since the <a href="https://www.itpro.com/business/policy-legislation/370403/what-is-the-network-and-information-security-2-nis2-directive"><u>Network and Information Systems 2 (NIS2) Directive</u></a> (NIS2) came into force in the EU but many organizations are still struggling to comply. So much so that the EU’s leading security agency ENISA has issued a <a href="https://www.enisa.europa.eu/news/enisa-nis360-2024-report"><u>stark warning</u></a> after finding that six <a href="https://www.itpro.com/security/cyber-attacks/why-attacks-against-critical-national-infrastructure-cni-are-such-a-threat"><u>critical national infrastructure</u></a> (CNI) sectors are failing in their implementation of the directive.</p><p>ENISA found a need to align requirements across borders in each NIS sector. It said that collaboration must be strengthened through community building events and cooperation at sector, national and EU level. </p><p>Some industries are more far behind others, according to the report, which calls out six sectors struggling to meet the expectations of NIS2: ICT service management, space, public administrations, maritime, gas and health. </p><p>So why is NIS2 compliance causing so many headaches and what can security leaders do about it? </p><h2 id="challenged-sectors">Challenged sectors</h2><p>Some sectors were not equipped to deal with NIS2’s cybersecurity requirements in the first place. Certain industries are struggling due to complex and outdated infrastructure, a lack of sector-specific guidance and “insufficient investment in cybersecurity measures”, says Matt Riley, director for information security at Sharp UK and Europe.</p><p>All the highlighted sectors in ENISA’s report share common challenges, says John Lynch, director at Kiteworks: “Complex supply chains with numerous third-party data exchanges, limited visibility into how sensitive data moves between entities, and difficulty implementing the governance controls required by NIS2 for secure data sharing across organizational boundaries.”</p><p>One of the most affected sectors is ICT service management, which faces difficulties due to its cross-border nature and the “vast number of diverse entities” involved, says Vincent Lomba, chief technical security officer at Alcatel-Lucent Enterprise. This complexity makes it challenging to implement uniform cybersecurity measures across all levels of the sector, he says.</p><p>Healthcare also faces obstacles in complying with the NIS2 Directive, because organizations tend to have complex, interconnected supply chains that introduce vulnerabilities. “Additionally, the widespread use of legacy systems and poorly secured medical devices increases the <a href="https://www.itpro.com/business/business-strategy/keeping-up-with-the-compliance-landscape-in-2024">difficulty of compliance</a>,” Lomba explains.</p><p>Adding to this, healthcare is often held back by tight budgets and a lack of resources, making it no surprise that compliance is challenging.  </p><p>Small businesses also face budget constraints and are under “significant pressure” to manage operating costs while maintaining their service delivery, says Lomba.</p><p>In contrast, sectors such as electricity, telecoms and banking have shown “strong resilience and maturity” in their cybersecurity practices, says Riley. </p><p>These sectors benefit from long-term investments, robust regulatory oversight, and strong public-private partnerships. This “proactive approach to cybersecurity”, including regular <a href="https://www.itpro.com/security/do-risk-awareness-and-risk-management-strategies-actually-make-a-difference">risk assessments</a>, continuous monitoring and “a culture of collaboration and information sharing” makes the sectors much more prepared than their peers in other industries, he points out.</p><h2 id="country-by-country-regulation">Country-by-country regulation</h2><p>There are issues with the regulation at a country level holding many firms back from NIS2 compliance. Only a handful of EU member states including Belgium, Croatia, Hungary, Italy, Latvia, and Lithuania have adopted national legislation to transpose the NIS2 Directive. Others <a href="https://digital-strategy.ec.europa.eu/en/news/commission-calls-19-member-states-fully-transpose-nis2-directive" target="_blank">remain at various stages of implementation</a>, says Scott Hudson, principal consultant at Bridewell.</p><p>Governments are facing capacity constraints and competing priorities, which has delayed the process, he says. “The fact that many member states have not yet established the laws needed to implement NIS2 clearly makes compliance challenging.”</p><p>The UK is not directly regulated by NIS2 following Brexit, but the regulation does impact firms doing business in the EU. At the same time, the UK has its own NIS regulations, which are being strengthened to align with NIS2's principles. </p><p>The proposed <a href="https://www.itpro.com/security/msps-face-scrutiny-in-cyber-security-and-resilience-bill"><u>UK Cyber Security and Resilience Bill</u></a> is not expected to be as broad in its sector focus as NIS2. Yet it will align the UK more closely with the EU's approach, says Clare Reynolds, digital resilience specialist at Taylor Wessing UK. “The expectation is that the UK regime will be no more onerous than NIS2, with minimal additional policies required to comply with both.”</p><h2 id="compliance-quick-fixes-and-long-term-strategies">Compliance quick fixes and long term strategies</h2><p>If the NIS2 Directive impacts you, it’s important to not bury your head in the sand, says Hudson. He recommends gaining “a clear understanding of your assets, systems, critical functions and cyber risk exposure”, which he says is “essential” to remaining compliant. </p><p>Ollie Gower, senior managing director in the cybersecurity practice at FTI Consulting thinks an “organization-wide, risk-based approach” that “considers the business, culture, technology and supply chain” is key. “With so many elements to take into account, a pragmatic approach based on quick wins and clear prioritization of the most prominent gaps is recommended.”</p><p>To boost compliance with NIS2, organizations can adopt both quick fixes and long-term strategies. For a quick fix, Gower recommends firms appointing a leader to take control of NIS2. At the same time, organizations should focus on visibility. “Map out your critical assets, ICT systems and suppliers. You can’t secure what you don’t fully understand.”</p><p>Riley concurs, advising firms to conduct “comprehensive risk assessments to <a href="https://www.itpro.com/software/367874/best-software-asset-management-tools">identify your assets</a>”.</p><iframe allow="" height="200px" width="100%" id="" style="" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/e72e3adf-5bdc-4be4-bfe8-51510b6b9843/"></iframe><p>At the same time, ensure you are implementing basic cybersecurity hygiene practices such as regular software updates and patch management, and providing awareness training to employees, he adds.</p><p>Long-term strategies involve developing a robust cybersecurity framework, aligned to recognized standards such as ISO27001, alongside continuous monitoring and regular audits. </p><p>Hudson also advises ensuring you have dedicated resources, either in-house or externally, with the right skills and capabilities to “assess risk, prioritize efforts and drive compliance forward”.</p><p>Supply chain risk is a major part of NIS2. Taking this into account, organizations — especially those in high-risk sectors with complex supply chains such as healthcare — need to start evaluating their third-party vendors more rigorously, says Gower. “Create a provider inventory, and ensure there are clear expectations in contracts with third parties around cybersecurity practices.” </p><p>Meanwhile, having a basic, well-communicated incident response plan in place can make “all the difference in a time of crisis”, says Gower. He recommends “getting leadership involved early” and “making sure they understand the stakes.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Meta isn’t playing ball with the EU on the AI Act ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/meta-isnt-playing-ball-with-the-eu-on-the-ai-act</link>
                                                                            <description>
                            <![CDATA[ Europe is 'heading down the wrong path on AI', according to Meta, with the company accusing the EU of overreach ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KhFr49uEw5Fx54P4VMjqo6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Kk6Qvhw6UhQGx3igACUs4E-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 21 Jul 2025 10:33:02 +0000</pubDate>                                                                                                                                <updated>Mon, 21 Jul 2025 10:33:24 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Kk6Qvhw6UhQGx3igACUs4E-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo and branding of Meta, developer of the Llama 4 AI model range, pictured at an event in Mumbai, India.]]></media:description>                                                            <media:text><![CDATA[Logo and branding of Meta, developer of the Llama 4 AI model range, pictured at an event in Mumbai, India.]]></media:text>
                                <media:title type="plain"><![CDATA[Logo and branding of Meta, developer of the Llama 4 AI model range, pictured at an event in Mumbai, India.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Kk6Qvhw6UhQGx3igACUs4E-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Meta has said it won't sign up for the EU's code of practice for providers of <a href="https://www.itpro.com/technology/artificial-intelligence/the-eu-just-launched-a-bold-new-initiative-to-support-regional-ai-startups-and-drive-innovation">general-purpose AI models</a>, citing concerns over "legal uncertainties".</p><p>The voluntary guidelines form part of the <a href="https://www.itpro.com/technology/artificial-intelligence/eu-ai-act-everything-you-need-to-know-about-the-legislation-including-rules-requirements-and-who-will-be-forced-to-comply">EU AI Act</a>, due to come into force next month. They ask companies to, amongst other things, refrain from <a href="https://www.itpro.com/technology/artificial-intelligence/dollar100-billion-to-build-an-ai-model-anthropic-ceo-dario-amodei-predicts-soaring-ai-training-costs-but-models-will-become-far-more-powerful">training AI</a> on pirated materials and comply with requests from content creators to omit their work from training data.</p><p>As part of the rules, providers are also required to issue regular updates on <a href="https://www.itpro.com/software/development/ai-tools-software-development-workforce-layoffs">AI tools</a> and services.</p><p>While the code is voluntary, the EU has said that AI providers who don't sign up will be expected to demonstrate compliance by other means, and might face more regulatory scrutiny.</p><p>Meta has hit back at lawmakers, however, accusing the EU of overreach. </p><p>"Europe is heading down the wrong path on AI. We have carefully reviewed the European Commission’s Code of Practice for general-purpose AI (GPAI) models and Meta won’t be signing it," wrote chief global affairs officer Joel Kaplan in a <a href="https://www.linkedin.com/posts/joel-kaplan-63905618_europe-is-heading-down-the-wrong-path-on-activity-7351928745668055042-XuF7/" target="_blank"><u>post on LinkedIn</u></a>. </p><p>"This Code introduces a number of legal uncertainties for model developers, as well as measures which go far beyond the scope of the AI Act."</p><h2 id="meta-has-history-with-the-eu">Meta has history with the EU</h2><p>Meta has been complaining about the AI Act for a while. Last summer, <a href="https://www.itpro.com/software/development/a-sign-of-things-to-come-in-software-development-mark-zuckerberg-says-ai-will-be-doing-the-work-of-mid-level-engineers-this-year-and-hes-not-the-only-big-tech-exec-predicting-the-end-of-the-profession">Mark Zuckerberg</a> and Spotify CEO Daniel Ek issued a <a href="https://about.fb.com/news/2024/08/why-europe-should-embrace-open-source-ai-zuckerberg-ek/" target="_blank"><u>joint statement</u></a> saying that "Europe’s risk-averse, complex regulation could prevent it from capitalizing on the big bets that can translate into big rewards."</p><p>The tech giant has support from US president Donald Trump on the issue, who has called for the AI Act to be paused - although the EU appears to be standing firm. </p><p>Henna Virkkunen, the European Commission vice-president responsible for tech sovereignty, recently said lawmakers are "very committed to our rules when it comes to the digital world". </p><p>Earlier this month, companies including Google, Meta, Airbus, BNP Paribas, and TotalEnergies called for a two-year delay in implementation, claiming that as it stands, the AI Act will stifle innovation.</p><p>"Businesses and policymakers across Europe have spoken out against this regulation. Earlier this month, over 40 of Europe’s largest businesses signed a letter calling for the Commission to ‘Stop the Clock’ in its implementation," said Kaplan. </p><p>"We share concerns raised by these businesses that this over-reach will throttle the development and deployment of frontier AI models in Europe, and stunt European companies looking to build businesses on top of them."</p><p>OpenAI and Mistral have already signed the code - although the latter has voiced concerns about the impact of the legislation.</p><p>"Compliance with the Code and the AI Act’s risk based framework must be as simple and streamlined as possible for the homegrown start-ups and smaller businesses that will be the future leaders of Europe’s AI-first economy," said OpenAI in a <a href="https://openai.com/global-affairs/eu-code-of-practice/"><u>statement</u></a>. </p><p>"We have advocated⁠ for greater simplification and harmonization to support these next generation companies and will continue to back their concerns, as they are key to AI of, by and for Europe." </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/technology/artificial-intelligence/the-uk-government-is-working-with-meta-to-create-an-ai-engineering-dream-team-to-drive-public-sector-adoption">The UK government is working with Meta to create an AI engineering dream team</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/meta-open-source-ai-linux-foundation">Meta faces new ‘open washing’ accusations with AI whitepaper</a></li><li><a href="https://www.itpro.com/infrastructure/data-centres/meta-working-on-a-5gw-data-center-to-supercharge-ai-infrastructure-and-mark-zuckerberg-says-one-cluster-alone-covers-a-significant-part-of-the-footprint-of-manhattan">Meta is working on a 5GW data center to supercharge AI infrastructure</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What the UK’s Online Safety Act means for IT companies ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/what-the-uks-online-safety-act-means-for-it-companies</link>
                                                                            <description>
                            <![CDATA[ Experts reveal the potential impact and necessary requirements of the UK’s Online Safety Act, introduced to protect children from harmful content online ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uWac3zfj8VMrXLsdiqGknN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RytBMt57BpcZ3EQpS9yi4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 15 Jul 2025 11:35:39 +0000</pubDate>                                                                                                                                <updated>Mon, 21 Jul 2025 12:50:51 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dan Oliver ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/fUHHmswmUp5prBWfMTLsgi.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Dan Oliver is a writer and B2B content marketing specialist with years of experience in the field. In addition to his work for &lt;em&gt;ITPro, &lt;/em&gt;he has written for brands including TechRadar, T3 magazine, and The Sunday Times.&lt;/p&gt;&lt;p&gt;In addition to his journalism, he has also worked in content marketing since 2016. In this capacity, he has produced reports, case studies, blogs, SEO strategies, and social media campaigns for brands including Microsoft, Dell, AWS, and the University of Bristol.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RytBMt57BpcZ3EQpS9yi4-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[View of the Houses of Parliament, London, UK.]]></media:description>                                                            <media:text><![CDATA[View of the Houses of Parliament, London, UK.]]></media:text>
                                <media:title type="plain"><![CDATA[View of the Houses of Parliament, London, UK.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RytBMt57BpcZ3EQpS9yi4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK government’s <a href="https://www.legislation.gov.uk/ukpga/2023/50"><u>Online Safety Act</u></a> (OSA) comes into force on 25 July 2025, requiring technology platforms to implement processes and systems to prevent users – particularly children – from accessing “harmful and age-inappropriate digital content”.</p><p>The UK’s media regulator, Ofcom, which will be enforcing the new act, says that 59% of teenage children (aged 13-17) have encountered potentially harmful content online. It has determined that technology providers can do more to address this and has set out new <a href="https://www.ofcom.org.uk/siteassets/resources/documents/consultations/category-1-10-weeks/statement-protecting-children-from-harms-online/main-document/codes-at-a-glance.pdf?v=395791"><u>codes of practice</u></a> to which these providers must adhere.</p><p>“The Online Safety Act introduces a fundamental shift in how online services – both UK-based and international – must operate when accessible by UK users,” explains Dr. Loredana Tassone, Managing Consultant and Head of EU and UK Representative Services at GRCI Law. “Ofcom now holds wide-ranging investigatory and enforcement powers, making <a href="https://www.itpro.com/business/policy-and-legislation/governance-risk-and-compliance-is-a-major-growth-opportunity-but-how-will-the-market-develop"><u>compliance</u></a> not just a legal necessity, but an operational and ethical imperative.”</p><p>The legislation regulates operators of digital platforms in a number of new ways, making them more responsible for their users’ safety. And it includes the responsibility to implement systems and processes that reduce the risk of illegal activity, including the removal of illegal content when it does appear. </p><p>“The regulator, Ofcom, has the power to require the provision of certain information, to issue fines of up to the greater of 10% of global annual turnover or £18m and to impose various business disruption measures,” says Nick Harrison, senior associate at global law firm Taylor Wessing. “New criminal offences are also introduced for certain breaches or failures to comply.”</p><p>All tech businesses operating in the UK need to carefully consider whether their services comply with the law and keep it in mind when seeking to expand in the region.</p><h2 id="ofcom-s-guidance">Ofcom’s guidance</h2><p>On 24 April 2025, Ofcom presented its codes of practice to the UK Parliament, <a href="https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/guide-for-services"><u>publishing guidance</u></a> on how providers should carry out risk assessments for evaluating the potential harm to children, with services given three months to complete their audits ahead of the 24 July deadline.</p><p>“The Act places significant demands on platform governance and user content moderation, especially for services likely to be accessed by children,” says Tassone. “Businesses will need to embed safety into their governance structures, assess and mitigate content risks proactively, and implement age assurance mechanisms that are effective yet privacy conscious.”</p><p>The OSA doesn’t just apply to UK businesses, either, or those with a physical presence in the United Kingdom; it applies to any service which has "links with the UK". </p><p>“This threshold can be met in a number of ways: if the number of UK users of the service is "significant" (this is deliberately not defined and will be context-dependent), if UK users are a target market of the service, or if content on the service presents a material risk of significant harm to users in the UK who can access the service,” Harrison tells <em>ITPro</em>. </p><p>The OSA sets out a range of duties and explains how providers should approach them. For example, one of the safety duties surrounding illegal content is to take proportionate measures to prevent users from encountering that content. And it also stipulates that this applies to how a service is designed, operated and used. </p><p>“It is simply not enough for a provider to say that it was happy with the original design of a service and the real-world operation of it was uncontrollable,” says Daniel Milnes, partner at Forbes Solicitors. “What happens to users, specifically including the effect of <a href="https://www.itpro.com/data-insights/30212/what-is-an-algorithm">algorithms</a>, is a provider’s responsibility. The existence of this specific set of duties, mandatory assessments and reporting, and dedicated enforcement powers, is certainly intended to make providers focus more on protecting users.”</p><h2 id="concerns-from-smes">Concerns from SMEs</h2><p>Smaller companies, especially SMEs and startups, have expressed concerns that the Online Safety Act may place excessive pressure on them.</p><p>"Implementation of the Online Safety Act faces hurdles in cost and technical feasibility,” explains Jason Soroko, Senior Fellow at Sectigo, a leading provider of <a href="https://www.itpro.com/network-internet/30416/http-vs-https-what-difference-does-it-make-to-security">SSL certificates</a>. “Platforms, especially smaller or independent operators, may struggle with the expense of robust age verification and content moderation tools. </p><p>“Enforcement also poses challenges due to varied jurisdictional reach and resource constraints. Regulators risk focusing on easily targeted platforms while larger, multinational sites exploit legal loopholes or inconsistent international cooperation.”</p><p>Kevin Quirk, director at AI Bridge Solutions, agrees that the Online Safety Act may result in smaller companies being disproportionately affected, whilst also facing greater scrutiny from Ofcom.</p><p>“While large tech firms have long had legal teams and compliance departments in place, the Act presents a real challenge for smaller companies like ours, particularly when trying to remain <a href="google.com/search?q=site%3Aitpro.com+agile&rlz=1C5GCEM_enGB1166GB1166&oq=site%3Aitpro.com+agile&gs_lcrp=EgZjaHJvbWUqBggAEEUYOzIGCAAQRRg7MgYIARBFGEAyBggCEEUYOtIBBzkzMmowajeoAgCwAgA&sourceid=chrome&ie=UTF-8">agile</a> and cost-effective,” Quirk tells <em>ITPro</em>. “Since the Act came into force, our clients have become far more cautious when launching new platforms. We’re seeing delays in deployment timelines while legal teams reassess features. Others have asked us to rebuild or modify platforms to better align with safety-by-design principles.”</p><p>Quirk also claims that, whilst the Act requires “reasonable steps” to be taken, it doesn’t do a satisfactory job of defining what “reasonable” looks like for an SME. “That ambiguity creates risk,” he says. “We’re spending more time than ever on policy, legal consultations, and risk assessments; resources that would otherwise go toward development and innovation.”</p><iframe allow="" height="200px" width="100%" id="" style="" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/e72e3adf-5bdc-4be4-bfe8-51510b6b9843/"></iframe><h2 id="potential-knock-on-effects">Potential knock-on effects</h2><p>Alongside the added pressure of cost and compliance, there have also been concerns raised about a lack of clarity around “harmful content”, which may further complicate compliance, as platforms concerned about incurring fines are forced to navigate the waters between the Scylla of harmful content and the Charybdis of excessive censorship. </p><p>“One consequence may be censorship,” says Boris Cipot, senior security engineer at Black Duck, which helps teams manage security and compliance risks. “In many cases, content will be removed or prohibited due to generic rules disregarding the context due to the fear of facing penalties. This may mean that different viewpoints might be disregarded.”</p><p>Nick Henderson-Mayo, Director of Learning and Content at compliance eLearning and software provider, VinciWorks, agrees that censorship needs to be addressed with consideration, as it could affect areas such as encryption, an issue that was <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it"><u>raised by companies such as WhatsApp and Signal in 2023</u></a>.</p><p>“<a href="https://www.itpro.com/security/encryption/the-encryption-stand-off-is-getting-weirder"><u>Encryption could be at risk</u></a> if scanning mandates go too far, and fear of fines might lead to over-censorship. Ofcom says it’ll act proportionately, but privacy-focused platforms are watching closely,” says Henderson-Mayo. “In fact, several chat app providers have warned that if compelled to scan private messages proactively, it would “nullify the purpose of end-to-end encryption”. Some secure messaging apps might even withdraw from the UK rather than compromise their encryption, but we will need to see if they are serious or just scaremongering.”</p><p>While the UK’s Online Safety Act will mirror the <a href="https://digital-strategy.ec.europa.eu/en/news/making-online-world-safer-children-and-young-people-safer-internet-day"><u>EU’s goal of making the internet safer</u></a>, with both the UK and EU acting in concert, there are concerns that the OSA and the EU’s Digital Services Act (DSA) may dissuade companies from launching and operating in Europe.</p><p>But Cipot tells <em>ITPro</em> that while firms may be concerned about this, the long-term effect is likely to be beneficial.</p><p>“Some services might not be willing to enter the UK market as they do not want to implement the additional safeguards. On the other hand, would you be ok using a service that does not have the safeguards provided by the Act?,” says Cipot. “I believe the Act will be a good way to ensure online safety improves.”</p><h2 id="preparing-for-the-online-safety-act">Preparing for the Online Safety Act</h2><p>To prepared for the OSA, IT companies will need to determine whether they are in-scope and, if so, familiarize themselves with the various duties under the OSA and related guidance from Ofcom. They should then begin carrying out <a href="https://www.itpro.com/security/do-risk-awareness-and-risk-management-strategies-actually-make-a-difference"><u>risk assessments</u></a> as soon as possible. “This is a significant task and should not be put off since the timelines are quite tight and many deadlines for compliance have already passed,” explains Harrison. </p><p>By 25 July, affected online services, which are likely to be accessed by UK children, need to complete their risk assessment and comply with Ofcom’s <a href="https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/quick-guide-to-childrens-safety-codes"><u>Protection of Children Codes</u></a>.</p><p>“The July 2025 deadline to protect children from harmful content adds urgency,” says Tassone. “Organizations should act now—conducting gap analyses, assigning accountability, and building cross-functional governance—to meet expectations and reduce compliance risk.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Confusing for developers and bad for users’: Apple launches appeal over ‘unprecedented’ EU fine ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/confusing-for-developers-and-bad-for-users-apple-launches-appeal-over-unprecedented-eu-fine</link>
