EU targets AWS and Azure under the DMA

The European Commission has informed Amazon and Microsoft of its preliminary view that their cloud computing services, Amazon Web Services and Microsoft Azure, should be designated as gatekeepers under the Digital Markets Act.

The move could extend the DMA’s reach into cloud infrastructure, a sector the Commission describes as critical to Europe’s digital economy and AI development.

The Commission opened market investigations into AWS and Azure in November 2025. It has now been provisionally concluded that both services act as important gateways between businesses and customers in the EU, despite not meeting the DMA’s standard quantitative thresholds.

According to the Commission, AWS and Azure benefit from large and established user bases, high switching costs, loyalty effects, broad cloud ecosystems and long-standing market positions. It also said their AI tool portfolios and partnerships are becoming increasingly important for cloud customers.

Amazon and Microsoft now have the opportunity to examine the investigation files and respond to the preliminary findings. If the Commission confirms its assessment, AWS and Azure would be designated as gatekeepers, and the companies would have six months to comply with DMA obligations.

The Commission said fair and competitive cloud markets are important for secure, sustainable and interoperable cloud services in Europe. It also linked the case to Europe’s wider technological sovereignty objectives, as cloud infrastructure underpins AI systems, enterprise software and public services.

Why does it matter?

The case shows how the EU competition policy is moving deeper into the infrastructure behind the AI economy. Cloud platforms are no longer just business services; they shape access to compute, data, AI tools, software ecosystems and switching options for companies and public institutions. If AWS and Azure are designated as DMA gatekeepers, the decision could affect cloud interoperability, customer lock-in and the balance of power between US hyperscalers and European cloud providers.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

EDPB updates right to erasure case digest

The European Data Protection Board has updated its one-stop-shop case digest on the GDPR rights to erasure and to object.

The digest is based on final one-stop-shop decisions from the EDPB’s public register under Article 60 of the GDPR. It presents key decisions on a specific theme and provides aggregate findings from relevant cross-border cases.

The updated digest focuses on how data protection authorities assess the internal processes organisations use to comply with erasure requests and objections to processing.

It also lists frequent infringements and provides an overview of corrective measures issued by data protection authorities. Cases include objections to direct marketing and requests by individuals to delete accounts or online data profiles.

The update reflects hundreds of new one-stop-shop decisions adopted by data protection authorities since the original digest was finalised.

The digest was developed under the EDPB’s Support Pool of Experts programme, which supports cooperation among European data protection authorities by providing expertise and enforcement tools.

Why does it matter?

The right to erasure and the right to object are among the GDPR rights most directly used by individuals to control how organisations handle their personal data. The updated digest can help regulators and organisations understand how data protection authorities apply these rights in practice, especially in cross-border cases. It also supports more consistent GDPR enforcement by highlighting recurring infringements, procedural weaknesses and corrective measures.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

Greek supercomputer DAEDALUS enters global supercomputer rankings

Greece’s DAEDALUS supercomputer has entered the international TOP500 and Green500 rankings, strengthening the country’s position in Europe’s high-performance computing landscape.

The system ranked 31st in the TOP500 list of the world’s most powerful supercomputers and 23rd in the Green500 list of energy-efficient systems. According to GRNET, DAEDALUS recorded a measured performance of 85.69 petaflops, making it the most powerful computing system ever ranked in Greece.

DAEDALUS is based on Hewlett Packard Enterprise architecture and uses NVIDIA GH200 accelerators. It also uses direct liquid cooling, combining high computing performance with energy efficiency.

The supercomputer and its data centre are located at the Lavrio Technological and Cultural Park of the National Technical University of Athens, inside the former Power Station building.

Once fully operational, DAEDALUS is expected to support researchers, universities, industry and public authorities working on demanding computational tasks. These include AI, cybersecurity, personalised healthcare, climate research, public administration and large-scale data analytics.

The system will also serve as the computational core of PHAROS, Greece’s national AI Factory under the European AI Factories initiative. Through PHAROS, Greece aims to expand access to AI infrastructure and support the development of AI applications across research, business and the public sector.

The project forms part of Greece’s wider digital transformation agenda and contributes to European efforts to strengthen technological capacity, AI infrastructure and digital sovereignty through high-performance computing.

Why does it matter?

DAEDALUS gives Greece strategic computing capacity for AI research, scientific modelling and public-sector digital transformation. Its role in PHAROS also links national supercomputing infrastructure to the EU’s AI Factories initiative, which aims to give researchers and companies access to advanced computing resources for AI development. The Green500 ranking matters as well, because Europe’s AI infrastructure push increasingly depends not only on raw performance, but also on energy efficiency and sustainable data-centre design.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!  

