News and Insights

Practical updates on AI governance, workforce strategy, and digital resilience for EU organisations
Europe’s First Uber Robotaxi Still Has A Safety Operator France excludes OpenAI from cyber work Ten Days To Answer A European Production Order Your Vendor Can Leave You Holding The Provider Obligations UK growth: AI vendors, not AI users Two clouds. One jurisdiction. No regulator paused Astra. OpenAI did. US productivity up 1.4%, cause unproven Moldova’s GDPR law lands on 23 August

Stay ahead of AI change. Get practical updates from Future Prep direct to your inbox.

By subscribing you agree to receive Future Prep news. Unsubscribe any time.

Latest Insights

From the Future Prep blog

AI confidentiality risk shown as private desk notes exposed to a hidden public gallery through one-way glass.

The AI Confidentiality Risk Hiding in Your Everyday Tools

Two US rulings show that material run through public AI tools can lose privilege and confidentiality. For EU practitioners, contract terms, deployment environment and acceptable-use rules are the controls that decide whether sensitive work stays protected before the next dispute.
Single sheet ruled into six fields with a magnifying glass and an open leather volume beside it, illustrating the Annex III classification memo against the Commission's draft guidelines

Annex III Classification: 6 Critical Fields

The Commission's draft guidelines of 19 May 2026 set worked examples across all eight Annex III categories. The Annex III classification memo now has an external benchmark. Six fields make the call defensible before the 23 June consultation closes.
Balance scale weighing a single explanation sheet against a binder of paperwork, illustrating the right to explanation under Article 22 GDPR and Article 86 AI Act

Right to Explanation: 3 Critical Gaps

The Dutch DPA's consultation on the right to explanation closes on 26 May 2026. The draft reframes Article 22 GDPR and Article 86 AI Act obligations as a deliverable on demand, not paperwork. Three deployer gaps to close before the final guidance arrives in Q3 2026.
Wooden shipping crate held closed by two independent fasteners, illustrating the Europrivacy transfer tool stack under Article 46.

The Europrivacy Transfer Tool: What Changes in AI Procurement

The EDPB has confirmed Europrivacy as both a Data Protection Seal under Article 42(5) and as an Article 46 transfer tool when combined with binding and enforceable commitments. Five concrete updates to make to your procurement file this quarter, with a decision sheet as the operational companion.
Three sets of calipers measuring one metal workpiece on a workshop bench, illustrating cyber-capable AI compliance across three regimes.

Cyber-Capable AI Compliance: : Three Regimes – the Same Model

A frontier AI model that finds and exploits software vulnerabilities sits inside three legal regimes at once: NIS2, the AI Act and the CRA. For deployers that means three sets of obligations and three sets of audit risk. The fix is a single control map built now.
A speaker at a lectern with mouth closed while twelve journalists take notes, illustrating AI chatbot data leakage before any user input.

Hidden AI Chatbot Data Leakage Risk

A new UC Davis measurement study shows AI chatbot data leakage is now the default behaviour of the modern chatbot stack. Names, emails and prompt content leave for third parties before a question is asked. For revenue leaders, this is a supply chain problem.

Latest News

Short updates

France excludes OpenAI from cyber work

French Budget Minister David Amiel said the state will hire sovereign AI providers such as Mistral to test public systems for security vulnerabilities, and that this excludes OpenAI. The decision came days after a breach at the tax authority affecting around 700,000 people. Jurisdiction is turning into a procurement filter, applied after an incident rather than in a strategy paper. Worth knowing which of your vendors would survive that filter.

UK growth: AI vendors, not AI users

Britain’s economy grew 0.4% in the second quarter and information and communication supplied almost half of it. Inside that, computer programming and consultancy rose 3.7%, computing and electronics manufacturing 10.7% year on year. So the measurable growth sits with the firms selling AI, not the firms using it. One economist attributes part of June’s rise to the World Cup and the weather. Adoption returns remain unmeasured.

Two clouds. One jurisdiction.

Ryanair has added Google Cloud on a five-year deal, sixteen days after renewing AWS for five years. Chief executive Eddie Wilson calls the dual-cloud strategy infrastructure resilience, and against outage risk it is. Jurisdictional exposure is a different question, and two US providers do not answer it. The two contracts also cover separate workloads rather than mirroring each other. Worth watching whether European boards start telling those two risks apart.

No regulator paused Astra. OpenAI did.

OpenAI says preliminary evaluations of Astra, an unreleased model, cannot rule out the Critical cybersecurity level under its own Preparedness Framework. It has paused internal work that fails the strengthened controls and added isolated testing, encrypted weights and universal monitoring. No regulator required this. For EU organisations the point is evidential: so far the only safety case that exists is the vendor’s own unverified reading, published before the model reaches any market.

US productivity up 1.4%, cause unproven

US nonfarm business productivity rose at a 1.4% annual rate in the second quarter, and 2.2% on the year. Output rose 1.7%, hours worked 0.3% and unit labour costs 1.3%. The release credits nothing to AI, because the series cannot separate one input from another. Revised figures follow on 3 September. Any AI business case leaning on this data is adding a claim the statistics do not carry.

Moldova’s GDPR law lands on 23 August

Moldova’s Law 195/2024 takes effect on 23 August, bringing GDPR-style duties and a regulator with fining powers. Ceilings are 1 million lei or 1% of turnover for documentation and processor failures, and 2 million lei or 2% for serious breaches. DLA Piper puts 2 million lei at roughly 104,000 euros. Fines phase in over three years. Controllers outside Moldova that serve or monitor people there have to appoint a local representative.

Scroll to Top