News and Insights

Practical updates on AI governance, workforce strategy, and digital resilience for EU organisations
Europe’s First Uber Robotaxi Still Has A Safety Operator France excludes OpenAI from cyber work Ten Days To Answer A European Production Order Your Vendor Can Leave You Holding The Provider Obligations UK growth: AI vendors, not AI users Two clouds. One jurisdiction. No regulator paused Astra. OpenAI did. US productivity up 1.4%, cause unproven Moldova’s GDPR law lands on 23 August

Stay ahead of AI change. Get practical updates from Future Prep direct to your inbox.

By subscribing you agree to receive Future Prep news. Unsubscribe any time.

Latest Insights

From the Future Prep blog

Tree splitting a boundary wall between two contrasting landscapes representing AI provider jurisdiction risk

Your AI Provider Just Got Blacklisted. Now What?

When your AI provider gets blacklisted in one country and courted by another, governance teams face a new risk category: AI provider jurisdiction risk.
Split desk scene representing AI data-sharing readiness between government and AI provider

When Governments Want Your AI Data

The Australia-Anthropic MoU signals a new regulatory pattern: governments negotiating direct access to AI usage data. EU governance teams should prepare now.
A hand hovering over a payment terminal beside a tablet showing abstract analytics, representing the governance question of who authorises action when AI systems can execute decisions.

From chatbot to agent: what changes when AI starts doing, not just saying

Starling Bank's AI moves money. Norway's sovereign wealth fund keeps humans in charge. Both are deploying agentic AI but with very different governance choices. Here is what changes when AI starts acting, not just recommending, and what your oversight framework must address.
A central junction block with three connected cables resting on contract, regulatory, and risk register documents, representing third-party AI vendor risk and supplier dependency.

When Your AI Vendor’s Market Power Becomes Your Governance Problem

The EU’s antitrust chief has put every layer of the AI stack under scrutiny. For organisations using major platforms, that scrutiny is now a vendor risk input; one that most governance programmes have not yet mapped. Here are three practical steps to close that gap.
EU sovereign cloud concept showing a padlock with EU stars on a glass server rack containing US-flagged hardware, with an unread contract beside it

EU Sovereign Cloud: What the Label Actually Means

The EU sovereign cloud label has no agreed legal definition. Before trusting a vendor’s sovereignty claim, practitioners should demand written answers to three questions about ownership, jurisdiction and certification.
AI-generated output ownership gap illustrated by a stamped document dissolving into blank paper on a desk

Who Owns What Your AI Produces?

The EU AI Act regulates AI inputs but says nothing about who owns the output. Most governance programmes have not addressed this gap. Here are four steps to close it.

Latest News

Short updates

France excludes OpenAI from cyber work

French Budget Minister David Amiel said the state will hire sovereign AI providers such as Mistral to test public systems for security vulnerabilities, and that this excludes OpenAI. The decision came days after a breach at the tax authority affecting around 700,000 people. Jurisdiction is turning into a procurement filter, applied after an incident rather than in a strategy paper. Worth knowing which of your vendors would survive that filter.

UK growth: AI vendors, not AI users

Britain’s economy grew 0.4% in the second quarter and information and communication supplied almost half of it. Inside that, computer programming and consultancy rose 3.7%, computing and electronics manufacturing 10.7% year on year. So the measurable growth sits with the firms selling AI, not the firms using it. One economist attributes part of June’s rise to the World Cup and the weather. Adoption returns remain unmeasured.

Two clouds. One jurisdiction.

Ryanair has added Google Cloud on a five-year deal, sixteen days after renewing AWS for five years. Chief executive Eddie Wilson calls the dual-cloud strategy infrastructure resilience, and against outage risk it is. Jurisdictional exposure is a different question, and two US providers do not answer it. The two contracts also cover separate workloads rather than mirroring each other. Worth watching whether European boards start telling those two risks apart.

No regulator paused Astra. OpenAI did.

OpenAI says preliminary evaluations of Astra, an unreleased model, cannot rule out the Critical cybersecurity level under its own Preparedness Framework. It has paused internal work that fails the strengthened controls and added isolated testing, encrypted weights and universal monitoring. No regulator required this. For EU organisations the point is evidential: so far the only safety case that exists is the vendor’s own unverified reading, published before the model reaches any market.

US productivity up 1.4%, cause unproven

US nonfarm business productivity rose at a 1.4% annual rate in the second quarter, and 2.2% on the year. Output rose 1.7%, hours worked 0.3% and unit labour costs 1.3%. The release credits nothing to AI, because the series cannot separate one input from another. Revised figures follow on 3 September. Any AI business case leaning on this data is adding a claim the statistics do not carry.

Moldova’s GDPR law lands on 23 August

Moldova’s Law 195/2024 takes effect on 23 August, bringing GDPR-style duties and a regulator with fining powers. Ceilings are 1 million lei or 1% of turnover for documentation and processor failures, and 2 million lei or 2% for serious breaches. DLA Piper puts 2 million lei at roughly 104,000 euros. Fines phase in over three years. Controllers outside Moldova that serve or monitor people there have to appoint a local representative.

Scroll to Top