                                                                            <description>
                            <![CDATA[ Apple is pushing back against new app store rules imposed by the European Commission, suggesting a €500m fine is a step too far. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SgBNKK3ovJuVCqEr9dFTBn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xFFY74w8NVNvf4jaQpUham-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Jul 2025 10:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xFFY74w8NVNvf4jaQpUham-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A pedestrian passes by an Apple smart products flagship store on Nanjing Road in Shanghai, China on June 29, 2025.]]></media:description>                                                            <media:text><![CDATA[A pedestrian passes by an Apple smart products flagship store on Nanjing Road in Shanghai, China on June 29, 2025.]]></media:text>
                                <media:title type="plain"><![CDATA[A pedestrian passes by an Apple smart products flagship store on Nanjing Road in Shanghai, China on June 29, 2025.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xFFY74w8NVNvf4jaQpUham-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/uk/software/apple">Apple </a>is pushing back against new app store rules imposed by the European Commission (EC), claiming the EU body has taken changes and a €500 million (£430m) fine too far. </p><p>The EC levied the fine in April, arguing Apple was in breach of anti-steering obligations in the <a href="https://www.itpro.com/business/policy-legislation/368435/what-is-the-eus-digital-markets-act-dma">EU Digital Markets Act (DMA)</a>. That refers to Apple's long-running ban on <a href="https://www.itpro.com/security/forcing-apple-to-allow-alternative-app-stores-might-cause-major-security-risks">alternative app stores</a> and rules that stop developers from telling users about discounts or other offers outside of the Apple platform. </p><p>Apple previously took a cut of up to 30% on sales inside apps and has been locked in a war of words over the practice with <a href="https://www.itpro.com/software/development/burnout-is-now-rife-across-the-software-community-with-almost-half-of-developers-turning-to-self-help-apps">developers</a>. </p><p>The tech giant complied with the app store rule changes last month in order to avoid additional fines that could reach 5% of its average revenue globally. </p><p>That included a wider range of commission rates up to 13%, alongside user acquisition fees, with the costs dependent on what marketing support the developer wants in the App Store as well as technical aspects such as automatic updates. </p><p>Developers will also be able to promote alternative ways of purchasing services outside the app, though Apple would charge a commission on sales advertised via apps in its App Store. </p><h2 id="apple-is-baffled-the-ec-is-standing-firm">Apple is baffled, the EC is standing firm</h2><p>Key to Apple’s argument, and appeal, is that the company claims this new system is "confusing" to business users. </p><p>"Today we filed our appeal because we believe the European Commission’s decision – and their unprecedented fine – go far beyond what the law requires," said Apple in a statement. </p><p>"As our appeal will show, the EC is mandating how we run our store and forcing business terms which are confusing for developers and bad for users."</p><p>Apple has yet to reply to a request for comment from <em>ITPro</em>. </p><p>The Commission, meanwhile, is standing by its decision. In a statement responding to the appeal, it <a href="https://www.theguardian.com/technology/2025/jul/07/apple-appeals-eu-fine-app-store#:~:text=%E2%80%9CToday%20we%20filed%20our%20appeal,highest%20court%20in%20the%20EU." target="_blank"><u>said</u></a>: "We stand ready to defend our decisions in court.” </p><p>The EC previously <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_24_3433" target="_blank"><u>said</u></a> that Apple shouldn't charge developers for the right to "steer" customers, suggesting that a commission on sales promoted in-app wouldn't meet requirements.</p><h2 id="political-battle">Political battle</h2><p>A legal expert told <a href="https://www.theguardian.com/technology/2025/jul/07/apple-appeals-eu-fine-app-store#:~:text=%E2%80%9CToday%20we%20filed%20our%20appeal,highest%20court%20in%20the%20EU." target="_blank"><u><em>The Guardian</em></u></a><em> </em>that Apple may be employing delay tactics. </p><p>"The blunt truth is that it is worth spending a few million on legal fees in order to disrupt and delay the development of a more open app ecosystem, which is a market that is worth many billions a year to Apple," Tom Smith, a competition lawyer at Geradin Partners, told the publication. </p><p>The app store quarrel isn't the only ongoing battle between the EU and tech companies. In April, Meta was hit with a €200m fine for charging users to get rid of ads, while last year Apple was fined €1.8bn over music streaming competition.</p><p>The appeal comes ahead of US President Donald Trump's 9 July deadline to settle a trade deal with the EU or risk 50% tariffs. The Trump administration has repeatedly said the EU is targeting US tech companies in retaliation for trade disruption and other political concerns, with Trump trade advisor Peter Navarro <a href="https://www.euronews.com/my-europe/2025/04/08/big-tech-probes-non-negotiable-in-us-trade-talks-brussels-warns" target="_blank"><u>calling</u></a> it "lawfare". </p><p>EU action against tech giants stretches back well before even the first Trump administration, with a €497 million fine against Microsoft in 2004 over Windows Media Player bundling that was later increased to €899 million for non-compliance. </p><p>That was followed by cases against Intel in 2009, an investigation against Google on search that began in 2010, and investigations into taxes that pulled in Apple and Amazon beginning in 2014. </p><p>That said, things have accelerated since 2017 with a €2.42bn fine against Google over price comparison shopping services. In subsequent years, EU lawmakers imposed a €4.34bn for Android and €1.49bn over AdSense, with other cases targeting Apple, Amazon and Meta in recent years. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/technology/artificial-intelligence/apple-ai-reasoning-research-paper-openai-google-anthropic">Apple throws cold water on the potential of AI reasoning</a></li><li><a href="https://www.itpro.com/security/apple-is-offering-rewards-of-up-to-usd1-million-to-find-critical-flaws-in-its-private-ai-cloud-systems">Apple is offering rewards of up to $1 million to find critical flaws in its private AI cloud systems</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/apple-our-ai-data-was-gathered-responsibly">Apple: Our AI data was gathered responsibly</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Will US tech workers get the right to disconnect? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/will-us-tech-workers-get-the-right-to-disconnect</link>
                                                                            <description>
                            <![CDATA[ International examples show the benefits of more hands-on protections for employees ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Xa9HoVaV7w4uk2TgbU427B</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/3RuckbKiSHGaTYKq6sKTL9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Jul 2025 07:45:00 +0000</pubDate>                                                                                                                                <updated>Wed, 02 Jul 2025 13:58:12 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rich McEachran) ]]></author>                    <dc:creator><![CDATA[ Rich McEachran ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/RRL5GmJQGuXidQxTVcGXXn.jpeg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/3RuckbKiSHGaTYKq6sKTL9-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A business person closing their laptop, which sits on a cluttered desk.]]></media:description>                                                            <media:text><![CDATA[A business person closing their laptop, which sits on a cluttered desk.]]></media:text>
                                <media:title type="plain"><![CDATA[A business person closing their laptop, which sits on a cluttered desk.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/3RuckbKiSHGaTYKq6sKTL9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The tech industry is known for its culture of long working days and employees putting in extra hours, either to get a project completed or because they’re collaborating with colleagues in another time zone. </p><p>The last thing tech workers want after logging out for the evening is to have to take a phone call or respond to an email about a non-urgent matter that could have waited until they’re in the office the next day. </p><p>This is why there are arguments for the US to adopt ‘right to disconnect’ legislation that would make it illegal for employers to contact their employees outside of working hours. </p><p>According to <a href="https://images.tech.co/wp-content/uploads/Techco-Workplace-Report-2025.pdf" target="_blank"><u>Tech.co's Impact of Technology on the Workplace Report 2025</u></a>, 83% of employees feel obligated to respond to work-related emails and calls even when on holiday. The survey of 1,036 US-based senior leaders at companies with at least 10 employees found that 72% of senior leaders in the tech industry support the 'right to disconnect’ law, while 14% are against and the other 14% are on the fence. </p><p>So is the US likely to adopt a law like this any time soon? And how could it look to international examples for benefits and drawbacks?</p><h2 id="how-other-countries-have-approached-the-issue">How other countries have approached the issue</h2><p>Different countries have taken different approaches to the ‘right to disconnect’. </p><p>Since 2017, companies in France with a headcount of at least 50 are required to draw up a charter in conjunction with union representatives setting out the hours that workers don’t have to send or respond to emails.  </p><p>France is currently <a href="https://www.eurofound.europa.eu/sites/default/files/2023-11/ef23002en.pdf" target="_blank"><u>one of ten EU states</u></a> that have introduced legislation. The others are Belgium, Croatia, Cyprus, Greece, Italy, Luxembourg, Portugal, Slovakia and Spain. </p><p>Australia <a href="https://www.fairwork.gov.au/newsroom/media-releases/2024-media-releases/august-2024/20240826-right-to-disconnect-stage-1-media-release"><u>adopted legislation</u></a> last year that allows employees at companies with a headcount of at least 15 to refuse to monitor, read or respond to contact outside of working hours without fear of being punished. The onus is on employers to discuss with their workers what constitutes a reasonable refusal, according to the Fair Work Ombudsman, Australia’s workplace regulator. </p><p>Failure to comply with these laws can lead to sizable fines, though the severity of the penalty varies country to country. </p><p>On the other hand, Ireland <a href="https://www.ictu.ie/blog/irelands-new-right-disconnect-how-it-works"><u>adopted a code of practice in 2021</u></a> that encourages employers to engage with employees on how they can disconnect in conjunction with union representatives. The code is voluntary, not statutory, though, so there’s no legal requirement, and, as such, there are no penalties for companies that don’t adopt it. </p><p>The UK is also <a href="https://www.itpro.com/business-strategy/flexible-working/359193/union-calls-for-the-right-to-disconnect-in-forthcoming"><u>weighing up</u></a> whether to introduce legislation. The Labour government has <a href="https://brodies.com/insights/employment-and-immigration/labours-right-to-switch-off-what-do-we-know-so-far/" target="_blank"><u>pledged to introduce</u></a> a ‘right to switch off’ law where “working from home does not become homes turning into 24/7 offices”. This is backed by the Trades Union Congress, which highlighted the need for the 'statutory right to disconnect’ in its draft AI Bill published in April last year. </p><h2 id="the-reality-of-the-us-implementing-legislation">The reality of the US implementing legislation </h2><p>California, known for its progressive politics, <a href="https://www.hrpolicy.org/insight-and-research/resources/2024/hr_workforce/public/04/california-becomes-first-state-to-push-for-right-t/" target="_blank"><u>became the first US state</u></a> to push for the ‘right to disconnect’ to be enshrined into law last year. But a bill that would have required employers to create boundaries for their workers was <a href="https://www.shrm.org/mena/topics-tools/employment-law-compliance/right-to-disconnect-bill-defeated" target="_blank"><u>shelved last May</u></a>.</p><p>The problem is labor laws in Europe have tended to focus on protecting workers, whereas US labor laws are more about protecting employer flexibility, Kelsey Szamet, partner at California-based employment law firm Kingsley Szamet Employment Lawyers, tells <em>ITPro</em>. </p><p>The US has also entered a period of deregulation across a number of industries, so it’s unlikely that the ‘right to disconnect’ will be legalized at the federal level during the current presidency. </p><p>If the US were to eventually adopt legislation, then the main takeaway from how other countries have implemented the ‘right to disconnect’, continues Szamet, is the need for explicit boundaries and to ensure sanctions are enforced on any company that fails to comply.</p><p>“There are some that will attempt to circumvent them by employing broad loopholes and ambiguous job definitions, such as labeling employees ‘exempt’ from overtime law,” she says. Tech workers, especially those at young, fast-paced startups that operate on a tight budget, may be considered ‘exempt employees’, meaning they’re not eligible for overtime pay as set out under the Fair Labor Standards Act. </p><p>To reduce resistance to the ‘right to disconnect’, there’s going to need to be a huge culture change. </p><p>“Countries like France and Belgium have made it clear that <a href="https://www.itpro.com/business/business-strategy/uk-workers-still-seeking-better-work-life-balance-report-says"><u>protecting personal time</u></a> isn’t a luxury; it's essential to sustaining a healthy workforce. Implementing similar protections in the US would challenge existing norms, but it’s not impossible,” says Greg Davis, CEO at Oregon-based cloud connectivity firm Bigleaf Networks.</p><p>Davis suggests one way companies can prepare for future legislation is by giving employees structured time to disconnect. </p><p>Szamet agrees with this sentiment, adding that the next best thing until legislation is passed is unionization and companies voluntarily introducing corporate policies that support employees to switch off once their working day is over. </p><p>“This would allow workers to set reasonable boundaries without waiting for lawmakers to catch up,” she concludes. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The security implications of the Data (Use and Access) Bill ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/the-security-implications-of-the-data-use-and-access-bill</link>
                                                                            <description>
                            <![CDATA[ The Data (Use and Access) Bill will revise the UK’s data protection policies, but what does that mean for businesses operating in the UK? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sUFT9utKNnT3P7P8Eixjo9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RytBMt57BpcZ3EQpS9yi4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 29 May 2025 15:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Peter Ray Allison ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RytBMt57BpcZ3EQpS9yi4-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[View of the Houses of Parliament, London, UK.]]></media:description>                                                            <media:text><![CDATA[View of the Houses of Parliament, London, UK.]]></media:text>
                                <media:title type="plain"><![CDATA[View of the Houses of Parliament, London, UK.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RytBMt57BpcZ3EQpS9yi4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://bills.parliament.uk/bills/3825"><u>Data (Use and Access) Bill</u></a> is the latest data protection legislation currently making its way through parliament and will apply to any organization operating in the UK. This bill aims to update the UK’s data policies, including <a href="https://www.itpro.com/security/gdpr/four-years-on-hows-uk-gdpr-holding-up"><u>UK GDPR</u></a>, <a href="https://www.legislation.gov.uk/ukpga/2016/25/contents"><u>Investigatory Powers Act 2016</u></a> and <a href="https://www.legislation.gov.uk/ukpga/2018/12/contents"><u>Data Protection Act 2018</u></a>, as well as relaxing the permitted uses of data processing for scientific research and streamlining data processing for public services.</p><p>There has been a growing expectation for some time that the UK’s data protection policies will be updated. The <a href="https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018">Data Protection Act 2018</a> was the previous such update and new technologies requiring legislative attention have emerged since then. A proposed update was planned earlier this year, but the <a href="https://bills.parliament.uk/bills/3430"><u>Data Protection and Digital Information (DPDI) Bill</u></a> was prorogued due to the change in government.</p><p>“My view is that the changes which have been proposed, even when taken together, won't threaten the UK's <a href="https://ico.org.uk/for-organisations/data-protection-and-the-eu/data-protection-and-the-eu-in-detail/adequacy/"><u>adequacy status</u></a>,” says Anthony Lee, a partner specialising in information technology and data protection at gunnercooke LLP. “Whereas I felt with the <a href="https://www.itpro.com/business/policy-and-legislation/data-protection-and-digital-information-dpid-bill-small-businesses"><u>DPDI</u></a>, there were quite a few changes that might well have resulted in the UK losing its adequacy status.”</p><p>Those hoping for a simple and condensed approach to data protection may be disappointed. The Data (Use and Access) Bill is massive, at over 260 pages. However, the reason for the bill’s size is that it is revising and amalgamating a diverse array of legislation.</p><p>“The Data Use and Access Bill weakens our rights and gives companies and organizations more powers to use automated decisions,” said legal and policy officer Mariano delli Santi, in a statement from the Open Rights Group. “This is of particular concern in areas of policing, welfare and immigration where life-changing decisions could be made without human review. The Government says that this Bill will generate billions for the economy, but at what cost to the privacy, security and dignity of the British public?”</p><p>One of the key elements is Part 1, where the Data (Use and Access) Bill makes clear distinctions between business data and customer data.</p><p>Business data is defined as anything regarding goods, services and digital content supplied or provided by the trader. Meanwhile, customer data is information relating to goods, services and digital content supplied or provided by the trader to the customer, or to another person at the customer’s request.</p><p>Much like the previous DPDI, the Data (Use and Access) Bill attempts to establish the regulatory foundations for digital identities. Chapter 27, subsection 1 concerns the reliability of digital verification services and the Secretary of State would be expected to prepare and publish, in collaboration with the information commissioner, the “DVS trust framework” document. This would set out further rules and regulations regarding the provision of digital verification services.</p><p>The DVS trust framework would replace the UK’s current <a href="https://ico.org.uk/for-organisations/guide-to-eidas/what-is-the-eidas-regulation/"><u>Electronic Identification, Authentication, and Trust Services (eIDAS)</u></a> regulation. The bill would also abolish the <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico"><u>Information Commissioner’s Office</u></a> and replace it with the Information Commission, with the functions transferred to the new organization.</p><p>Part 5 of the bill updates the UK data protection and privacy. In particular, clause 67 expands the use of data processing for statistical and research purposes.</p><p>The same section also revises Article 4 of UK GDPR, explaining that references to the processing of personal data for scientific research now includes publicly and privately funded research as well as research carried out as part of a commercial or non-commercial activity. However, the bill reinforces that consent still needs to be given for the processing of personal data for scientific research.</p><p>Article 22B of the bill will be added to the UK GDPR, which restricts automated decision-making processes. The Article declares that a significant decision, based entirely or partly on the processing of special categories of personal data (such as faith ethnicity, genetic data or biometric data), may not be taken based solely on automated processing, unless one of a series of conditions is met.</p><p>These conditions include where the data owner has explicitly agreed to automated decision making, necessary for completing a contract agreed between the data subject and the data controller, or when the data processing is required by law.</p><iframe allow="" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://www.itpro.com/business/policy-and-legislation/data-protection-and-digital-information-dpid-bill-small-businesses"></iframe><p>The bill also outlines the appropriate safeguards for data processing. It states that the safeguards have not been met if the processing “is likely to cause substantial damage or substantial distress to a data subject.” Furthermore, the requirement is only satisfied if the safeguards include technical and organizational measures for the purpose of ensuring respect for the principle of data minimization, such as pseudonymization.</p><p>Overall, the bill as it currently stands is a lengthy document, but not all of it will be relevant to all businesses. It is also still making its way through parliament, and therefore changes may well occur – digital verification is especially controversial. However, there is an expectation that the UK’s data protection policies will evolve and it is therefore incumbent that stakeholders engage with legislators to ensure that they are prepared and fully aware of what is to come.</p><p>“The more the UK diverges from the GDPR and dilutes people’s rights and protections, the more likely it is that the UK will be regarded by the European Commission as not being a safe pair of hands from a privacy perspective,” concludes Lee.</p><p>“Whilst there are changes proposed which will result in some rights being diluted (such as making automated decision making more flexible than under the GDPR and having a list of legitimate interests where an assessment is not required, such as in emergencies), my sense is that changes will not result in the UK being considered to having inadequate privacy laws.”</p><p>He adds that there are controls in the bill to keep human oversight for sensitive data, with some wiggle room open for what does and doesn’t constitute the minimum amount of human participation in a given task.</p><p>“A decision will have been taken by solely automated means if there has been no meaningful involvement. It is going to be interesting to see the debates about what is meant by no meaningful human involvement.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A decade-long ban on AI laws is a “terrible idea” for everyone but big tech, critics claim ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/a-decade-long-ban-on-ai-laws-is-a-terrible-idea-for-everyone-but-big-tech-critics-claim</link>
