News and Insights

Practical updates on AI governance, workforce strategy, and digital resilience for EU organisations
Europe’s First Uber Robotaxi Still Has A Safety Operator France excludes OpenAI from cyber work Ten Days To Answer A European Production Order Your Vendor Can Leave You Holding The Provider Obligations UK growth: AI vendors, not AI users Two clouds. One jurisdiction. No regulator paused Astra. OpenAI did. US productivity up 1.4%, cause unproven Moldova’s GDPR law lands on 23 August

Stay ahead of AI change. Get practical updates from Future Prep direct to your inbox.

By subscribing you agree to receive Future Prep news. Unsubscribe any time.

Latest Insights

From the Future Prep blog

AI cyber risk shown as a high-tech security door undone by one unfastened basic bolt.

AI Cyber Risk: Why the Newest Threat Demands the Oldest Discipline

A joint Five Eyes statement reframes AI cyber risk as an immediate leadership responsibility on a months-not-years horizon. The defence is unglamorous basic hygiene plus AI-aware threat modelling. We translate it into the EU frame of NIS2, DORA and the AI Act, and the questions a board should ask now.
A vast machine line governed by a single small control desk, illustrating the governance debt of scaling AI.

Scaling AI Is The Easy Part

British AI use just hit a tipping point, and the same week a survey found one in five organisations had already had an AI incident. Adoption tipped; control did not. This is the governance debt that builds when AI moves from pilot to production, and how to stay ahead of
Two near-identical bound volumes set slightly out of alignment, illustrating Canada's privacy reform diverging from the GDPR.

Canada’s Privacy Reform: Familiar on the Surface, Divergent Underneath

Canada has tabled Bill C-36, a GDPR-style privacy overhaul. For organisations already under European rules it reads as convergence but works as divergence: a second regulator, second thresholds and a second set of rights to map across adequacy, automated decisions and transfers.
A dark secure gallery with four progressively protected bays and a single procurement dossier in the foreground representing graded sovereignty assessment.

CADA’s Four Sovereignty Levels Change How You Buy Cloud and AI

CADA defines four assurance levels for cloud and AI sovereignty, up to EU ownership at Level 3 and full supply-chain control at Level 4. The proposal is not law yet, but the levels already work as a scoring frame. Five procurement and due diligence changes to make this quarter.
Overhead view of a dark boardroom table with a loose folder and papers on the left, a strict four-tier document stack on the right, and a central diagram sheet connecting both sides.

Transatlantic AI Governance: Two Philosophies, One Control Map

In one week the US chose voluntary, standards-referenced AI oversight while the EU adopted CADA's graded sovereignty test. A deployer operating across both cannot run on a single mental model. Here is one control map, with two triggers per control, that answers the European and American regimes at once.
An engineer alone bears the full weight of building AI in-house, with supplier crates left unused behind.

So You Decided to Build. Now You Have to Govern It.

The moment you move from buyer to builder, provider obligations, auditability, logging and exit discipline become yours. Here is how a mid-market organisation keeps a proprietary or co-developed AI tool governable, without a large-firm budget, and where the Cyber Resilience Act starts to bite.

Latest News

Short updates

France excludes OpenAI from cyber work

French Budget Minister David Amiel said the state will hire sovereign AI providers such as Mistral to test public systems for security vulnerabilities, and that this excludes OpenAI. The decision came days after a breach at the tax authority affecting around 700,000 people. Jurisdiction is turning into a procurement filter, applied after an incident rather than in a strategy paper. Worth knowing which of your vendors would survive that filter.

UK growth: AI vendors, not AI users

Britain’s economy grew 0.4% in the second quarter and information and communication supplied almost half of it. Inside that, computer programming and consultancy rose 3.7%, computing and electronics manufacturing 10.7% year on year. So the measurable growth sits with the firms selling AI, not the firms using it. One economist attributes part of June’s rise to the World Cup and the weather. Adoption returns remain unmeasured.

Two clouds. One jurisdiction.

Ryanair has added Google Cloud on a five-year deal, sixteen days after renewing AWS for five years. Chief executive Eddie Wilson calls the dual-cloud strategy infrastructure resilience, and against outage risk it is. Jurisdictional exposure is a different question, and two US providers do not answer it. The two contracts also cover separate workloads rather than mirroring each other. Worth watching whether European boards start telling those two risks apart.

No regulator paused Astra. OpenAI did.

OpenAI says preliminary evaluations of Astra, an unreleased model, cannot rule out the Critical cybersecurity level under its own Preparedness Framework. It has paused internal work that fails the strengthened controls and added isolated testing, encrypted weights and universal monitoring. No regulator required this. For EU organisations the point is evidential: so far the only safety case that exists is the vendor’s own unverified reading, published before the model reaches any market.

US productivity up 1.4%, cause unproven

US nonfarm business productivity rose at a 1.4% annual rate in the second quarter, and 2.2% on the year. Output rose 1.7%, hours worked 0.3% and unit labour costs 1.3%. The release credits nothing to AI, because the series cannot separate one input from another. Revised figures follow on 3 September. Any AI business case leaning on this data is adding a claim the statistics do not carry.

Moldova’s GDPR law lands on 23 August

Moldova’s Law 195/2024 takes effect on 23 August, bringing GDPR-style duties and a regulator with fining powers. Ceilings are 1 million lei or 1% of turnover for documentation and processor failures, and 2 million lei or 2% for serious breaches. DLA Piper puts 2 million lei at roughly 104,000 euros. Fines phase in over three years. Controllers outside Moldova that serve or monitor people there have to appoint a local representative.

Scroll to Top