                                                                            <description>
                            <![CDATA[ A proposed decade-long ban on US states implementing AI laws is a "terrible idea" that highlights the scale of big tech lobbying, according to critics. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">PxDLDKSbvG6ZLnjRniN2QH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cV9dcvdDaqd5KB535Uii7T-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 15 May 2025 14:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/cV9dcvdDaqd5KB535Uii7T-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The United States Capitol Building on the National Mall in Washington, D.C.]]></media:description>                                                            <media:text><![CDATA[The United States Capitol Building on the National Mall in Washington, D.C.]]></media:text>
                                <media:title type="plain"><![CDATA[The United States Capitol Building on the National Mall in Washington, D.C.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cV9dcvdDaqd5KB535Uii7T-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A proposed decade-long ban on US states implementing AI laws is a "terrible idea" that highlights the scale of big tech lobbying, according to critics. </p><p>Earlier this week, a Republican-led committee <a href="https://www.theguardian.com/us-news/2025/may/14/republican-budget-bill-ai-laws"><u>proposed</u></a> a budget reconciliation <a href="https://docs.house.gov/meetings/IF/IF00/20250513/118261/HMKP-119-IF00-20250513-SD003.pdf"><u>bill</u></a> which at the last minute tucked within its pages a clause that would ban state-level AI regulation for the next ten years. If approved, only the US Congress could legislate on AI, not state governments. </p><p>The bill included a line that said "no State or political subdivision thereof may enforce any law or regulation regulating artificial intelligence models, artificial intelligence systems, or automated decision systems during the 10-year period of this Act."</p><p>That would preempt efforts by <a href="https://www.itpro.com/business/policy-and-legislation/california-lawmakers-approve-sweeping-ai-legislation-but-not-everyone-is-happy"><u>California</u></a> and other states looking to rein in AI using regulation. It remains to be seen if the section will be included in the final bill and whether that will be passed. </p><p>Following the move, the Electronic Frontier Foundation (EFF) published a <a href="https://www.eff.org/deeplinks/2025/05/stopping-states-passing-ai-laws-next-decade-terrible-idea" target="_blank"><u>statement</u></a> strongly opposing the proposals, calling it a "terrible idea". </p><p>The EFF noted that it would override existing state laws designed to prevent people from harms caused by AI and would prevent other states from writing similar legislation — a problem as Congress is much slower at taking on new technologies. </p><p>Similarly, the non-profit said this risks no regulation being implemented at all for ten years during a critical time in the development of the technology. </p><p>"Even if Congress does nothing on AI for the next ten years, this would still prevent states from stepping into the breach," the EFF said in a statement. "Given how different the AI industry looks now from how it looked just three years ago, it’s hard to even conceptualize how different it may look in ten years."</p><p>"Congress does not react quickly and, particularly when addressing harms from emerging technologies, has been far slower to act than states,” the EFF added.</p><h2 id="wider-criticism">Wider criticism</h2><p>An <a href="https://garymarcus.substack.com/p/8aa50f9a-5bde-47b4-b69b-0fdbf2f6670c"><u>open letter</u></a> signed by a series of state-level representatives — as well as frequent AI dissenter and New York University professor Gary Marcus — made a similar argument,  calling the attempt to preempt AI laws "deeply problematic". </p><p>"If enacted, the statute would preempt states from acting — even if AI systems cause measurable harm, such as through discriminatory lending, unsafe autonomous vehicles, or invasive workplace surveillance," the letter added. </p><p>Other critics made it clear the move was seen as benefiting big tech. Lee Hepner, senior legal counsel at the American Economic Liberties Project, described the move as a “sweeping and reckless attempt” to shield large corporations from accountability. </p><h2 id="why-ban-ai-laws">Why ban AI laws? </h2><p>A ten-year ban on AI laws may sound inherently extreme, but those in favor of it argue that AI regulation requires a national approach to minimize the costs and impact of regulation at a time when the US is battling China for dominance in this domain. </p><p>An article in <a href="https://www.lawfaremedia.org/article/1-000-ai-bills--time-for-congress-to-get-serious-about-preemption" target="_blank"><u><em>Lawfare</em></u></a><em> </em>argued that the current “patchwork of parochial regulatory policies” could severely undermine US innovation in the AI space at a critical juncture. </p><p>But the open letter noted that presented a "false choice" between too many laws and a single set of federal laws, given there was effectively zero of the latter. </p><p>"If Washington wants to pass a comprehensive privacy or AI law with teeth, more power to them, but we all know this is unlikely," the letter added. </p><p>At a state-level, there are dozens of examples of <a href="https://www.itpro.com/business/policy-and-legislation/why-ai-could-be-a-legal-nightmare-for-years-to-come">AI laws</a> — from Colorado's AI protection bill to California's attempts to rein in its own industry. </p><p>"It's specifically because of state momentum that Big Tech is trying to shut the states down," the letter added. </p><p>The EFF echoed that: "As the big technology companies have done (and continue to do) with privacy legislation, AI companies are currently going all out to slow or roll back legal protections in states." </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/business/policy-and-legislation/is-the-uk-falling-behind-the-eu-on-ai-regulation">Is the UK falling behind the EU on AI regulation?</a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/american-tech-workers-want-ai-regulation-but-they-might-have-to-wait-a-while">American tech workers want AI regulation – but they might have to wait a while</a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/why-ai-could-be-a-legal-nightmare-for-years-to-come">Why AI could be a legal nightmare for years to come</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple, Meta hit back at EU after landmark DMA fines ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/apple-meta-hit-back-at-eu-after-landmark-fines-under-digital-markets-act</link>
                                                                            <description>
                            <![CDATA[ The European Commission has issued its first penalties under the EU Digital Markets Act (DMA), fining Apple €500 million and Meta €200m. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oxT6CeYyAfhF3kKMfaGQZM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qnGSwbfzp9zTsFt2t49oUT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 24 Apr 2025 09:57:45 +0000</pubDate>                                                                                                                                <updated>Thu, 24 Apr 2025 10:02:27 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qnGSwbfzp9zTsFt2t49oUT-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[EU flags fly outside the union headquarters in Brussels, Belgium.]]></media:description>                                                            <media:text><![CDATA[EU flags fly outside the union headquarters in Brussels, Belgium.]]></media:text>
                                <media:title type="plain"><![CDATA[EU flags fly outside the union headquarters in Brussels, Belgium.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qnGSwbfzp9zTsFt2t49oUT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The European Commission has issued its first penalties under the <a href="https://www.itpro.com/business/policy-legislation/368435/what-is-the-eus-digital-markets-act-dma"><u>EU Digital Markets Act</u></a> (DMA), fining Apple €500 million and Meta €200m and requiring both to make changes to how they operate. </p><p>The DMA came into effect in 2023 and was created to regulate competition in the digital economy, in part by reining in abuse of power by larger platforms.  </p><p>Apple was found to be in breach of "anti-steering obligations" over restrictions that ban apps from informing customers of offers outside the App Store, which the EC said limited customer choice. </p><p>The Commission has ordered Apple to remove that restriction, and the tech giant plans to appeal the fine. </p><p>Meta, meanwhile, was fined for its introduction of a <a href="https://www.itpro.com/security/privacy/why-metas-pay-or-consent-ad-model-has-landed-it-in-hot-water-with-eu-regulators"><u>model that would force users to pay</u></a> for an ad-free service or consent to their data being used for advertising. </p><p>The Commission said that fell foul of an obligation under the DMA to give consumers the choice of a service that uses less of their personal data.</p><h2 id="apple-and-meta-respond">Apple and Meta respond </h2><p>Both companies made it clear they disagreed with the fines. In a <a href="https://x.com/jackeparrock/status/1914980345310556652"><u>statement</u></a>, Apple hit out at the Commission, suggesting the penalties show it is “unfairly targeting” the company. </p><p>The tech giant said the decisions are “bad for the privacy and security of our users, bad for products, and force us to give away our technology for free”.</p><p>"We have spent hundreds of thousands of engineering hours and made dozens of changes to comply with this law, none of which our users have asked for,” the statement added. </p><p>“Despite countless meetings, the Commission continues to move the goal posts every step of the way. We will appeal and continue engaging with the Commission in service of our European customers.”</p><p>Meta offered harsher criticism in its response, accusing the EC of treating US businesses unfairly. </p><p>"The European Commission is attempting to handicap successful American businesses while allowing Chinese and European companies to operate under different standards," Meta's Chief Global Affairs Officer, Joel Kaplan, said in a <a href="https://about.fb.com/news/2025/04/metas-statement-in-response-to-the-european-commissions-decision-on-the-digital-markets-act/" target="_blank"><u>statement</u></a>. </p><p>"This isn’t just about a fine; the Commission forcing us to change our business model effectively imposes a multi-billion-dollar tariff on Meta while requiring us to offer an inferior service," he added. "And by unfairly restricting personalized advertising the European Commission is also hurting European businesses and economies."</p><h2 id="a-strong-and-clear-message-from-the-eu">A ‘strong and clear’ message from the EU</h2><p>Despite the complaints, Teresa Ribera, Executive Vice-President for a Clean, Just and Competitive Transition, said in a <a href="https://ec.europa.eu/commission/presscorner/detail/en/mex_25_1088" target="_blank"><u>statement</u></a> the fines send a "strong and clear message" to digital companies, adding that the legislation is a crucial tool to ensuring fair markets. </p><p>"Apple and Meta have fallen short of compliance with the DMA by implementing measures that reinforce the dependence of business users and consumers on their platforms," Ribera said. "As a result, we have taken firm but balanced enforcement action against both companies, based on clear and predictable rules."</p><p>"All companies operating in the EU must follow our laws and respect European values,” she added.</p><p>That reference to <a href="https://www.itpro.com/business/policy-and-legislation/the-eus-long-arm-regulatory-approach-could-create-frosty-us-environment-for-european-tech-firms"><u>European values reflects geopolitical turmoil</u></a> between the US and the rest of the world, according to Joe Jones, director of research and insights at IAPP. </p><p>"The fines land at a time of heightened scrutiny by the current US Administration on the application of EU laws to US companies," Jones said. </p><p>"The EU Digital Markets Act was even name-checked in an Executive Order issued by President Trump last February as facing scrutiny as part of the Administration’s work to “defend American companies and innovators from overseas extortion,” he added.</p><p>"Open questions include not only how will addressed companies respond to EU regulatory enforcement but how will overseas governments, including and especially the US, respond.  The U.S. Administration has declared it will consider responsive actions like tariffs to combat certain foreign government policies levied against US companies."</p><h2 id="beyond-the-fines">Beyond the fines</h2><p>As Meta noted, there's more to the decision than fines. Indeed, despite the seemingly large figures, the fines were much smaller than the EU could have levied, as high as <a href="https://www.itpro.com/business/policy-and-legislation/big-tech-firms-face-10-turnover-fines-under-new-competition-law"><u>10% of their global annual turnover</u></a>. Last year, Meta's earnings topped $165 billion and Apple's was $391 billion.  </p><p>In a statement, the EC said that developers using Apple's App Store should be able to tell customers about alternative offers outside that store, such as discounted subscription offers. The EC added that Apple had failed to give a reason why such restrictions are "necessary and proportionate." </p><p>Beyond the fine, the EC has ordered Apple to remove such restrictions and not introduce similar restrictions in the future. </p><p>The EC also <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_25_1086"><u>closed an investigation</u></a> into Apple's tactic of not allowing its own pre-installed apps to be removed from its devices, such as its Safari web browser. </p><p>Following a "constructive dialogue", Apple made it easier to select a new default browser on iPhones, uninstall several Apple pre-installed apps, and change default settings for other tools such as keyboards and translation.</p><p>Alongside those two investigations, the EC also issued preliminary findings on Apple banning third-party app stores and requiring users to download apps via the official App Store. </p><p>The EC said that its preliminary view is that Apple isn't complying with the DMA by disincentivising developers from offering apps elsewhere via a new fee, the Core Technology fee, while also introducing strict eligibility requirements. </p><p>Apple can now respond to those findings ahead of a final ruling. </p><p>For Meta, it has been fined under DMA rules that mean "gatekeepers" must get user consent for combining personal data between services, and still offer an equivalent alternative service for any who refuse to consent. </p><p>This decision refers to Meta's "consent or pay" advertising model that was introduced in November 2023, which gave Facebook and Instagram users the option of consenting to their data being combined for personalized advertising or paying a subscription to opt out and receive an ad-free service. </p><p>The EC said that model didn't offer enough of an alternative service for those who opted out. A year later, Meta offered a new version that included a tier that used less personal data to display ads. </p><p>This particular fine applies only to the period up to November 2024 when those changes came into effect, as the regulator is still considering the changes. </p><p>Alongside the advertising data ruling, the EC also announced that Facebook Marketplace was small enough that it should no longer be designated under the DMA.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/business/policy-and-legislation/how-the-eu-ai-act-compares-to-other-international-regulatory-approaches">How the EU AI Act compares to other international regulatory approaches</a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/dora-and-why-resilience-once-again-matters-to-the-board">DORA and why resilience (once again) matters to the board</a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/the-fractured-regulatory-landscape-tech-companies-face-in-2025">The fractured regulatory landscape tech companies face in 2025</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google breakup plans would ‘hurt America’s consumers, economy, and technological leadership’, senior exec claims ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/google-breakup-doj-plans-us-economy</link>
                                                                            <description>
                            <![CDATA[ Google has struck back against US regulators, claiming that plans to dismantle the company would "hurt the economy". ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fk67PBNZ5Fzfh7kqZZcTmL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/X7EasjNoUzp6PoYuY5kdab-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Apr 2025 07:58:41 +0000</pubDate>                                                                                                                                <updated>Wed, 23 Apr 2025 08:15:19 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/X7EasjNoUzp6PoYuY5kdab-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Alphabet and Google CEO Sundar Pichai meets with Polish Prime Minister Donald Tusk at Google for Startups in Warsaw, Poland, on February 13, 2025. ]]></media:description>                                                            <media:text><![CDATA[Alphabet and Google CEO Sundar Pichai meets with Polish Prime Minister Donald Tusk at Google for Startups in Warsaw, Poland, on February 13, 2025. ]]></media:text>
                                <media:title type="plain"><![CDATA[Alphabet and Google CEO Sundar Pichai meets with Polish Prime Minister Donald Tusk at Google for Startups in Warsaw, Poland, on February 13, 2025. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/X7EasjNoUzp6PoYuY5kdab-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google has struck back against US regulators, claiming that plans to dismantle the company would "hurt the economy". </p><p>Last year, a court case brought by the US Department of Justice (DOJ) found Google had a monopoly in search. A trial that began this week seeks to decide the correct remedies, which could include <a href="https://www.itpro.com/business/policy-and-legislation/doj-demands-google-sells-chrome-and-potentially-android"><u>breaking up aspects of Google, selling Chrome or spinning out Android</u></a>. </p><p>The DOJ <a href="https://qz.com/google-doj-chrome-antitrust-case-search-engine-monopoly-1851777192" target="_blank"><u>said in a filing</u></a> that Google forces Americans to submit to "unbridled demands and shifting, ideological preferences" just to access a decent search tool. </p><p>Justice Department lawyer David Dahlquist <a href="https://qz.com/google-doj-chrome-antitrust-case-search-engine-monopoly-1851777192" target="_blank"><u>said in court</u></a> Monday: "This is the time for the court to tell Google and all other monopolists who are out there listening — and they are listening — that there are consequences when you break the antitrust laws."</p><p>Last week, in a separate case, a US judge <a href="https://www.reuters.com/technology/us-judge-finds-google-holds-illegal-online-ad-tech-monopolies-2025-04-17/" target="_blank"><u>found</u></a> that Google has an illegal monopoly in advertising technology, and it faces a class-action style suit in the <a href="https://www.itpro.com/business/policy-and-legislation/google-faces-first-of-its-kind-class-action-for-search-ads-overcharging-in-uk"><u>UK on the same subject</u></a>. </p><h2 id="google-breakup-plans-would-harm-the-economy">Google breakup plans would harm the economy</h2><p>While Google will get a chance to have its say in court, the company shared a <a href="https://blog.google/outreach-initiatives/public-policy/doj-search-remedies-apr-2025/"><u>blog post over the weekend</u></a> ahead of the beginning of the trial, arguing its case to the public, and reiterating that it disagreed with the court's decision last year. </p><p>The post pointed to its own <a href="https://blog.google/outreach-initiatives/public-policy/google-remedies-proposal-dec-2024/" target="_blank"><u>proposal for remedies</u></a> that would allow multiple search agreements, de-link Google's apps in Android, and stressed that Google would appeal the ruling once the remedy was decided. </p><p>Penned by Lee-Anne Mulholland, vice president of regulatory affairs, the post said the case was "backwards looking" given the current level of intense competition in online search sparked by the rise of <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a>, pointing to <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369965/what-is-chatgpt-and-what-does-it-mean-for-businesses">ChatGPT </a>and DeepSeek. </p><p>"At trial we will show how DOJ’s unprecedented proposals go miles beyond the Court’s decision, and would hurt America’s consumers, economy, and technological leadership," she wrote. </p><p>The post further argued the DOJ proposal would make it harder to access online services. </p><p>"People use Google because they want to, not because they have to," Mulholland wrote. "DOJ's proposal would force browsers and phones to default to search services like Microsoft’s Bing, making it harder for you to access Google."</p><p>She added that the proposal would prevent competition in search, raise prices and slow innovation, adding that it would damage Mozilla Firefox which relies on Google payments from search distribution. </p><p>Similarly, the move would force Google to share sensitive and private search data with "companies you may never have heard of". </p><p>On the topic of Android potentially being spun out, Google argued it would impact security, raise prices and hurt businesses. </p><p>"DOJ’s proposal to split off Chrome and Android — which we built at great cost over many years and make available for free — would break those platforms, hurt businesses built on them, and undermine security," she wrote. </p><h2 id="ai-a-new-front-for-case">AI a new front for case? </h2><p>Google argued that the DOJ proposal would "hamstring how we develop AI" by requiring a government committee to regulate the design of its related products. </p><p>Mulholland suggested this would “hold back American innovation at a critical juncture” as the firm and its counterparts contend with rising competition from overseas developers. </p><p>At the trial, Dahlquist argued that the court's remedy should actively consider AI, saying Perplexity AI and OpenAI will both testify about the impact of Google's industry dominance on their own businesses. </p><p>"This court's remedy should be forward-looking and not ignore what is on the horizon," Dahlquist <a href="https://www.msn.com/en-gb/money/technology/google-could-use-ai-to-extend-search-monopoly-doj-says-as-trial-begins/ar-AA1DlbRm" target="_blank">said</a>.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/business/business-strategy/google-layoffs-continue-with-hundreds-cut-from-chrome-android-and-pixel-teams">Google layoffs continue with "hundreds" cut from Chrome, Android, and Pixel teams</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/demis-hassabis-google-deepmind-ai">Google DeepMind’s Demis Hassabis says AI isn’t a ‘silver bullet’ </a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/google-cloud-uk-sovereign-data-agentic-ai">Google Cloud announces UK data residency for agentic AI services</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google faces 'first of its kind' class action for search ads overcharging in UK ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/google-faces-first-of-its-kind-class-action-for-search-ads-overcharging-in-uk</link>
                                                                            <description>
                            <![CDATA[ Google faces a "first of its kind" £5 billion lawsuit in the UK over accusations it has a monopoly in digital advertising that allows it to overcharge customers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">atwSsEAa9DNe3nvmyTM9Ym</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MsYzHUkgkcsbSN9HtdM9NN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 17 Apr 2025 13:50:56 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MsYzHUkgkcsbSN9HtdM9NN-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google logo and branding pictured on front of an office entrance at King&#039;s Cross, London, UK. ]]></media:description>                                                            <media:text><![CDATA[Google logo and branding pictured on front of an office entrance at King&#039;s Cross, London, UK. ]]></media:text>
                                <media:title type="plain"><![CDATA[Google logo and branding pictured on front of an office entrance at King&#039;s Cross, London, UK. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MsYzHUkgkcsbSN9HtdM9NN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google faces a "first of its kind" £5 billion lawsuit in the UK over accusations it has a monopoly in digital advertising that allows it to overcharge customers. </p><p>The suit was brought via law firm Geradin Partners but led by Or Brook, an associate professor of competition law at the University of Leeds, and filed at the UK Competition Appeal Tribunal on behalf of all affected UK businesses. </p><p>Google is accused of forcing mobile phone makers and network operators to preinstall Google's Search and Chrome on Android devices, as well as paying Apple billions of pounds to make Google Search the default on its Safari browser. </p><p>Those tactics, the suit alleges, solidified Google's default position and allowed the company to drive up prices for search advertising, costing its customers. </p><p>"Today, UK businesses and organizations, big or small, have almost no choice but to use Google ads to advertise their products and services," said Brook in a <a href="https://www.geradinpartners.com/google-faces-multi-billion-pound-damages-action-on-behalf-of-uk-search-advertisers/" target="_blank"><u>statement</u></a>. </p><p>"Regulators around the world have described Google as a monopoly and securing a spot on Google’s top pages is essential for visibility." </p><p>Last year in the US, a judge <a href="https://www.itpro.com/software/google/google-has-a-monopoly-over-the-online-search-market-us-court-rules"><u>ruled that Google had a monopoly in search</u></a>, with the Department of Justice <a href="https://www.itpro.com/business/policy-and-legislation/doj-mulls-potential-google-services-breakup-in-monopoly-lawsuit-what-happens-next"><u>considering breaking up the wider company</u></a>. In 2018, Google was <a href="https://www.itpro.com/google-android/31531/google-launches-appeal-against-record-38bn-penalty-over-android-abuse"><u>fined €4.3 billion for abusing</u></a> the dominance of the Android OS by requiring mobile makers to install Chrome and Search. </p><p>Similarly, earlier this year the UK's Competition and Market Authority <a href="https://www.gov.uk/government/news/cma-to-investigate-googles-search-services"><u>launched an investigation into Google's search market share</u></a>, noting that it holds 90% of all search queries. </p><p>In a <a href="https://www.linkedin.com/posts/or-brook-6b8632174_google-searchads-competitionlaw-activity-7318202636170637313-29JX?utm_source=share&utm_medium=member_desktop&rcm=ACoAAAOQPAgBToOxeUq0I2lEmnXtZsHAFVyUi5Y" target="_blank"><u>LinkedIn post</u></a>, Brooks said the lawsuit was unique because it sought to represent businesses, rather than individuals. </p><p>"We have now filed the first collective action of its kind in the UK that seeks redress for the direct harm caused to businesses (rather than consumers) who have been forced to pay sub-competitive prices for advertising space on Google pages," she wrote. </p><h2 id="google-is-contesting-the-claims">Google is contesting the claims</h2><p>A Google spokesperson dismissed the case, said the company would fight the allegations, and that customers weren't forced to use Google advertising.</p><p>"This is yet another speculative and opportunistic case and we will argue against it vigorously," the Google spokesperson told <a href="https://www.theguardian.com/technology/2025/apr/16/google-sued-for-5bn-in-uk-over-allegations-of-shutting-out-rivals" target="_blank"><u><em>The Guardian</em></u></a>. "Consumers and advertisers use Google because it is helpful, not because there are no alternatives."</p><p><em>ITPro </em>approached Google for comment, but had received no response at time of publication.</p><h2 id="suit-claims-google-is-driving-up-prices">Suit claims Google is driving up prices</h2><p>Brook said Google made use of its monopoly to raise prices due to lack of competition, noting that Google made £14 billion from search advertising in the UK alone last year. </p><p>"Google has been leveraging its dominance in the general search and search advertising market to overcharge advertisers," Brook added. "This class action is about holding Google accountable for its unlawful practices and seeking compensation on behalf of UK advertisers who have been overcharged.</p><p>Beyond ensuring Search was the default on mobile devices, the lawsuit alleges that Google's Search Engine Management Platform had better access to advertising than rivals. </p><p>The action seeks compensation for overcharges from 2011 to 2015, which is estimated to be in the region of £5 billion. Any payouts would depend on the settlement if the case is won, and calculated based on how much a company spent during the time period. The case is expected to take up to three years. </p><p>Companies that advertised via Google search in the indicated time frame will be automatically included in the class action, though they can choose to opt-out.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/software/google/google-settles-dollar5-billion-privacy-lawsuit-ahead-of-cookie-phase-out">Google settles $5 billion privacy lawsuit ahead of cookie phase-out</a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/doj-mulls-potential-google-services-breakup-in-monopoly-lawsuit-what-happens-next">DoJ mulls potential Google services breakup in monopoly lawsuit</a></li><li><a href="https://www.itpro.com/security/privacy/google-forced-to-delete-billions-of-incognito-browsing-records-after-privacy-controversy">Google forced to delete billions of incognito browsing records after privacy controversy</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK firms are pulling ahead of EU competitors in the AI race – here's why ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/ai-adoption-rates-uk-europe</link>
                                                                            <description>
                            <![CDATA[ UK organizations are pulling ahead of EU competitors in implementing AI, new research suggests, and a key factor lies in their confidence about regulatory compliance. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rD2zSLyZaovJri8F5qqh8Q</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JvFEHz3W8DCoZC4MakWaVo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Mar 2025 00:05:00 +0000</pubDate>                                                                                                                                <updated>Fri, 14 Mar 2025 16:47:59 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JvFEHz3W8DCoZC4MakWaVo-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[UK map concept art showing digitized UK landmass outline in blue.]]></media:description>                                                            <media:text><![CDATA[UK map concept art showing digitized UK landmass outline in blue.]]></media:text>
                                <media:title type="plain"><![CDATA[UK map concept art showing digitized UK landmass outline in blue.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JvFEHz3W8DCoZC4MakWaVo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>UK organizations are pulling ahead of EU competitors in implementing <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a>, new research suggests, and a key factor lies in their confidence about regulatory compliance.</p><p>Almost a quarter of UK CEOs told AI firm Daikatu they have a formal <a href="https://www.itpro.com/technology/artificial-intelligence/splunk-will-pay-a-key-role-in-ciscos-ai-plans-claims-former-ceo">roadmap for AI</a> implementation over the next year, double the global average and nearly five times as many as in Germany.</p><p>And while four-in-ten CEOs in France and a third in Germany said they'd cancelled an AI project due to regulatory uncertainty, only one-in-five UK CEOs said the same.  </p><p>Florian Douetteau, CEO and co-founder of Dataiku, said the contrasting regulatory landscapes on both sides of the English Channel are enabling British firms to capitalize on the AI ‘boom’. </p><p>"The market research in our report suggests reduced regulatory uncertainty is giving UK businesses the clarity to act — accelerating innovation and adoption, even as AI evolves at a relentless pace," Douetteau said. </p><p>"Working with our enterprise customers, we have seen first-hand that when CEOs have confidence in compliance and control over governance, they can move faster, scale smarter, and fully capitalize on AI’s potential." </p><p>Hesitation over AI regulation is a global issue, the study noted, with eight-in-ten CEOs concerned that the <a href="https://www.itpro.com/business/policy-and-legislation/how-the-eu-ai-act-compares-to-other-international-regulatory-approaches">EU AI Act</a> could slow adoption in their organizations. </p><p>The Act brings with it a common regulatory and legal framework for AI, and is aimed at ensuring AI development and deployment in the EU is carried out responsibly.</p><p>However, there's been plenty of room for confusion and uncertainty, with the latest draft of the General-Purpose <a href="https://www.itpro.com/technology/artificial-intelligence/uk-releases-draft-code-of-practice-for-ai-security">AI Code of Practice</a> published only recently, and potentially set for more changes before it comes into force in May.</p><p>"The EU AI Act has raised more questions than it answered, and in the process has seen businesses within its jurisdiction become increasingly cautious with their AI programmes," said Jacob Beswick, senior director of <a href="https://www.itpro.com/business/digital-transformation/why-ai-governance-is-a-business-imperative-for-scaling-enterprise-ai">AI governance</a> at Dataiku and former UK assistant director for AI adoption and regulation.</p><p>"Heavier regulations in the EU mean there are more restrictions on what you can and cannot operationalize and put on the market than in the UK, in turn arguably making the UK an attractive market for AI innovators."</p><h2 id="firms-still-conscious-of-ai-governance">Firms still conscious of AI governance</h2><p>CEOs acknowledged that while AI is a critical competitive differentiator, their organizations often lack the governance, planning, and oversight needed to carry projects out successfully.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="wCjD6wBijnsfxorQRW3s6G" name="IBM generative AI assistants_ The complete 2024 buyers guide.jpg" caption="" alt="IBM generative AI assistants: The complete 2024 buyers guide" src="https://cdn.mos.cms.futurecdn.net/wCjD6wBijnsfxorQRW3s6G.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/ibm-generative-ai-assistants-the-complete-2024-buyers-guide"><em>Discover the benefits of IBM AI assistants</em></a></p></div></div><p>While eight-in-ten CEOs globally said they were confident in their company’s AI governance framework, or their ability to set rules around data access and privacy, only a third of these described themselves as extremely confident.</p><p>Overall, more than a third of CEOs said their AI projects had been delayed due to regulatory uncertainty, with 32% having canceled or abandoned them altogether.</p><p>However, Beswick noted that while regulatory considerations may slow down AI implementation, those without stricter guidelines must ensure they are creating AI products “with risk awareness in mind, as opposed to simply doing so because they can”. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/business/policy-and-legislation/regulatory-uncertainty-is-holding-back-ai-adoption-heres-what-the-industry-needs-going-forward">Regulatory uncertainty is holding back AI adoption</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/data-strategy-ai-adoption-failures">A quarter of firms still don't have a formal AI strategy</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/only-a-handful-of-generative-ai-projects-make-it-into-production-heres-why">Only a handful of generative AI projects make it into production</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The CMA just dropped its probe into the Microsoft–OpenAI deal ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/the-cma-just-dropped-its-probe-into-the-microsoft-openai-deal</link>
                                                                            <description>
                            <![CDATA[ The CMA has dropped its probe into the partnership between Microsoft and OpenAI, saying the deal doesn't give Microsoft a controlling interest over the AI firm. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cUrPSR5ewvn35S9tijwHSX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9944EGjar5x4f7f2oC6yL6-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 Mar 2025 13:27:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9944EGjar5x4f7f2oC6yL6-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[OpenAI logo and branding pictured at Mobile World Congress 2024 in Barcelona, Spain.]]></media:description>                                                            <media:text><![CDATA[OpenAI logo and branding pictured at Mobile World Congress 2024 in Barcelona, Spain.]]></media:text>
                                <media:title type="plain"><![CDATA[OpenAI logo and branding pictured at Mobile World Congress 2024 in Barcelona, Spain.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9944EGjar5x4f7f2oC6yL6-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK's Competition and Markets Authority (CMA) has dropped its probe into the partnership between Microsoft and <a href="https://www.itpro.com/technology/artificial-intelligence/openais-day-in-the-sun-is-over">OpenAI</a>, saying the deal doesn't give Microsoft a controlling interest over the AI firm.</p><p>The competition regulator said that despite Microsoft's heavy investment in OpenAI and its exclusive deals for some products, the tech giant has only a 'material influence' over OpenAI, meaning that the tie-up doesn't meet the threshold for a full enquiry.</p><p>"Looking at the evidence in the round (including the recent changes), we have found that there has not been a change of control by Microsoft from material influence to de facto control over OpenAI," said Joel Bamford, executive director of the CMA, in a <a href="https://www.linkedin.com/pulse/what-key-takeaways-from-our-review-microsoftopenai-joel-bamford-auzre/" target="_blank"><u>LinkedIn post</u></a>.</p><p>"Because this change of control has not happened, the partnership in its current form does not qualify for review under the UK’s merger control regime." </p><p>However, he warned <a href="https://www.gov.uk/cma-cases/microsoft-slash-openai-partnership-merger-inquiry" target="_blank"><u>the decision </u></a>is just a question of jurisdiction, and should not be read as the partnership being given a clean bill of health on potential competition concerns.</p><h2 id="what-concerned-regulators">What concerned regulators?</h2><p>The investigation examined a deal signed between the two companies in 2019, which saw <a href="https://www.itpro.com/business/business-strategy/369850/microsofts-10b-openai-investment-could-end-ai-competition">Microsoft invest an initial $10 billion in OpenAI</a>, with another $3 billion following. </p><p>But it was four years later that the <a href="https://www.itpro.com/technology/artificial-intelligence/openai-drama-prompts-cma-review-into-microsoft-relationship">CMA opened its investigation</a> after Sam Altman was first sacked and then reinstated as OpenAI’s chief executive.</p><p>"In view of Microsoft's potentially important role in securing Sam Altman's re-appointment, the CMA believed there was a reasonable chance that an investigation would reveal that Microsoft had increased its control over OpenAI's commercial policy," the CMA said at the time.</p><p>This new decision is based partly on the shifts in the relationship between the two firms that have taken place over the last few years. In January, for example, Microsoft announced a change to its contractual rights in relation to supply of compute capacity, which reduced OpenAI’s reliance on Microsoft. </p><p>The CMA has faced criticism for the time it's taken to reach its conclusions - probes into other partnerships in the AI sector have taken just a matter of months. </p><p>"We are not blind to the length of time that this investigation has taken – particularly given the reforms we have launched recently which will considerably speed up and streamline the UK mergers process. We know pace matters to business confidence and investment," said Bamford. </p><p>However, Bamford added that simply hasn't been possible in this case.</p><p>"A combination of the degree of complexity, the changing nature of the arrangements and how they operate in practice, and the mutual desire for open dialogue between the CMA and the companies to ensure we understood these developments over time, has led to an exceptionally extended period of review," he said. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/business/policy-and-legislation/satya-nadella-says-microsoft-and-openai-have-a-pro-competition-partnership-regulators-arent-so-sure">Satya Nadella says Microsoft and OpenAI have a “pro-competition partnership"</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/openais-regulatory-probes-explained">OpenAI and Microsoft's regulatory probes explained</a></li><li><a href="https://www.itpro.com/software/microsoft/openai-continues-to-be-our-partner-on-frontier-models-microsoft-is-open-to-using-a-range-of-ai-models-in-365-copilot-but-openai-remains-its-go-to-choice">Microsoft is open to using a range of AI models in 365 Copilot, but OpenAI remains its go-to choice</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The impact of tariffs on tech ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/the-impact-of-tariffs-on-tech</link>
                                                                            <description>
                            <![CDATA[ Uncertainty over the impact of tariffs on tech firms has thrown US domestic manufacturing under scrutiny and reignited supply chain concern ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ojhqDxLURebGdApsbASksM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SzUocnVKJnZtgoRTpHcDLg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Mar 2025 10:33:47 +0000</pubDate>                                                                                                                                <updated>Mon, 10 Mar 2025 12:51:34 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ john@jloeppky.com (John Loeppky) ]]></author>                    <dc:creator><![CDATA[ John Loeppky ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GJCxqX7ryKSC5XjEDLnEtU.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;John Loeppky is a British-Canadian disabled freelance writer currently based on Treaty 6 territory in Saskatoon, Saskatchewan, Canada where he lives with his wife and three dogs.&lt;/p&gt;&lt;p&gt;In addition to his work for ITPro, he regularly works with outlets such as &lt;em&gt;CBC&lt;/em&gt;, &lt;em&gt;Healthline&lt;/em&gt;, &lt;em&gt;VeryWell&lt;/em&gt;, &lt;em&gt;Defector&lt;/em&gt;, and a host of others. John began his journalism career at the University of Regina at their student newspaper, The Carillon. He started as a sports writer, then sports editor, before serving as EIC until 2020. &lt;/p&gt;&lt;p&gt;John holds a BA and an MFA from the University of Regina. His graduate work focused on disability, identity, and solo performance in theatre. Prior to shifting to being a full-time freelancer, John worked for Listen to Dis&#039; Community Arts Organization, Saskatchewan&#039;s only disability-led disability arts organization. &lt;/p&gt;&lt;p&gt;His focus as a generalist is to cover things with societal and cultural impact, particularly when it comes to inclusion in its various forms. As a result, he&#039;s written for FiveThirtyEight about Apple Watches, covered the Paris Paralympics for CBC, and written for Defector about a scandal in American wheelchair basketball. He also serves as a member of the National Center on Disability and Journalism&#039;s advisory board. John&#039;s goal in life is to have an entertaining obituary to read. &lt;/p&gt;&lt;p&gt;You can find more of his work at Jloeppky.com/portfolio and you can contact him via email at John@Jloeppky.com.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/SzUocnVKJnZtgoRTpHcDLg-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A container emblazoned with the US flag being lowered onto an orange container flanked by green and black containers, representing US tariffs on imports and the US supply chain.]]></media:description>                                                            <media:text><![CDATA[A container emblazoned with the US flag being lowered onto an orange container flanked by green and black containers, representing US tariffs on imports and the US supply chain.]]></media:text>
                                <media:title type="plain"><![CDATA[A container emblazoned with the US flag being lowered onto an orange container flanked by green and black containers, representing US tariffs on imports and the US supply chain.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SzUocnVKJnZtgoRTpHcDLg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The uncertainty around the impact of tariffs is stark right now, with those in the tech sector far from alone in wondering how they might be affected by sweeping taxes on imports. </p><p>First on the campaign trail and now in office, the Trump administration has repeatedly sung the praises of tariffs and, at time of publication, is in the process of levying 25% tariffs on imports from Canada and Mexico – the US’ largest trading partners. China is also facing a combined 20% rate, with President Trump having promised 25% tariffs on Europe in the immediate future. </p><p>While no one can predict the exact effects of these tariffs, the broad implications are a significant topic of discussion for the IT and broader tech industry. Steve Hall, chief AI officer at consultancy company ISG and president of its EMEA operations, has been producing the company’s index for a decade. <a href="https://isg-one.com/research/isg-index"><u>Its Q4 2024</u></a> analysis projected that US tariffs would play a marked role in the sector’s overall growth rate.</p><p>“First of all, I think there's a general belief that the tariffs are going to increase inflation. Fed's [US Federal Reserve] going to fight inflation, so it' likely means that they're not going to be able to have the room that they need to do to lower the interest rates,” Hall tells <em>ITPro</em>, “So when that happens, as we've seen over the last couple years, large enterprises really pull back on discretionary spending.”</p><p>Hall says that the discretionary spending likely to be axed by companies, should the pain of tariffs be severe, could include budgets for digital transformation projects, with companies opting instead to focus on cost optimization opportunities. That doesn’t mean he expects all areas of the industry to contract, with the growth of the behemoth <a href="https://www.itpro.com/software/saas-dependency-is-causing-serious-problems-for-tech-leaders">software as a service (SaaS)</a> and <a href="https://www.itpro.com/technology/artificial-intelligence/hyperscaler-ai-spending-is-getting-out-of-control-and-microsoft-says-it-could-take-15-years-for-it-to-make-good-on-investments">hyperscale spending</a> expected to continue, in large part due to the <a href="https://www.itpro.com/business/business-strategy/microsoft-promises-more-ai-spending-despite-cloud-cost-stumble">continued expansion of AI products and services</a>. Companies that are focused on digital services are less likely to feel the full weight of tariffs as digital trade is, traditionally, not subject to the same types of customs measures. </p><p>Martin Balaam, the CEO and founder of SaaS product information and digital asset management firm Pimberly, says that though the vast majority of business expenses for companies like his are tied up in intellectual property and the human power to produce it, there are still aspects of the market place where IT companies can play a role in the mitigation of tariffs. He finds this particularly true when it comes to helping clients with <a href="https://www.itpro.com/business/business-strategy/supply-chain-oversight-critical-for-businesses">supply chain oversight</a> in all areas of the world, as Pimberly works to expand its market in the US.</p><p>“There are limited things that we can do, other than enable our customers to have more visibility in terms of where their products come from and which countries potentially are at  a higher risk of some of these things actually happening to them.”</p><p>Balaam says that this keen eye on process has been ongoing since the first wave of the COVID-19 pandemic, with companies contemplating near shoring production to mitigate the <a href="https://www.itpro.com/business/business-strategy/what-the-supply-chain-crisis-taught-us-and-how-to-prepare-for-the-next-one"><u>supply chain crisis</u></a>. But there is still concern across sectors that, despite the expressed hopes of the Trump administration, there just isn’t the ability to scale US production capabilities at the speed needed to entirely shield the domestic economy. </p><p>Balaam does see opportunities for innovation, particularly when it comes to a large disruption, like a tariff’s tendency to dislodge complacency amongst key company decision makers. One example given was the additional cost of computing power that could come from broad tariffs. </p><p>Still, Hall doesn’t see US manufacturing accelerating at the speed that tariff evangelists hope it will. This is of particular concern for those interested in tech innovation, with much of the materials required being way off shore. For example semiconductors, used in a vast number of modern devices, are largely imported from Taiwan and Taiwan Semiconductor Manufacturing Company (TSMC) produces 90% of the most advanced chips in the world, per <a href="https://www.economist.com/special-report/2023/03/06/taiwans-dominance-of-the-chip-industry-makes-it-more-important" target="_blank"><u><em>The Economist</em></u></a>.</p><p>In a <a href="https://rollcall.com/factbase/trump/transcript/donald-trump-speech-house-gop-conference-miami-january-27-2025/#:~:text=They%20needed%20an,giving%20them%20money." target="_blank"><u>speech to House Republicans</u></a> on January 27, President Trump threatened to levy tariffs as high as 100% against Taiwan to spur further investment in US chip fabrication. Hall doubts whether the US can compete with Taiwan in the immediate future.</p><p>“It’s going to take years before the <a href="https://www.itpro.com/business/policy-and-legislation/us-carries-out-semiconductor-review-in-light-of-security-concerns"><u>US has the chip manufacturing capability</u></a> that comes out of Taiwan right now, and most of that is co[-produced].” Hall says, adding that US firms including Apple and Intel have a supply chain heavily integrated with Taiwan, which can make it hard to pinpoint the exact impact and severity of tariffs.</p><p><a href="https://www.itpro.com/business/business-strategy/everything-you-need-to-know-about-nvidia"><u>Nvidia</u></a>, which has <a href="https://www.itpro.com/hardware/how-nvidia-took-the-world-by-storm"><u>become one of the most valuable companies</u></a> in the world off the back of record demand for its <a href="https://www.itpro.com/hardware/30399/what-is-a-gpu"><u>graphics processing units (GPUs)</u></a> for <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai"><u>generative AI</u></a> training and inferencing, is highly reliant on manufacturing plants in Taiwan. On 3 March, its stock fell 9% against a backdrop of confirmed Mexico-Canada tariffs by the Trump administration.</p><iframe allow="" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/7e19ae9f-f4ad-41f9-91c0-269fc7b59719/"></iframe><p>Despite the general gloom over current prospects of American economic policy, Paul F. Magel, the president of the application solutions group at Computer Generated Solutions, suggests that the current administration is “saber-rattling” and that its motives and their eventual downstream consequences still aren’t entirely clear. </p><p>“From a Trump standpoint, he's utilizing, certainly, the size of the US market and the threat of tariffs to drive other initiatives that he's trying to accomplish,” Magel tells <em>ITPro</em>. Some early responses to tariffs may already be visible. Amid reports that the tariffs will be going ahead, <a href="https://pr.tsmc.com/english/news/3210"><u>TSMC announced a $100 billion investment</u></a> in new US fabricating plants.</p><p>Magel counts himself amongst the portion of the sector who see technology as part of an effective tariff response as the US tries to bring more manufacturing home.</p><p>“Depending on the industry and the marketplace, we don't necessarily have the labor force anymore to bring all of the manufacturing back that we had 100 years ago or 50 years ago,” he tells <em>ITPro</em>. “So, some of that has to be balanced out. That's where things like… <a href="https://www.itpro.com/strategy/28181/what-is-ai"><u>AI</u></a> robotics automation will take place. There's this labour component in manufacturing that you've got to make sure is not going to be a constraint if you start bringing it back to the United States of America.”</p><p>The current landscape is incredibly hard to transparently assess. What will be key, according to those in the broader IT and tech industry, is the ability of tech companies to use technology to further streamline their processes and for their providers’ ability to respond to current market needs. The world’s supply chains have become more and more integrated over many decades – some trace Canada’s integral connection to the US market as far back as the great depression, for example – and that detangling does not, and cannot, happen overnight. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New Ofcom guidelines show it’s getting tougher on big tech ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/ofcom-online-safety-act-guidance</link>
                                                                            <description>
                            <![CDATA[ New Ofcom guidance outlining its plans for the Online Safety Act show the regulator is toughening up on big tech. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">FpCNftHzY6BKUsjbRAM4ej</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/N8h7uACYqQfmXe3eapwCRD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 28 Feb 2025 10:21:07 +0000</pubDate>                                                                                                                                <updated>Fri, 28 Feb 2025 14:54:13 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/N8h7uACYqQfmXe3eapwCRD-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Silhouetted hand typing on an illuminated laptop keyboard.]]></media:description>                                                            <media:text><![CDATA[Silhouetted hand typing on an illuminated laptop keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[Silhouetted hand typing on an illuminated laptop keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/N8h7uACYqQfmXe3eapwCRD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Ofcom has spelled out how it intends to use its powers under the <a href="https://www.itpro.com/business/policy-legislation/368807/how-will-the-online-safety-bill-change-the-tech-industry">Online Safety Act</a> – and it plans to take a tougher stance with big tech.</p><p>The Online Safety Act applies to search firms and services that allow users to post content online or to interact with each other - everything from <a href="https://www.itpro.com/social-media-marketing/33251/choosing-the-right-social-media-platform">social media</a> and consumer <a href="https://www.itpro.com/cloud/cloud-storage/362576/top-ten-cloud-storage-tips-and-tricks">cloud storage</a> and sharing sites to online forums and dating services. </p><p>It gives them new duties to put systems and processes in place to reduce the risk that their services are used for illegal activity, and to take down illegal content when it does appear. </p><p>Under the Act, Ofcom has the legal power to access information held by regulated companies and third parties, and said it will carefully scrutinize how effective tech firms’ safety measures are. </p><p>It will also demand data where it has specific concerns that the rules aren’t being followed.</p><p>This could include the power to remotely inspect how a platform’s algorithm works in real time, and the regulator said it will hold organizations to account over what they recommend to users, particularly children.</p><p>"As well as requesting information and data, we are also able to carry out an audit of a tech firm’s safety measures and features," said Ofcom. </p><p>"In exceptional cases, we can enter the UK premises of tech companies to access information they hold and examine their equipment."</p><p>It may do this in order to assess whether a provider is complying with the rules, or, if it isn't, to assess the nature and level of risk.</p><h2 id="ofcom-eyes-flexibility-with-new-guidance">Ofcom eyes flexibility with new guidance</h2><p>Ofcom said in the new <a href="https://www.ofcom.org.uk/siteassets/resources/documents/consultations/category-1-10-weeks/185926-consultation-online-safety-information-guidance/associated-documents/online-safety-information-gathering-guidance.pdf?v=391825"><u>guidance</u></a> that it will try to be flexible, and that when deciding whether to disclose information it will carefully balance the need against any concerns or objections.</p><p>However, if tech firms fail to comply with a request for information in an accurate, complete, and timely way, there will be consequences - some very serious - Ofcom warned.</p><p>They could, for example, face fines of up to £18 million or 10% of their worldwide revenue, whichever is higher. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="x7QkfYAMgcrBoSUayNJ4aV" name="Living off The Land Attacks.jpg" caption="" alt="Living off The Land Attacks" src="https://cdn.mos.cms.futurecdn.net/x7QkfYAMgcrBoSUayNJ4aV.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: CyberFox)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/living-off-the-land-attacks"><em>Are native system files being used against you?</em></a></p></div></div><p>In the most extreme cases, there could be criminal liability for individual executives for breaches such as knowingly or recklessly providing false information, failing to provide information, or failing to take all reasonable steps to prevent other information offences.</p><p>Last year, Ofcom fined TikTok under separate rules governing video-sharing platforms, for failing to respond to a request for information about its parental controls.</p><p>Meanwhile it's currently investigating OnlyFans' compliance with the Act, through a request for information.</p><h2 id="what-to-expect-from-the-ofcom-rules">What to expect from the Ofcom rules</h2><p>The new guidance is effective immediately. The act applies to sites and apps that publish user-made content to other users, as well as large search engines – covering more than 100,000 online services. </p><p>Under the act, firms will be required to nominate a senior executive to be accountable for compliance; have properly staffed and funded moderation teams that can swiftly remove illegal material, and implement robust testing of algorithms – which curate what users see on their feeds – to make it harder for illegal material to spread. </p><p>Similarly, organizations will be obligated to remove accounts operated by - or behalf of - terrorist groups. </p><p>Tech platforms are also expected to operate “easy to find” tools for making content complaints which acknowledge receiving a complaint and indicate when it will be dealt with. </p><p>The biggest platforms are expected to give users options to block and mute other accounts on the platform, along with the option to disable comments.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/cloud/cloud-computing/ofcom-calls-for-uk-cloud-antitrust-probe-amid-competition-concerns">Everything you need to know about Ofcom's cloud competition probe</a></li><li><a href="https://www.itpro.com/security/privacy/explained-the-state-of-end-to-end-encryption-in-the-uk-now-the-online-safety-bill-saga-is-over">How the Online Safety Act affects end-to-end encryption</a></li><li><a href="https://www.itpro.com/business/policy-legislation/370308/online-safety-bill-ofcom-government-big-tech">Ofcom is being thrown under the bus with the Online Safety Act</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ I think the UK government's attempt to strong-arm Apple into giving it an ADP backdoor is a travesty – and so does most of the industry  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/uk-governments-attempt-to-strongarm-apple-into-backdoor-adp-is-a-travesty</link>
                                                                            <description>
                            <![CDATA[ The UK’s demands for a government backdoor are misguided from a cybersecurity, privacy, and business perspective ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BPjz99j3z4Jy4sMe9AT4tD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sMARoEMrhAwnrvTJmZLppR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Feb 2025 11:50:00 +0000</pubDate>                                                                                                                                <updated>Tue, 25 Feb 2025 14:54:10 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a Staff Writer at ITPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2021 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sMARoEMrhAwnrvTJmZLppR-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Apple logo on a white flag at the brand&#039;s Regent Street store, representing Apple in the UK.]]></media:description>                                                            <media:text><![CDATA[The Apple logo on a white flag at the brand&#039;s Regent Street store, representing Apple in the UK.]]></media:text>
                                <media:title type="plain"><![CDATA[The Apple logo on a white flag at the brand&#039;s Regent Street store, representing Apple in the UK.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sMARoEMrhAwnrvTJmZLppR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Earlier this month reports emerged that the UK government issued an order to Apple to give it access to users’ encrypted data, reigniting the debate around digital privacy.</p><p>The issue centered around Apple’s Advanced Data Protection (ADP) tool, which is a feature that uses <a href="https://www.itpro.com/security/encryption/359943/what-is-end-to-end-encryption-and-why-is-everyone-fighting-over-it"><u>end-to-end encryption</u></a> to ensure only users that are signed in on a trusted device can view their personal files, excluding even Apple from accessing the data. </p><p>The order issued by the government, which will not be published, would have required Apple to give authorities a backdoor through which it could access the encrypted data for UK users. Apple has consistently reiterated that it opposes creating any backdoors for its <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption"><u>encryption</u></a> because it defeats the entire purpose of encryption – so it opted to simply turn off ADP in the UK, meaning that not all customer data stored via iCloud will be fully encrypted.</p><p>I believe the UK government’s decision is a total travesty, both from the perspective of global privacy and cybersecurity, as well as its ability to compete in the global tech industry.</p><p>Firstly, from a consumer rights perspective this is an unquestionable loss. Though the government maintains that encryption backdoors are important for combatting crime this logic totally misses the myriad ways in which encryption protects citizens.</p><p>Modern cryptography techniques have been a huge leap forward in terms of protecting people’s private data. Encryption means you can access your bank account from your phone securely, or view medical records online without worrying about cyber criminals intercepting your communications.</p><p>The bottom line is that in the internet age encryption is vital for almost all digital services and the continued attempts by governments to ensure they have a master key not only violates privacy, but undermines the overall security of the internet.</p><h2 id="uk-demands-could-set-privacy-and-security-back-decades">UK demands could set privacy and security back decades </h2><p>What the government fails to understand is that compromising the integrity of end-to-end encryption will introduce a raft of new harms for individuals and businesses alike.</p><p>As previously stated, introducing a backdoor to break encryption defeats the purpose of the entire exercise and gives <a href="https://www.itpro.com/security/cyber-attacks/the-new-era-of-cyber-threats">malicious actors</a> an easy target for compromising the most sensitive data.</p><p>The UK government has made similar attempts at circumventing encryption layers used by private companies in the past as noted in a 2015 paper <a href="https://academic.oup.com/cybersecurity/article/1/1/69/2367066" target="_blank"><u>published</u></a> in the <em>Journal of Cybersecurity</em> looking at the security implications of requiring ‘exceptional access’ to information systems.</p><p>In the paper, researchers perfectly laid out why government efforts to access  information would hinge on developers coming up with designs that minimized the impact of breaches, but that this is “unworkable in practice” and would set the global cybersecurity community back decades.</p><p>“The complexity of today’s Internet environment, with millions of apps and globally connected services, means that new law enforcement requirements are likely to introduce unanticipated, hard to detect security flaws,” the researchers wrote.</p><p>The UK government is setting a dangerous precedent by insisting its agencies be given a backdoor to private companies’ encryption systems. It frequently lambasts other governments such as China for privacy violations, but the latter still allows Apple’s ADP technology in the region. </p><p>I’m far from alone in my feelings of disappointment in the government for pushing ahead with its decision. Experts from across the tech sector have argued that undermining encryption is unacceptable.</p><p>In an unpublished letter <a href="https://x.com/FutureJurvetson/status/1893301827505942839" target="_blank">shared</a> on X, <a href="https://www.itpro.com/business/business-operations/368997/signal-hires-former-google-manager-meredith-whittaker-as-first-president">Meredith Whittaker</a>, president of the Signal Foundation, which has warned it may have to quit the UK if it continues to undermineend–to-end encryption, wrote that the move puts sensitive information belonging to UK businesses and citizens at “grave risk from malicious actors”.</p><h2 id="technically-illiterate-request-risks-harming-uk-s-tech-ambitions">“Technically illiterate” request risks harming UK’s tech ambitions</h2><p>The current government follows the last in citing its ambition for the UK to become a global tech hub and <a href="https://www.itpro.com/technology/artificial-intelligence/public-sector-improvements-infrastructure-investment-and-ai-pothole-repairs-tech-industry-welcomes-uks-ambitious-ai-action-plan">unlock AI opportunities</a>. But by taking actions like this, it is seriously shooting itself in the foot.</p><p>Legal experts such as Will Richmond-Coggan, a partner specializing in cybersecurity and privacy disputes at Freeths LLP, said Apple’s decision to turn off ADP could have a domino effect on other major tech companies, warning “the UK may no longer be seen as a safe destination for personal data”.</p><p>“If that in turn results in the UK losing its <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">adequacy status with the EU</a>, every company doing business in Europe will be subject to additional costly <a href="https://www.itpro.com/business/business-strategy/keeping-up-with-the-compliance-landscape-in-2024">compliance obligations</a>, hampering the government's plans for growth, and a closer European political relationship.”</p><p>Whittaker described the move as “technically illiterate” restating that Signal would sooner stop operating in the UK than compromise its encryption.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LjWdHEMBU3LCLK4bVET7Rg" name="Understanding Least Privileges.jpg" caption="" alt="Understanding Least Privileges" src="https://cdn.mos.cms.futurecdn.net/LjWdHEMBU3LCLK4bVET7Rg.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: CyberFox)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/understanding-least-privileges"><em>Protect your company from ransomware attacks</em></a></p></div></div><p>“The UK's technically illiterate demand also undermines its ambitions to become a tech hub. You can’t be tech friendly while eroding the foundation of cybersecurity on which robust tech depends. Encryption is not a luxury – it is a fundamental human right essential to a free society that also happens to underpin the global economy,” she argued.</p><p>This furore all started with the UK government taking exception to an optional feature that the majority of users don’t have turned on – making a mountain of a molehill – but it could have major consequences. </p><p>The government should roll this back, and quickly, if it wants to send the right signals to global business and regain any credibility it has on discussions on privacy and cybersecurity.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is the Advanced Research and Invention Agency (ARIA)? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/what-is-aria</link>
                                                                            <description>
                            <![CDATA[ The UK’s ARIA drives high-risk, high-reward innovation with £800m in funding, fostering technological advancements and scientific breakthroughs ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GQvnyJ9aVadcDZB4dh9vfP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/V2ys9pFQ9KUiNYDEcrF4MS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 24 Feb 2025 13:15:33 +0000</pubDate>                                                                                                                                <updated>Tue, 25 Feb 2025 09:17:48 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ David Howell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/QST9gbWQZLs5T4KfoM2StL.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/V2ys9pFQ9KUiNYDEcrF4MS-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A futuristic, dark glossy instrument panel showing white a digital map of the UK surrounded by stats, diagnostics. ]]></media:description>                                                            <media:text><![CDATA[A futuristic, dark glossy instrument panel showing white a digital map of the UK surrounded by stats, diagnostics. ]]></media:text>
                                <media:title type="plain"><![CDATA[A futuristic, dark glossy instrument panel showing white a digital map of the UK surrounded by stats, diagnostics. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/V2ys9pFQ9KUiNYDEcrF4MS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Advanced Research and Invention Agency (ARIA) is a UK-based research and development funding agency established to catalyze transformative scientific and technological breakthroughs. </p><p>The success of the UK's COVID response – exemplified by initiatives like the Vaccines Taskforce and Rapid Response Funds – has highlighted the importance of agile funding models. ARIA seeks to apply these lessons, operating as a flexible, independent body dedicated to high-risk, high-reward projects.</p><p>First announced in February 2021 and backed by a government investment of £800 million, the organization was inspired by the principles of the US Advanced Research Projects Agency (ARPA), now known as <a href="https://www.itpro.com/software/development/darpa-wants-to-accelerate-translation-of-c-code-to-rust-and-its-relying-on-ai-to-do-it"><u>Defense Advanced Research Projects Agency (DARPA)</u></a>. </p><p>Since the 1950s, DARPA has been instrumental in funding transformative technological advancements, including developing the Internet (ARPANET), GPS technology, and early voice recognition systems. Other countries, such as Japan and Germany, have since established similar bodies, such as Japan's Moonshot R&D and Germany's SPRIN-D.</p><h2 id="funding-and-project-support">Funding and project support</h2><p>Traditional research funding in the UK has often been characterized by cautious <a href="https://www.itpro.com/business/uk-chancellor-looks-to-mirror-us-tech-investment-success-in-autumn-statement"><u>investment</u></a> strategies, prioritizing projects with predictable outcomes. ARIA seeks to disrupt this paradigm by providing the autonomy and resources necessary for researchers to pursue bold ideas without the constraints of conventional funding mechanisms.</p><p>Overall, ARIA operates with a budget of £800 million allocated over five years, from 2023 to 2028. The UK government provides this funding through the <a href="https://www.itpro.com/business/policy-and-legislation/who-is-peter-kyle-the-uks-new-technology-secretary-and-what-are-his-plans-for-the-future-of-the-sector"><u>Department for Science, Innovation and Technology (DSIT)</u></a>. As an independent agency, ARIA can allocate these funds toward projects that align with its mission of unlocking significant scientific and technological advancements. This financial structure is designed to provide ARIA with the agility to respond swiftly to emerging opportunities and support projects that may not fit the traditional funding frameworks.</p><p>"Our funding terms are designed to encourage inventor-led startups and stimulate science entrepreneurship in the UK," comments Antonia Jenkinson, chief finance and operating officer <a href="https://www.aria.org.uk/about-aria/how-we-work" target="_blank">on the ARIA website.</a></p><p>The following core principles define ARIA’s approach:</p><ul><li>High-risk, high-reward research focus: ARIA exclusively supports projects that have the potential to create paradigm shifts in science and technology. While many funded projects may not succeed, those that do could profoundly impact society.</li><li>Strategic and scientific autonomy: ARIA operates independently in selecting research programs, funding allocation, and institutional culture. Programme Directors have full discretion over the projects they support, with minimal government intervention.</li><li>Empowering talented individuals: ARIA provides exceptional researchers and innovators the freedom to pursue their boldest ideas. Program directors are appointed based on their expertise and vision, allowing them to direct funding dynamically.</li><li>Financial flexibility and operational freedom: ARIA is structured to minimize bureaucratic constraints and maximize efficiency. To encourage disruptive innovation, it employs various innovative funding mechanisms, including seed grants, equity stakes, and prize-based incentives.</li></ul><p>The agency operates through two primary funding modes: programs and opportunity seeds. Programs are large-scale initiatives to advance complex ideas requiring coordinated investment across multiple disciplines and institutions, totalling between £50-80 million ($63-101 million). Program directors manage a portfolio of projects within these programs to drive significant breakthroughs. </p><p>Opportunity seeds of up to £500,000 ($631,700) support individual research teams exploring novel pathways that could inspire future programmes or evolve into standalone projects. This approach allows ARIA to fund diverse ideas and rapidly test their potential.</p><p>The agency does not retain intellectual property rights to the work it funds and generally does not require match funding. ARIA also does not take equity stakes in spinouts commercializing ARIA-funded IP. This approach is designed to <a href="https://www.itpro.com/business/why-the-uk-keeps-losing-promising-startups">encourage inventor-led UK startups</a> and stimulate science entrepreneurship in the UK.</p><iframe allow="" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/5cc670e6-73df-41bf-bace-b8510d63edb1/"></iframe><p>ARIA has identified several "opportunity spaces"—critically important but underexplored research areas ripe for breakthroughs. Each opportunity space is a foundation for multi-year programmes directed by the agency's Programme Directors. Notable opportunity spaces include:</p><ul><li><strong>Mathematics for safe AI</strong>: This program aims to develop technical solutions to ensure that powerful <a href="https://www.itpro.com/strategy/28181/what-is-ai"><u>AI</u></a> systems interact as intended with real-world systems and populations. It combines scientific models and mathematical proofs to achieve <a href="https://www.itpro.com/technology/30736/what-is-ethical-ai"><u>ethical AI</u></a> that can transform the tech sector while preventing user harm.</li><li><strong>Nature computes better</strong>: This research explores redefining how computers process information by exploiting natural principles, potentially leading to dramatically more efficient computing systems.</li><li><strong>Smarter robot bodies</strong>: Focusing on creating robots capable of operating independently in complex and dynamic environments, this program aims to develop smarter <a href="https://www.itpro.com/business/digital-transformation/not-if-but-when-where-are-the-autonomous-robots">robotic systems</a> to reduce the burden of physical labour.</li><li><strong>Scalable neural interfaces</strong>: This area focuses on developing minimally invasive technologies to <a href="https://www.itpro.com/technology/369239/what-the-brain-computer-interface-bci-means-for-business">interface with the human brain</a> at scale, aiming to transform our understanding and treatment of neurological and neuropsychiatric disorders.</li><li><strong>Programmable plants</strong>: By programming plants, this initiative seeks to address challenges like food insecurity, climate change, and environmental degradation, ensuring a sustainable biosphere for future generations.</li></ul><p>Through these initiatives, ARIA actively funds projects that challenge existing assumptions, open new research paths, and strive toward transformative capabilities. The agency's commitment to high-risk, high-reward research is designed to position the UK as a leader in scientific and technological innovation, with the potential to generate significant social and economic benefits.</p><h2 id="key-aria-personnel-and-relationships-with-public-sector">Key ARIA personnel and relationships with public sector</h2><p>ARIA's leadership comprises individuals with diverse science, technology, and innovation expertise. Ilan Gur serves as the CEO at ARIA, bringing a wealth of experience from his previous roles, including his tenure as a Program Director at ARPA-E and as the founder of Activate, an organization supporting early-stage scientists in transforming research into viable products and businesses. </p><p>Antonia Jenkinson, chief finance and operating officer at ARIA, supports Gur and oversees ARIA's financial and operational functions. The agency's strategic direction is further guided by its board, which includes notable figures such as the entrepreneur and government advisor Matt Clifford, who oversaw the UK’s recently-published <a href="https://www.itpro.com/technology/artificial-intelligence/public-sector-improvements-infrastructure-investment-and-ai-pothole-repairs-tech-industry-welcomes-uks-ambitious-ai-action-plan"><u>AI Opportunities Action Plan</u></a>, as well as Nobel laureate David MacMillan and Kate Bingham, the former head of the UK’s Vaccine Taskforce.</p><p>Its advisors also include <a href="https://www.itpro.com/software/google/demis-hassabis-the-man-behind-google-deepmind-commits-to-ethical-ai"><u>Demis Hassabis</u></a>, the co-founder and CEO of Google DeepMind. ARIA states that its board and advisors allow it to ground its high-risk, high-reward scientific exploration in diverse perspectives and expert-led governance.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="3cvMNbN3QogMsPACwHfYdc" name="Making cloud accessible and affordable for small businesses" caption="" alt="Making cloud accessible and affordable for small businesses" src="https://cdn.mos.cms.futurecdn.net/3cvMNbN3QogMsPACwHfYdc.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ANS)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-computing/making-cloud-accessible-and-affordable-for-small-businesses"><em>Removing barriers to growth</em></a></p></div></div><p>ARIA operates as an independent public body under the Department for Business, Energy & Industrial Strategy (BEIS) sponsorship. While it has significant autonomy, the agency remains subject to national security oversight and financial transparency requirements, including an annual audit by the National Audit Office.</p><p>Unlike <a href="https://www.itpro.com/business/uks-answer-to-silicon-valley-planned-for-west-of-england-and-wales"><u>UK Research and Innovation (UKRI)</u></a>, which manages a broad research funding portfolio across multiple disciplines, ARIA focuses on a narrower range of projects. However, both agencies must collaborate to ensure alignment in the UK's research ecosystem. ARIA's distinct model allows it to take risks that traditional funding mechanisms cannot, complementing UKRI’s more structured approach.</p><h2 id="future-development">Future development</h2><p>ARIA represents a bold new approach to research funding in the UK, drawing inspiration from the world’s most successful innovation agencies. By embracing risk, minimizing bureaucracy, and providing top researchers with unprecedented autonomy, ARIA aims to unlock breakthrough discoveries that will shape the future of science, technology, and industry.</p><p>With an initial investment of £800 million and a leadership team committed to transformative research, ARIA has the potential to cement the UK’s status as a science superpower and drive economic growth through pioneering technological advancements.</p><p>In a world where technological advancements are accelerating, ARIA's establishment reflects a strategic commitment to ensuring that the UK remains at the cutting edge of scientific discovery and innovation. By empowering researchers to pursue visionary projects, ARIA hopes to deliver breakthroughs that could have profound and lasting impacts on not just the tech sector but wider society.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is the Data Use and Access Bill? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/data-use-and-access-bill-explained</link>
                                                                            <description>
                            <![CDATA[ Aimed at boosting efficiency in the UK, the Data Use and Access Bill is designed to cut red tape around data use. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KymztDpbaTtgK28HCwdGxn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dvYJkE4V4YUFg6s5Nvkq8H-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Feb 2025 13:04:32 +0000</pubDate>                                                                                                                                <updated>Tue, 18 Feb 2025 09:06:10 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ george.fitzmaurice@futurenet.com (George Fitzmaurice) ]]></author>                    <dc:creator><![CDATA[ George Fitzmaurice ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/N4xHCjSAXKcijjt3oiQtfc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dvYJkE4V4YUFg6s5Nvkq8H-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Westminster Parliament and the Big Ben clocktower pictured with Westminster Bridge.]]></media:description>                                                            <media:text><![CDATA[Westminster Parliament and the Big Ben clocktower pictured with Westminster Bridge.]]></media:text>
                                <media:title type="plain"><![CDATA[Westminster Parliament and the Big Ben clocktower pictured with Westminster Bridge.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dvYJkE4V4YUFg6s5Nvkq8H-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.itpro.com/business/public-sector/government-says-new-data-bill-will-free-up-millions-of-hours-of-public-sector-time">Data Use and Access Bill</a> is a piece of legislation introduced by the UK government to allow for a greater level of <a href="https://www.itpro.com/business/policy-legislation/361798/uk-and-us-agree-on-deeper-data-sharing-partnership">data sharing</a> and data exchange within both public and private sector organizations. </p><p>Introduced to parliament <a href="https://www.itpro.com/business/public-sector/government-says-new-data-bill-will-free-up-millions-of-hours-of-public-sector-time"><u>towards the end of 2024</u></a>, the government says this bill could save millions of hours for many public sector workers as well as add an estimated £10 billion to the UK economy over a period of 10 years. The bill can be divided into seven sections <a href="https://commonslibrary.parliament.uk/research-briefings/cbp-10186/#:~:text=According%20to%20the%20government%2C%20the,pressures%20to%20the%20country's%20finances%E2%80%9D." target="_blank"><u>according to the government</u></a>, with the first centered on the enablement of “smart data” use outside the finance sector.</p><p>It would regulate the provision of digital verification services, digitalize birth and death registrations, make changes to the UK’s data protection regime, and transfer the function of the <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a> to a new Information Commission.</p><p>The bill would also make further provisions about the use of or access to data in areas such as health and social care, smart meter communication services, public service delivery, and online safety. </p><p> "With laws that help us to use data securely and effectively, this Bill will help us boost the UK’s economy, free up vital time for our front-line workers, and relieve people from unnecessary admin so that they can get on with their lives," technology secretary <a href="https://www.itpro.com/business/policy-and-legislation/who-is-peter-kyle-the-uks-new-technology-secretary-and-what-are-his-plans-for-the-future-of-the-sector"><u>Peter Kyle</u></a> said at the time of the bill’s announcement.</p><p>Experts from the tech sector have broadly welcomed the legislation, commending its focus on improving efficiency. Alex Laurie, senior vice president at Ping Identity, said that any legislation of this kind is a positive step.</p><p>“From my perspective, anything that makes it easier for us to do business as a citizen is massively important,” Laurie tells <em>ITPro</em>. “If it takes time out of people's working day I think it's an important thing.”</p><h2 id="how-will-the-data-use-and-access-bill-affect-the-public-sector">How will the Data Use and Access Bill affect the public sector?</h2><p>This legislation has the public sector at its core, with many of the bill’s benefits noted by the government relating to heightening efficiencies in the UK’s police force or the National Health Service (NHS).</p><p>Within the NHS, for example, administrative processes can be very lengthy and time consuming, having a negative impact on the organization and the customer. Laurie expressed his own understanding of this, referring to a study his firm undertook regarding disabled parking permits. </p><iframe allow="" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=62749338&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=true&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>“We did an analysis a few years ago on how many agencies and individual units were involved in getting a blue badge for someone, and it was like 35 different steps, which all needed identification, verification, proof,” Laurie says. </p><p>This bill will likely hone in on a set concept of data portability, Laurie adds, which is an important step forward in speeding up these sorts of processes. Lauren Wills-Dixon, solicitor at Gordons, tells <em>ITPro </em>the bill will also lay out a more coherent, straightforward idea of what data can be used and for what purposes.</p><p>“The bill introduces this concept of recognized <a href="https://www.itpro.com/technology/artificial-intelligence/generative-ai-training-in-the-crosshairs-as-ico-set-to-examine-legality-of-personal-data-use">legitimate interest</a> to give organizations certainty,” she says.</p><p>Wills-Dixon explains that it will recognize several legitimate interests including national security processing, emergency response, and safeguarding efforts.  </p><p>It will also cut red tape in the public sector, according to Richard Fayers, data and analytics practice lead at Slalom, reducing the lengths that workers have to go to in recording personal data use.</p><h2 id="how-will-the-data-use-and-access-bill-affect-the-private-sector">How will the Data Use and Access Bill affect the private sector?</h2><p>While there’s a huge opportunity in the public sector space, Fayers is keen to point out how elements of the bill – such as the smart data schemes – will likely drive innovation across the private sector landscape. </p><p>For example, he suggests the bill could introduce a greater level of openness for UK businesses and turn attention towards open standards akin to what has been seen in the finance sector with <a href="https://www.itpro.com/policy-legislation/30661/what-is-open-banking"><u>open banking</u></a>. Fayers sees massive opportunities across sectors by building on this interoperability of data. </p><p>There may also be better forecasting of public demand through a pooling of company information, Fayers adds, as well as the potential for businesses to share data to offer collaborative schemes or experiences to customers. Businesses could then give customers a unified profile that works from company to company.   </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LjWdHEMBU3LCLK4bVET7Rg" name="Understanding Least Privileges.jpg" caption="" alt="Understanding Least Privileges" src="https://cdn.mos.cms.futurecdn.net/LjWdHEMBU3LCLK4bVET7Rg.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: CyberFox)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/understanding-least-privileges"><em>Protect your company from ransomware attacks</em></a></p></div></div><p>Bill Wright, global head of government affairs at Elastic, echoes some of these predictions for potential advantages to the private sector. The bill will allow firms in every sector to access and analyze consumer data more effectively, Wright tells <em>ITPro</em>. </p><p>“Simplifying the data sharing rules are going to, maybe, break down some of those silos between industries and create some opportunities for startups to compete with some of the more established players,” Wright says. </p><p>It may even increase foreign investment into the UK, Wright says finally, by showing those outside the UK that the country has a data processing environment both predictable and innovative. </p><h2 id="what-do-it-leaders-need-to-know-about-compliance">What do IT leaders need to know about compliance?</h2><p>As with any new piece of legislation, the data use and access bill will require some degree of reorganization from firms when it comes to ensuring compliance. That being said, Wills-Dixon predicts companies that are already compliant with <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR</a> don't face serious challenges to becoming compliant with the Data Use and Access Bill.</p><p>“If you're carrying out research, statistical use of data, or processing in the public interest and things like that, then it will help, but for most commercial organizations, your obligations are going to be very similar as drafted,” Wills-Dixon adds. </p><p>That said, Fayers warns the new Information Commission will have enhanced enforcement powers and businesses will also need to ensure they can demonstrate robust security and data governance. This will demand a greater focus on compliance certification and accountability frameworks, Fayers says. </p><p>“If you're seen to be transparent – if you're providing customers with assurance and visibility of how you're managing this risk as well – that could also be seen as a benefit, whilst there's a cost,” Fayers concludes.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/software/development/what-is-chaos-engineering-and-how-can-it-benefit-businesses">What is chaos engineering and how can it benefit businesses?</a></li><li><a href="https://www.itpro.com/business/business-strategy/what-is-quiet-firing">What is quiet firing?</a></li><li><a href="https://www.itpro.com/security/i-love-magic-links-why-arent-more-services-using-them">Why magic links should be the default password replacement</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is the EU's AI plan? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/what-is-the-eus-ai-plan</link>
                                                                            <description>
                            <![CDATA[ As the EU moves to enable AI innovation, it could end up striking the perfect balance between regulation and public support – especially as US AI laws become more complex ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">CKRosNmZjpmXToEPFhfpb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bXDBt7574rhGuyQM6te3vA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Feb 2025 16:48:30 +0000</pubDate>                                                                                                                                <updated>Mon, 17 Feb 2025 16:47:24 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ rory.bathgate@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rory Bathgate is the Features and Multimedia Editor at ITPro, overseeing all in-depth content and case studies. He is a subject expert on artificial intelligence and business networks but in his time at ITPro has also covered a wide range of areas including cyber security and hardware. Throughout his time at ITPro, Rory has charted the rise in popularity of generative AI and specifically companies such as Microsoft, OpenAI, and Google.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Alongside this, he has delved into increasing calls for ethical and responsible AI as global legislators circle the technology, as well as the latest in mobile networking technology, from 5G mmWave to the 3G sunset and how it will affect businesses.&lt;/p&gt;
&lt;p&gt;He has provided coverage from high-profile tech conferences such as Dell Technologies World, SuiteWorld, and VMware Explore Europe. His on-the-ground coverage has included live blogs, extensive daily coverage of the most significant announcements, analysis pieces, and podcasts.&lt;/p&gt;
&lt;p&gt;Indeed, Rory is also a full-time co-host of the ITPro Podcast alongside Jane McCallion, where he swaps a keyboard for a microphone to discuss the latest learnings in tech. Each week, a guest comes onto the show to discuss topics such as cyber security, productivity, or digital transformation in detail.&lt;/p&gt;
&lt;p&gt;Rory has an MA in Eighteenth-Century Studies from King’s College London, as well as a BA in English and American Literature from the University of Kent. He joined ITPro in 2022 as a graduate, after four years in student journalism.&lt;/p&gt;
&lt;p&gt;In his free time, Rory enjoys photography and video editing, and can often be found at the cinema or reading a good science fiction paperback.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bXDBt7574rhGuyQM6te3vA-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The words &quot;What is the EU&#039;s AI plan?&quot; set against a blue backdrop with five gold stars draw on it in pencil. The words &quot;EU&#039;s AI plan&quot; are yellow, while the others are white. The ITPro Podcast logo is in the bottom right-hand corner.]]></media:description>                                                            <media:text><![CDATA[The words &quot;What is the EU&#039;s AI plan?&quot; set against a blue backdrop with five gold stars draw on it in pencil. The words &quot;EU&#039;s AI plan&quot; are yellow, while the others are white. The ITPro Podcast logo is in the bottom right-hand corner.]]></media:text>
                                <media:title type="plain"><![CDATA[The words &quot;What is the EU&#039;s AI plan?&quot; set against a blue backdrop with five gold stars draw on it in pencil. The words &quot;EU&#039;s AI plan&quot; are yellow, while the others are white. The ITPro Podcast logo is in the bottom right-hand corner.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bXDBt7574rhGuyQM6te3vA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <iframe allow="" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/e72e3adf-5bdc-4be4-bfe8-51510b6b9843/"></iframe><p>Years after first identifying the potential risks of AI systems, world leaders are having to balance concerns with an acknowledgment of the gains achievable through certain AI systems and nowhere is this more true than the EU.</p><p>The Artificial Intelligence Action Summit in Paris has seen a number of high-profile announcements made on EU AI investments, on both a continental and regional basis. But it’s also highlighted the distance the EU has yet to go for true international AI competition – up against the likes of the US and China, can it continue to stand out? </p><p>In this episode, Jane and Rory welcome Nader Henein, Gartner VP analyst, Data Protection and AI Governance, to discuss the finer details of EU AI and how public-private partnerships balance with its strong legal requirements for the technology.</p><h2 id="highlights">Highlights</h2><p>"There's a fair bit of AI development having happening at the sectoral level in pharmaceutical development, for example, there's a lot have there's a lot happening in medicine. So there's a lot happening. It might not be as newsworthy as something like Mistral or it might not be a unicorn worth multiple billions of dollars or euros, I should say. But there's a lot happening in Europe, from an AI perspective."</p><p>"I need to reach, pick up the phone and speak to the vendor, because there's not a piece of software that can scan my SaaS solution and tell me that, 'Oh, this SaaS solution you're using, the CRM and the cloud that you're using, it has 26 AI-enabled features, of which six are high risk. So you better pay attention to those and get a bit more detail'. Nothing's going to do that for you. You have to pick up the phone and speak to the vendor."</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="x7QkfYAMgcrBoSUayNJ4aV" name="Living off The Land Attacks.jpg" caption="" alt="Living off The Land Attacks" src="https://cdn.mos.cms.futurecdn.net/x7QkfYAMgcrBoSUayNJ4aV.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: CyberFox)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/living-off-the-land-attacks"><em>Hackers are using native system files against you</em></a></p></div></div><p>"And Ursula [von der Leyen] said – it was very nuanced yesterday – she made a comment, a throwaway comment in her speech, that you have 27 countries with one piece of legislation, one set of rules. And the fact of the matter is, for any business and for any outsider looking in, the US is going to be one country with 50 different laws. Even if the federal government gets out of the way. In fact, the federal government federal government had introduced AI regulation from the very beginning, there's a good chance that most states would have said that's what I'm going to follow."</p><h2 id="footnotes">Footnotes</h2><ul><li><a href="https://www.itpro.com/technology/artificial-intelligence/uk-and-us-reject-paris-ai-summit-agreement-as-atlantic-rift-on-regulation-grows"><u>UK and US reject Paris AI summit agreement as “Atlantic rift” on regulation grows</u></a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/unraveling-the-eu-ai-act"><u>Unraveling the EU AI Act</u></a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/the-eu-just-shelved-its-ai-liability-directive"><u>The EU just shelved its AI liability directive</u></a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/a-big-enforcement-deadline-for-the-eu-ai-act-is-just-around-the-corner"><u>A big enforcement deadline for the EU AI Act just passed – here's what you need to know</u></a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/looking-to-use-deepseek-r1-in-the-eu-this-new-study-shows-its-missing-key-criteria-to-comply-with-the-eu-ai-act"><u>Looking to use DeepSeek R1 in the EU? This new study shows it’s missing key criteria to comply with the EU AI Act</u></a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/how-the-eu-ai-act-compares-to-other-international-regulatory-approaches"><u>How the EU AI Act compares to other international regulatory approaches</u></a></li><li><a href="https://www.itpro.com/business/ai-growth-zone-uk-"><u>UK regions invited to apply for ‘AI Growth Zone’ status</u></a></li></ul><h2 id="subscribe">Subscribe</h2><ul><li><a href="https://podcasts.apple.com/gb/podcast/the-itpro-podcast/id1483810154" target="_blank"><u>Subscribe to The ITPro Podcast on Apple Podcasts</u></a></li><li><a href="https://open.spotify.com/show/7HpYehTy752KmtbwpOAgRZ" target="_blank"><u>Subscribe to The ITPro Podcast on Spotify</u></a></li><li><a href="https://www.itpro.com/newsletter-signup"><u>Subscribe to the ITPro newsletter</u></a></li><li><a href="https://youtube.com/playlist?list=PLlDcvb6CsY45dAoTg820kUsg6KsICq5Ah&si=5l7zAywUc4wN_YaV" target="_blank"><u>Subscribe to the ITPro Podcast on YouTube</u></a></li><li><a href="https://uk.linkedin.com/company/itpro-uk" target="_blank"><u>Join us on LinkedIn</u></a></li></ul><h2 id=""></h2>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Europe could do it, but it's chosen not to do it’: Eric Schmidt thinks EU regulation will stifle AI innovation – but Britain has a huge opportunity ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/eric-schmidt-eu-ai-regulation-uk</link>
                                                                            <description>
                            <![CDATA[ Former Google CEO Eric Schmidt believes EU AI regulation is hampering innovation in the region and placing enterprises at a disadvantage. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iLgsqgqzd7DfFoV9m2CxLS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iCDsnwPWSth6HFoamxBPUh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Feb 2025 10:06:44 +0000</pubDate>                                                                                                                                <updated>Wed, 19 Feb 2025 12:16:47 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iCDsnwPWSth6HFoamxBPUh-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Former Google CEO Eric Schmidt pictured at the AI Action Summit in Paris, France, on Monday, Feb. 10, 2025.]]></media:description>                                                            <media:text><![CDATA[Former Google CEO Eric Schmidt pictured at the AI Action Summit in Paris, France, on Monday, Feb. 10, 2025.]]></media:text>
                                <media:title type="plain"><![CDATA[Former Google CEO Eric Schmidt pictured at the AI Action Summit in Paris, France, on Monday, Feb. 10, 2025.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iCDsnwPWSth6HFoamxBPUh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/business/business-strategy/eric-schmidt-s-car-crash-stanford-interview-showed-big-tech-s-true-colors-on-remote-work">Former Google CEO Eric Schmidt</a> has hit out at <a href="https://www.itpro.com/business/policy-and-legislation/how-the-eu-ai-act-compares-to-other-international-regulatory-approaches">EU AI regulation</a>, suggesting overburdening rules put European companies at an inherent disadvantage compared to global counterparts. </p><p>Speaking on the <a href="https://www.bbc.co.uk/sounds/play/m0027tw9">BBC Radio 4<em>Today </em>program</a>, Schmidt said a combination of factors are hampering AI innovation in the region, including restrictive regulation and the natural “structure” of European markets. </p><p>Reflecting on his time at Google, Schmidt said he worked for “at least 10 years to try to get Europe up to the bar”, noting that lucrative talent pools on both the continent and in the UK give enterprises a prime opportunity to compete. </p><p>Regulatory barriers, however, are preventing the region from making any headway in the global AI race. </p><p>“The system doesn't work, right? They can't build big enough companies. The markets are not integrated. Partly it's just the structure of Europe, but it’s also that Brussels, in addition to promising uniform markets, also regulates in a particularly strong way,” he said. </p><p>“The result of this is that the AI revolution, which is the most important revolution in my opinion since electricity, is not going to be invented in Europe, and that's to Europe's disservice,” Schmidt added. </p><p>“Europe could do it, but it's chosen not to do it, and I'm really quite brutal on this.”</p><h2 id="fair-game-in-the-us-ai-market">Fair game in the US AI market</h2><p>The situation is quite different across the Atlantic, Schmidt noted. The US’ approach to <a href="https://www.itpro.com/technology/machine-learning/local-machine-learning-promises-to-cut-the-cost-of-ai-development-in-2024">AI development</a> stands in stark contrast to the European market, with lawmakers and enterprises alike engaged in a rabid race to the top. </p><p>With the Trump administration now in place in Washington DC, Schmidt pointed to a sense of burgeoning optimism among leading enterprises in the AI space, many of whom have invested billions of dollars thus far and intend to ramp up spending in the year ahead. </p><p>So far this year, Meta, AWS, Microsoft, and Google have all outlined plans to accelerate capital expenditure – and a key factor in this will be expanding AI infrastructure. Meta, for example, expected to spend upwards of $60 billion this year, marking a significant increase from $39 billion in 2024.</p><p>“When I looked at the swearing in with my friends behind the president I thought, ‘wow, we have arrived’ - and that doesn’t necessarily mean that we are going to be unregulated,” he said. </p><p>“It means the inverse in my view,” he added. “Everyone, starting with you, are watching what we're doing, which I view as a good thing.”</p><iframe allow="" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/e72e3adf-5bdc-4be4-bfe8-51510b6b9843/"></iframe><p>This doesn’t mean that the US will pursue a ‘Wild West’ approach to AI development, however. Instead, providing enterprises the regulatory flexibility to develop AI models and adopting a gentler approach is the ideal situation.</p><p>“The truth is that AI and the future is largely going to be built by private companies,” Schmidt said.</p><p>“It has to do with the incentives and the money, where the talent is, and how the world works, they're not going to be built in the equivalent of a Manhattan Project.”</p><p>Schmidt noted that it’s “really important that governments understand what we’re doing and keep their eye on us”. </p><p>“We’re not arguing that we should unilaterally be able to do things without oversight,” he added. </p><p>Schmidt has been highly vocal on the potential dangers posed by unchecked <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a> development in recent months, warning that systems could be used by bad actors for nefarious purposes ranging from biological warfare to <a href="https://www.itpro.com/security/cyber-crime/agentic-ai-cybersecurity-risks">cyber crime</a>. </p><h2 id="britain-has-an-opportunity-to-differentiate-itself">Britain has an opportunity to differentiate itself</h2><p>While discussions over the potential barriers to AI innovation in Europe continue, Schmidt did point to the UK’s opportunity, suggesting it can differentiate itself from European counterparts. </p><p>The <a href="https://www.itpro.com/technology/artificial-intelligence/uk-and-us-reject-paris-ai-summit-agreement-as-atlantic-rift-on-regulation-grows">UK joined the US in refusing to sign an international agreement</a> on sustainable AI development at this week’s global summit in Paris, prompting suggestions an ‘Atlantic rift’ is opening up on the topic of AI. </p><p>This decision was based on concerns that the declaration lacked 'practical clarity', officials said, particularly on the issue of global governance and national security.</p><p>The <a href="https://www.itpro.com/business/policy-and-legislation/is-the-uk-falling-behind-the-eu-on-ai-regulation">UK’s approach to AI has deviated from that in Europe</a>, and the current government has made clear it hopes to position itself as a global leader on this front by attracting international investment and building out infrastructure. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nMPk3hYgRaNUm4dqd8ZtSQ" name="Discover how these data centers from Germany and Australia became more resilient to disruption, while also lowering operating costs and CO2 emission" caption="" alt="Discover how these data centers from Germany and Australia became more resilient to disruption, while also lowering operating costs and CO2 emission." src="https://cdn.mos.cms.futurecdn.net/nMPk3hYgRaNUm4dqd8ZtSQ.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ABB)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/data-centres/discover-how-these-data-centers-from-germany-and-australia-became-more-resilient-to-disruption-while-also-lowering-operating-costs-and-co2-emission"><em>Data centers fortified with robust maintenance</em></a></p></div></div><p>Notably, Schmidt said the UK has success stories to champion that will stand it in good stead. </p><p>“So some credit to Britain,” he said. “Much of the path to general intelligence was pioneered in King’s Cross in a building occupied by a subsidiary of Google called DeepMind by - now a Nobel Prize winner - <a href="https://www.itpro.com/software/google/demis-hassabis-the-man-behind-google-deepmind-commits-to-ethical-ai"><u>Demis Hassabis</u></a>.”</p><p>“What they have done is so extraordinary it should be a point of national pride,” Schmidt added. “It may be the most important thing that Britain has done in the last five years, in my opinion.”</p><p>Schmidt further hailed the government’s apparent pursuit US-style regulation, which involves consultation and close collaborative ties with industry. </p><p>“It looks to me like the pairing of the US and the UK is a winning strategy,” he said. “And it looks to me like the Europeans, because of Brussels, are being held behind.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/infrastructure/salesforce-thinks-the-uk-is-ready-to-lead-the-next-wave-of-ai">Salesforce thinks the UK is ready to lead the next wave of AI</a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/the-uk-needs-to-be-more-hands-on-with-ai-legislation-simply-standing-on-the-world-stage-isnt-enough">Why the UK needs to look inward on AI legislation</a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/google-says-uk-needs-policy-step-change-to-embrace-its-ai-potential">Google says UK needs policy step change to embrace its AI potential</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The EU just shelved its AI liability directive ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/the-eu-just-shelved-its-ai-liability-directive</link>
                                                                            <description>
                            <![CDATA[ The European Commission has scrapped plans to introduce the AI Liability Directive aimed at protecting consumers from harmful AI systems. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">JgdzVsZCoMw2qCdUhsXvC5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qnGSwbfzp9zTsFt2t49oUT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Feb 2025 12:08:59 +0000</pubDate>                                                                                                                                <updated>Wed, 19 Feb 2025 12:15:34 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qnGSwbfzp9zTsFt2t49oUT-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[EU flags fly outside the union headquarters in Brussels, Belgium.]]></media:description>                                                            <media:text><![CDATA[EU flags fly outside the union headquarters in Brussels, Belgium.]]></media:text>
                                <media:title type="plain"><![CDATA[EU flags fly outside the union headquarters in Brussels, Belgium.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qnGSwbfzp9zTsFt2t49oUT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The European Commission has shelved plans to impose civil liability rules on enterprises using harmful <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>systems in a move critics have described as a “strategic mistake”. </p><p>First proposed in 2022, the AI Liability Directive aimed to overhaul existing rules on harmful AI systems and protect consumers. </p><p>However, the <a href="https://commission.europa.eu/strategy-and-policy/strategy-documents/commission-work-programme/commission-work-programme-2025_en" target="_blank"><u>publication of the Commission’s final work program</u></a> shows plans to introduce the rules will now be scrapped, noting that “no foreseeable agreement” has been reached by lawmakers. </p><p>The documents add that the Commission will “assess whether another proposal should be tabled or another type of approach should be chosen”.</p><p>The move comes in the wake of the <a href="https://www.itpro.com/technology/artificial-intelligence/uk-and-us-reject-paris-ai-summit-agreement-as-atlantic-rift-on-regulation-grows">AI Action Summit</a>, held in Paris, which saw industry stakeholders come together to discuss the future of <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a> innovation both across the European Union (EU) and globally. </p><p>During the summit, US vice president JD Vance voiced concerns over the EU’s supposed heavy handed regulatory approach to the technology. <a href="https://www.politico.eu/article/vp-jd-vance-calls-europe-row-back-tech-regulation-ai-action-summit/" target="_blank"><u>Vance urged European enterprises</u></a> and lawmakers to view the “new frontier of AI with optimism and not trepidation”. </p><p>“We want to embark on the AI revolution before us with the spirit of openness and collaboration, but to create that kind of trust we need international regulatory regimes that foster creation," he told attendees.</p><p>The liability directive was originally tabled alongside the <a href="https://www.itpro.com/technology/artificial-intelligence/eu-ai-act-everything-you-need-to-know-about-the-legislation-including-rules-requirements-and-who-will-be-forced-to-comply">EU AI Act</a>, but has since taken a backseat amid the push to impose the landmark legislation. </p><p>Some EU lawmakers have voiced their disapproval,. According to reports from <a href="https://www.euronews.com/next/2025/02/12/dont-drop-ai-liability-mechanism-lead-lawmaker-warns-commission" target="_blank"><u><em>Euronews</em></u></a>, Axel Voss, the EU Parliament’s lead representative for developing liability rules, described the move as a “strategic mistake”.</p><p>Voss told the publication the decision will lead to “legal uncertainty, corporate power imbalances, and a Wild West approach to <a href="https://www.itpro.com/security/data-breaches/threat-of-personal-liability-has-cisos-sweating">AI liability</a> that only benefits big tech”. </p><p>"The reality now is that AI liability will be dictated by a fragmented patchwork of 27 different national legal systems, suffocating European AI startups and SMEs,” he added.</p><iframe allow="" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/e72e3adf-5bdc-4be4-bfe8-51510b6b9843/"></iframe><h2 id="liability-directive-move-could-clean-up-patchwork-ai-regulation">Liability directive move could “clean up” patchwork AI regulation</h2><p>Peter van der Putten, director of <a href="https://www.itpro.com/technology/artificial-intelligence/pegasystems-ceo-alan-trefler-wants-to-help-enterprises-sift-through-the-ai-hype">Pegasystems</a>’ AI Lab and assistant professor at Leiden University, said that while the move may raise consumer protection concerns, the “impact may be relative” given new regulations such as the EU AI Act. </p><p>“The idea was that if a customer, citizen or business was claiming to have suffered harm, they wouldn’t have to prove in-depth causality between the AI system and the damage caused,” he explained. </p><p>“This would be more on the public or private organization operating the AI system (and/or underlying vendors).”</p><p>Ultimately, consumers and entities will still be protected against AI-related harms through the legislation, he noted, and the decision to shelve the proposals will create a more aligned regulatory environment. </p><p>“So whilst it is tempting to frame this all as a move towards less consumer protection in the global AI rat race, it can also just be seen as a sensible move to clean up the patchwork of AI regulation a bit, and not incite all kinds of litigation that in the end could either be resolved by existing regulation, or would likely not have been successful for claimants anyway,” van der Putten said. </p><h2 id="betting-on-a-blended-approach">Betting on a blended approach</h2><p>The decision to withdraw from the AI Liability Directive is being read by critics as the EU retreating on consumer protection in the face of AI companies.</p><p>While the EU AI Act contains protections for citizens and measures to monitor and control the harms of AI model deployment, it does not provide a direct route for consumers making claims against AI developers for damages such as algorithmic bias. </p><p>The AI Liability Directive was specifically designed to set out such a route, establishing concrete law on civil liability relating to AI and assisting consumers in making claims. </p><p>Timing is everything when it comes to the optics of a decision like this. In dropping the AI Liability Directive just one day after JD Vance’s warning that “excessive regulation” could kill AI innovation, the Commission could invite unwanted suggestions that it’s moving in lock-step with US approaches on AI.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="sN9hzieUPYt9YngAjVNAJK" name="Whitepaper_ DevSecOps is dead...or is it__" caption="" alt="Whitepaper: DevSecOps is dead...or is it?:" src="https://cdn.mos.cms.futurecdn.net/sN9hzieUPYt9YngAjVNAJK.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Snyk)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/devsecops-is-dead-or-is-it"><em>Integrate security into the development processes</em></a></p></div></div><p>But there’s every indication that rather than a reactive decision, this is more of a pragmatic move by the EU to maintain a handle on the AI sector. If it doesn’t keep its seat at the table by supporting EU-based AI developers and attracting investments from US tech giants, the EU Commission could lose any leverage it has over AI safety altogether.</p><p>The EU isn’t naïve and Vance’s statements on AI regulation wouldn’t have come as a surprise to anyone at the Paris Summit. As EU member states like France move to make the most of their established AI talent and the Commission gets more ambitious with its backing for AI infrastructure via its <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_25_467"><u>InvestAI initiative</u></a>, there will be more pragmatic decisions to come.</p><p>Attracting US investment, alongside home-grown talent, will be a necessity for the time being.</p><p>For the EU Commission’s part, it has stated that it saw “no foreseeable agreement” on the terms of the directive, adding “the Commission will assess whether another proposal should be tabled or another type of approach should be chosen”. </p><p>As yet, an alternative approach has not been officially put forward.</p><p>Ultimately, the EU may have made the bet that any reduced consumer power in the short term can be balanced out by regional success at AI advancement. If it can carve out a space for innovative AI that doesn’t infringe on inviolable rights, it could beat the US at its own game. </p><p>But it still has significant ground to make up, especially in comparison to the US and China.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/technology/artificial-intelligence/a-big-enforcement-deadline-for-the-eu-ai-act-is-just-around-the-corner#:~:text=The%20EU%20AI%20Act%20employs,human%20rights%2C%20or%20financial%20livelihood.">A big enforcement deadline for the EU AI Act just passed</a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/regulatory-uncertainty-is-holding-back-ai-adoption-heres-what-the-industry-needs-going-forward">Why regulatory uncertainty is holding back AI adoption</a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/why-ai-could-be-a-legal-nightmare-for-years-to-come">AI is going to be a legal nightmare for years to come</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The fractured regulatory landscape tech companies face in 2025 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/the-fractured-regulatory-landscape-tech-companies-face-in-2025</link>
                                                                            <description>
                            <![CDATA[ Sovereign data requirements and targeted legislation can be navigated with the right approach ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aGpHsshZAojpzGym2BCyWi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DLxjABjPkUcaH7dcPD3o2D-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 07 Feb 2025 12:32:32 +0000</pubDate>                                                                                                                                <updated>Fri, 07 Feb 2025 15:04:59 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keri Allan ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/oJZkdPii464j27ff4GCcoT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DLxjABjPkUcaH7dcPD3o2D-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An abstract map of the world overlaid with colorful geometric shapes, to represent the fractured regulatory landscape businesses face in 2025.]]></media:description>                                                            <media:text><![CDATA[An abstract map of the world overlaid with colorful geometric shapes, to represent the fractured regulatory landscape businesses face in 2025.]]></media:text>
                                <media:title type="plain"><![CDATA[An abstract map of the world overlaid with colorful geometric shapes, to represent the fractured regulatory landscape businesses face in 2025.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DLxjABjPkUcaH7dcPD3o2D-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The rise of data nationalism – when governments look to control data for security reasons – is leading to the creation of a patchwork of country or region-specific regulations that can add another layer of complexity to businesses’ global compliance. </p><p>The development of laws and regulations such as the <a href="https://www.itpro.com/business/policy-and-legislation/the-clock-is-ticking-for-firms-to-comply-with-the-eu-ai-act-heres-what-you-need-to-know"><u>EU AI Act</u></a> and the <a href="https://www.itpro.com/business/public-sector/government-says-new-data-bill-will-free-up-millions-of-hours-of-public-sector-time"><u>UK’s Data Use and Access Bill</u></a> reflects a growing recognition from governments that <a href="https://www.itpro.com/infrastructure/data-centres/data-centers-finally-get-critical-national-infrastructure-designation-in-the-uk"><u>data is a critical asset</u></a>, and has led to a growth in <a href="https://www.itpro.com/cloud/cloud-computing/what-is-a-sovereign-cloud"><u>data sovereignty</u></a> – where data is subject to the laws and regulations of the country where it’s collected or stored.</p><p>More often than not these new regulations mandate local data storage, but while being similar in their goals, there are often small differences in these laws’ data protection and cybersecurity frameworks. </p><h2 id="take-a-positive-view">Take a positive view</h2><p>These new regulations may feel like yet another burden IT leaders must shoulder but they show a maturing of the cybersecurity landscape. And while there is room for interpretation, leaders will find the main nuances are in enforcement and penalties.</p><p>“The laws aim to enforce more robust data sharing and resilient infrastructure, which is a change for the better,” notes Christian Have, CTO at IT security services provider Logpoint.</p><p>There are multiple ways to look at this growth of regional data regulations, says James Hodge, group vice president and chief strategy advisor at Splunk and member of the TechUK AI Committee. He recommends taking the view that it’s a positive thing for business.</p><p>“These kinds of frameworks give us concrete ways of working, give us certainty on how we should go about doing business in a specific country. So, I think that overall, we should take it as a very positive thing.”</p><h2 id="complying-with-region-specific-data-residency-requirements">Complying with region-specific data residency requirements </h2><p>Even so, it's impossible to ignore the new challenges organizations are facing due to this growth in data residency requirements.</p><p>New laws and policies may force organizations to fragment their data architecture, creating inefficiencies and redundancies notes Lauren Murphy, CEO of data consultancy Friday Initiatives, who also points to the challenge of aligning operations with varying legal definitions of data use, consent, and personal data and keeping up with evolving laws.</p><p>Then there’s the related cost burden. “Building localized infrastructure and hiring region-specific expertise increases operational costs significantly,” she says. </p><p>To meet the growing number of regional data regulations, forward-thinking companies are adopting dynamic, purpose-based frameworks, having acknowledged that traditional manual compliance programs no longer work. </p><p>These may include dynamic data profiling, which provides real-time visibility of data flows and use cases to ensure transparency and regulatory requirements, and purpose-based access controls that regulate data access and usage by aligning permissions with specific lawful purposes in different jurisdictions. </p><p>Murphy points to <a href="https://www.itpro.com/cloud/hybrid-cloud/security-and-compliance-concerns-are-driving-the-shift-to-hybrid-cloud">hybrid architectures</a> that combine centralized and decentralized systems to balance operational efficiency and localization needs, and cross-functional teams to bring together legal, technical, and business stakeholders to develop holistic strategies. There are also a multitude of tools and services available to help businesses collect, store, and analyze their data in line with regional regulations, Hodge says.</p><p>“We’re seeing data residency in software and management platforms to help track where data is stored and processed, and data localization technologies, typically with <a href="https://www.itpro.com/cloud/34476/what-is-multi-cloud">multi-cloud</a> architectures, the <a href="https://www.itpro.com/cloud/cloud-computing/aws-says-enterprises-are-moving-back-on-prem-but-does-cloud-repatriation-really-threaten-hyperscalers">hyperscalers</a>, and potential <a href="https://www.itpro.com/cloud/31389/what-is-edge-computing">edge computing</a>.</p><p>“I also think there’s a lot of opportunity in the automation and <a href="https://www.itpro.com/business-intelligence/28220/what-is-data-analytics">analytics</a> spaces,” he adds. </p><iframe allow="" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=62749338&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=true&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>Technologies like dynamic data mapping, AI-driven <a href="https://www.itpro.com/business/data-and-insights/data-governance-in-the-spotlight-as-uk-firms-ramp-up-ai-adoption"><u>data governance</u></a> tools and privacy-preserving methods like differential privacy streamline compliance with real-time insights and automation. Murphy champions context-aware governance tools that align data value with protection by integrating regulatory and business nuances in particular.</p><p>But while essential, experts agree that tools aren’t the full solution. They believe an organization’s data strategy should be about optimizing people, processes, and technology and gaining full visibility of your infrastructure to achieve the perfect balance between data value and protection.</p><p>Murphy advises focusing on starting small and scaling smart, integrated governance and human oversight. </p><p>“Pilot in critical areas before rolling out solutions broadly, and embed data policies and automation into daily workflows across departments," she says. "Don’t be naïve to think everyone in every role wants to be responsible for data governance because then it just won’t happen.</p><p>“Most tools can’t grasp legal nuances or adapt to business-specific rules, and even those that can you don’t want calling the shots; humans must drive strategic implementation.”</p><h2 id="shifting-mindsets-for-evolving-data-laws">Shifting mindsets for evolving data laws</h2><p>Many organizations are currently unequipped to handle the evolving data regulation landscape because of the way they approach compliance and require a shift in mindset. </p><p>Rather than approaching it as a checklist task, compliance should be integrated into any organization’s strategic priorities and treated as a driver of trust, operational efficiency, and value creation. This will be critical for long-term success says Murphy, as those organizations that adapt will not just comply but thrive in an increasingly <a href="https://www.itpro.com/business/business-strategy/keeping-up-with-the-compliance-landscape-in-2024">complex regulatory environment</a>.</p><p>“I don’t think you should look at regulation as a burden and compliance as a cost. It should be seen as just another project that needs to be done to address a market need. The most important thing is to ask what are the opportunities to come out of that compliance,” Hodge points out. </p><p>It’s also important for businesses to consider not only existing data laws and regulations but what’s also in the pipeline advises Will Richmond-Coggan, a partner in the data protection team at law firm Freeths. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="PVTgVkPVjkmkdMPBJBtHH7" name="Secure cloud best practices" caption="" alt="Secure cloud best practices" src="https://cdn.mos.cms.futurecdn.net/PVTgVkPVjkmkdMPBJBtHH7.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: AWS)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/secure-cloud-best-practices"><em>Strengthen your organization's cybersecurity</em></a></p></div></div><p>“In the next couple of years, we expect to see new rounds of legislation focused both on updating data protection rules to reflect better understanding of the range and extent of the data that these should apply to; and increasing regulation of emerging technologies, such as AI, which is often used to process such data.” </p><p>“I think there’s one thing we can say with almost 100 percent certainty and that’s there will be more legislation in data, cybersecurity, and AI,” agrees Hodge. “The more prepared you are as a business the faster you can respond – you can’t become agile unless you’re resilient first.</p><p>“By putting the hard work into understanding your digital infrastructure and developing an effective data strategy you’re building for the future rather than reacting to the latest regulation that comes out,” he concludes. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Governance, risk, and compliance is a major growth opportunity, but how will the market develop? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-and-legislation/governance-risk-and-compliance-is-a-major-growth-opportunity-but-how-will-the-market-develop</link>
                                                                            <description>
                            <![CDATA[ As DORA, NIS2, and AI regulations shake up the compliance landscape, GRC could be a golden opportunity for the channel ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Fc4FAqzX4KdpvvGe2iN8cF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/XeSkJPJvEUksmMKmBssuZW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 29 Jan 2025 08:39:15 +0000</pubDate>                                                                                                                                <updated>Thu, 24 Apr 2025 19:09:14 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ George Bonser ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Cgwvw3n5i8gb5NgaYPUFGh.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;George Bonser is an accomplished and highly successful sales professional with 20+ years of experience in enterprise sales and CXO engagement. Prior to Drata George Bonser was the VP Sales and GM EMEA at OpsRamp, and held senior positions at Okta, Inc.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/XeSkJPJvEUksmMKmBssuZW-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[GRC, Concept of Governance, Risk and Compliance. Company operates efficiently and ethically, complying with applicable regulations and laws.]]></media:description>                                                            <media:text><![CDATA[GRC, Concept of Governance, Risk and Compliance. Company operates efficiently and ethically, complying with applicable regulations and laws.]]></media:text>
                                <media:title type="plain"><![CDATA[GRC, Concept of Governance, Risk and Compliance. Company operates efficiently and ethically, complying with applicable regulations and laws.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/XeSkJPJvEUksmMKmBssuZW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The multi-billion governance, risk, and compliance (GRC) market is being driven by an increasingly complex regulatory environment, including <a href="https://www.itpro.com/security/data-protection/gdpr">GDPR</a>, <a href="https://www.itpro.com/cloud/cloud-computing/aligning-to-nis2-cybersecurity-risk-management-obligations-in-the-eu">NIS2</a>, and the Digital Operational Resilience Act (DORA) frameworks, among others.</p><p>At the same time, the growing integration of <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a> and automation technologies into GRC solutions is fueling adoption, as businesses see the benefits of applying digital transformation across their GRC strategies.</p><p>As we all know, the threat landscape continues to be extremely challenging. Cybersecurity and <a href="https://www.itpro.com/security/data-protection">data protection</a> breaches are increasingly followed by compliance enforcement action as authorities look to improve standards across the board.</p><p><a href="https://www.itpro.com/general-data-protection-regulation-gdpr/34665/gdpr-where-does-the-fine-money-go">Take GDPR, for example</a>, where <a href="https://www.enforcementtracker.com/?insights" target="_blank">cumulative compliance fines</a> burst through the €5 billion (£4.18 billion) barrier this year as part of a wider regulatory ecosystem where individual penalties can run into the millions.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="7xstTPfeX22UV2sBcQrbtn" name="217" caption="" alt="Three clouds supported by metal framework structure" src="https://cdn.mos.cms.futurecdn.net/7xstTPfeX22UV2sBcQrbtn.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/public-cloud/overcoming-devops-challenges-in-multi-cloud-environments">Overcoming DevOps challenges in multi-cloud environments</a></p></div></div><p>In addition, there’s also the potential compliance risks brought about by the integration of AI technologies into business processes. Here, issues such as data privacy, lack of transparency, and advanced tools that simply outpace existing regulatory frameworks are increasing the emphasis on compliance and whether organizations are keeping pace with their responsibilities.</p><p>Put these factors together and the results point to strong growth across the global <a href="https://www.itpro.com/technology/artificial-intelligence/building-a-strong-business-case-for-grc-automation">GRC</a> sector. Already worth more than $43 billion (£34.53 billion) this year, it is expected to accelerate significantly to surpass $111 billion (£89.13 billion) by 2032, according to <a href="https://www.fortunebusinessinsights.com/industry-reports/enterprise-governance-risk-and-compliance-egrc-market-101415" target="_blank">industry figures</a>. It’s not surprising that this is translating into significant and rapidly growing interest from the channel. </p><h2 id="the-road-ahead">The road ahead </h2><p>Clearly there is demand from customers across various sectors, many of whom share a sense of urgency around compliance and want to get a <a href="https://www.itpro.com/tag/data-governance">robust GRC strategy</a> in place – or at least update the technologies and processes they’re already relying on.</p><p>This translates into a significant opportunity for the channel, especially for those who are already specialists in cybersecurity. Whilst these are specific specializations in their own right, GRC and cybersecurity are clearly complementary. These firms should be well-positioned to drive GRC growth, including GRC as a service and virtual <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISO</a> offerings as these can be tailored to the specific requirements set out by NIS2, GDPR, and <a href="https://www.itpro.com/business/policy-and-legislation/dora-and-why-resilience-once-again-matters-to-the-board">DORA</a>, for example.</p><p>For resellers, <a href="https://www.itpro.com/security/guardz-launches-new-ultimate-plan-for-msps-with-integrated-sentinelone-edr">MSPs</a> and SIs there is a golden opportunity to build a service and product portfolio around that knowledge of the various essential compliance frameworks, leading them to engage in conversations with a wide range of customers on how they are preparing to step up their GRC efforts.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Jt8SiodKMVB5ZW8JcxPmgY" name="182" caption="" alt="Abstract big data picture spiral concept in blue on. black background" src="https://cdn.mos.cms.futurecdn.net/Jt8SiodKMVB5ZW8JcxPmgY.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/navigating-a-shifting-smb-channel-partner-paradigm">Navigating a shifting SMB channel partner paradigm</a></p></div></div><p>The availability of <a href="https://www.itpro.com/marketing-comms/business-communications/358483/nice-unveils-cloud-based-compliance-solution-for">centralized compliance platforms</a> will also help MSPs offer continuous monitoring and reporting services across customers’ business functions. These tools integrate data from various systems, such as cybersecurity, ITSM, or ERP tools, to provide a unified view of performance and potential vulnerabilities. At the same time, automated compliance workflows are growing in importance and, in many businesses, are already playing a major role in managing risk assessments, policies, and compliance audits.</p><p>There is also an important role for channel partners who can customize vendor solutions to meet sector-specific or regional requirements. Post-Brexit, for example, UK organizations that trade within the <a href="https://www.itpro.com/business/policy-legislation/369036/eu-to-introduce-strict-iot-security-regulation">EU</a> remain subject to various compliance requirements and as such, must design their processes and technology stack to address their obligations. Many of these businesses need the kind of expert guidance and experience that channel specialists are ideally placed to offer.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LwJQUwZFb66w8TQNw3yMh7" name="2024 Cloud Security Report" caption="" alt="2024 Cloud Security Report" src="https://cdn.mos.cms.futurecdn.net/LwJQUwZFb66w8TQNw3yMh7.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Fortinet)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/2024-cloud-security-report"><em>The latest insights on the trends driving cloud security</em></a></p></div></div><p>For instance, there has been growing demand for compliance solutions and a marked increase in the number of channel partners being onboarded. This is a trend we can expect to see accelerate further as organizations prioritize their compliance strategies, focus their investments and work more closely with service providers who can meet their needs. Ultimately, there is an opportunity for leaders in the field of <a href="https://www.itpro.com/business/is-there-any-future-for-the-it-helpdesk-ai-and-automation-could-render-it-redundant-within-three-years">AI and automation</a> to help steer <a href="https://www.itpro.com/security/bolstering-cyber-security-with-the-right-channel-partnerships">channel partners</a> to offer a risk-aware approach to compliance by harnessing the power of AI and automation.</p><p>Looking ahead to 2025 and beyond, the regulatory landscape will become even more complex. As a result, organizations will need to ensure their compliance efforts remain continually robust, in line with authorities moving from periodic to ongoing assessment. I anticipate that we’ll see a significant growth in channel partners focusing on their compliance offerings, including those who diversify their approach to help their clients integrate <a href="https://www.itpro.com/marketing-comms/business-communications/358483/nice-unveils-cloud-based-compliance-solution-for">compliance tools</a> seamlessly with other existing systems, streamline workflows, and ensure audit readiness.  </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A big enforcement deadline for the EU AI Act just passed – here's what you need to know ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence/a-big-enforcement-deadline-for-the-eu-ai-act-is-just-around-the-corner</link>
                                                                            <description>
                            <![CDATA[ The first set of compliance deadlines for the EU AI Act passed on the 2nd of February, and enterprises are urged to ramp up preparations for future deadlines. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nAVdzBbjirg8bjBEKEywfA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qnGSwbfzp9zTsFt2t49oUT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Jan 2025 13:40:25 +0000</pubDate>                                                                                                                                <updated>Wed, 19 Feb 2025 12:17:19 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ george.fitzmaurice@futurenet.com (George Fitzmaurice) ]]></author>                    <dc:creator><![CDATA[ George Fitzmaurice ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/N4xHCjSAXKcijjt3oiQtfc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qnGSwbfzp9zTsFt2t49oUT-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[EU flags fly outside the union headquarters in Brussels, Belgium.]]></media:description>                                                            <media:text><![CDATA[EU flags fly outside the union headquarters in Brussels, Belgium.]]></media:text>
                                <media:title type="plain"><![CDATA[EU flags fly outside the union headquarters in Brussels, Belgium.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qnGSwbfzp9zTsFt2t49oUT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The first of a number of enforcement actions for the <a href="https://www.itpro.com/business/policy-and-legislation/how-the-eu-ai-act-compares-to-other-international-regulatory-approaches">EU AI Act</a> have officially come into effect, and experts have warned firms should accelerate preparations for the next batch of deadlines. </p><p><a href="https://www.itpro.com/technology/artificial-intelligence/eu-ai-act-everything-you-need-to-know-about-the-legislation-including-rules-requirements-and-who-will-be-forced-to-comply">Passed in March last year</a>, the first elements of the EU’s landmark legislation came into effect on the 2nd February 2025, bringing with it a series of rules and regulations that AI developers and deployers must adhere to. </p><p>The EU AI Act employs a risk-based approach to assessing the potential impact of <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a> systems, designating them as being minimal, limited, or high-risk. High-risk systems, for example, are those defined as posing a potential threat to life, human rights, or financial livelihood. </p><p>These particular systems are in the crosshairs following the introduction of the new rules this month. </p><p>Speaking to <em>ITPro</em> ahead of the deadline, Enza Iannopollo, principal analyst at Forrester, said lawmakers specifically chose to target the most dangerous AI use cases with the first round of rules. </p><p>“Requirements enforced on this deadline focus on AI use-cases the EU considers pose the greatest risk to core Union values and fundamental rights, due to their potential negative impacts,” Iannopollo said.</p><p>“These rules are those related to prohibited AI use-cases, along with requirements related to AI literacy. Organizations that violate these rules could face severe fines — up to 7% of their global turnover — so it’s crucial that requirements are met effectively,” she added.</p><p>Iannopollo noted that fines will not be issued immediately, however, as details about sanctions are still a work-in-progress and the authorities in charge of enforcement are still not in place. </p><p>While there may not be any big fines in the headlines in the next few months, Iannopollo said this is still an important milestone.</p><p>Tim Roberts, UK country co-leader at AlixPartners, said the first set of compliance obligations will act similarly to GDPR, mainly in that they will apply to any organization doing business with AI models in Europe. </p><p>With this in mind, it’s critical that companies are aware of these first batch of rules, even if they are not EU-based. </p><p>“Naturally, this also reignites the debate about striking the right balance between innovation and regulation. But instead of seeing them as opposing forces, it’s more useful to think of them as two things we need to get right in parallel … because regulation can be a facilitator of innovation - not a blocker,” Roberts said.  </p><p>“The speed at which AI is advancing has caused discomfort for some consumers, but strong safeguards can build trust and create a thriving (and fairer) environment for greater business innovation. </p><p>“The EU AI Act is an important first step in this journey, and its success will depend on how well it is applied and how well it evolves, with the end goal being smarter regulation that drives businesses to continue pushing boundaries for the benefit of all.”</p><h2 id="eu-ai-act-firms-should-tighten-up-risk-assessments">EU AI Act: Firms should tighten up risk assessments </h2><p>Due to the global reach of the Act and the fact that requirements span the entire AI value chain, Iannopollo said enterprises must ensure they adhere to the regulation. </p><p>“The EU AI Act will have a significant impact on AI governance globally. With these regulations, the EU has established the ‘de facto’ standard for trustworthy AI and AI risk management,” she added.</p><p>To prepare for the rules, enterprises are advised to begin refining risk assessment practices to ensure they’ve classified AI use cases in line with the designated risk categories contained in the Act. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="XHwXjqsAzm6yMEXvN6seNV" name="Protect your organization with Microsoft 365" caption="" alt="Protect your organization with Microsoft 365" src="https://cdn.mos.cms.futurecdn.net/XHwXjqsAzm6yMEXvN6seNV.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: CDW | Microsoft)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/protect-your-organization-with-microsoft-365"><em>Implement the right Microsoft 365 solution</em></a></p></div></div><p>Systems that would fall within the ‘prohibited’ category need to be switched off immediately.</p><p>“Finally, they need to be prepared for the next key deadline on 2nd August. By this date, the enforcement machine and sanctions will be in better shape, and authorities will be much more likely to sanction firms that are not compliant. In other words, this is when we will see a lot more action.”</p><iframe allow="" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/e72e3adf-5bdc-4be4-bfe8-51510b6b9843/"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>