Canadian cybersecurity agency warns AI is reshaping cyber threats

Canada’s Centre for Cyber Security has warned that frontier AI models are rapidly transforming the cyber threat landscape, reducing the time organisations have to detect, contain and respond to attacks.

According to the Cyber Centre, AI is enabling cybercriminals to identify vulnerabilities, automate complex attack chains and generate increasingly convincing phishing campaigns, deepfakes and voice impersonation attacks at unprecedented speed and scale.

The advisory follows a joint statement by the Five Eyes cybersecurity agencies urging organisations worldwide to strengthen cyber resilience before AI-enabled attacks evolve into major operational, financial and national security incidents.

The Cyber Centre also highlights internal risks associated with unapproved AI use, including the exposure of sensitive information and reliance on inaccurate or manipulated AI-generated outputs.

Rather than viewing AI solely as a source of risk, the Cyber Centre encourages organisations to integrate frontier AI into cybersecurity operations. AI can help identify vulnerabilities earlier in software development, strengthen secure-by-design practices, improve security monitoring and accelerate incident detection and response.

The guidance emphasises that fundamental cyber hygiene, including timely patching, phishing-resistant multi-factor authentication, network segmentation, centralised logging and regularly tested incident response plans, remains essential despite rapid advances in AI capabilities.

Why does it matter?

The guidance reflects a shift in cybersecurity from preparing for future AI risks to responding to immediate operational challenges. As frontier AI enables attackers to identify vulnerabilities, automate exploitation and produce more sophisticated phishing and social engineering campaigns, organisations may have less time to detect and contain incidents.

The advisory also reinforces an emerging consensus among the Five Eyes partners that AI should be treated as both a cyber risk and a defensive capability. Alongside robust governance and responsible AI use, organisations are increasingly expected to combine AI-enabled security tools with strong cyber hygiene, secure-by-design practices and resilient incident response capabilities to keep pace with a rapidly evolving threat landscape.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!  

EU targets cross-border crime cooperation

The European Commission has proposed new measures to strengthen EU cooperation against cross-border crime, organised criminal networks, terrorism and hostile actors.

The Commission said crime is becoming more sophisticated, international and digital, requiring closer cooperation between police, customs authorities, prosecutors and courts from the start of investigations through to final judgments.

The package would strengthen the roles of Europol and Eurojust, the EU agencies that support national authorities in cross-border criminal investigations and judicial cooperation.

For Europol, the proposal would enable faster and more automated information sharing to support real-time collaboration during investigations. It would also create Europol Support Offices, staffed by former Europol officers, to provide operational assistance to the EU countries.

The Commission also wants to establish a technology and innovation hub within Europol to map law enforcement capability needs across the EU and support the use of new tools against cross-border crime.

Eurojust would receive stronger operational powers, including the ability to act on its own initiative to identify links between cases. Its mandate would also expand into emerging areas of crime, including cybercrime and gender-based violence.

The package would strengthen cooperation between Europol, Eurojust and the European Public Prosecutor’s Office, while also expanding international cooperation with third countries.

The Commission is also proposing to update the European Investigation Order, the EU procedure for gathering evidence across borders in criminal cases. A new European Remote Participation Order would allow suspects, accused persons and victims to take part remotely in criminal court hearings from another EU country.

Why does it matter?

Cross-border crime is increasingly digital and difficult for national authorities to tackle on their own. The Commission’s proposal aims to make EU investigations faster and more coordinated by improving data sharing, evidence gathering and cooperation between police, prosecutors and courts. The cybercrime and technology-hub elements are especially relevant because law enforcement agencies need technical capacity, legal tools and cross-border coordination to respond to digital criminal networks.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

EU funds first regional hubs to protect undersea cables

The European Commission has announced funding for the first two Regional Cable Hubs in the Baltic and Mediterranean seas as part of a broader effort to strengthen the protection of Europe’s critical undersea infrastructure. The initiative aims to improve coordination in monitoring and responding to risks affecting submarine communication and energy cables.

Alongside the €5.8 million allocated to establish the hubs, the Commission has launched a €40 million funding call to expand Europe’s capacity to repair damaged submarine cables. The measures form part of the EU Action Plan on Cable Security, which aims to improve resilience against both physical and cyber threats affecting critical data and energy infrastructure.

The programme is intended to enhance the EU’s ability to detect incidents earlier and coordinate rapid responses across member states. Officials say the initiative will also strengthen cross-border cooperation among countries facing shared security challenges in strategically important maritime regions.

Executive Vice-President Henna Virkkunen said the project reflects Europe’s commitment to improving security and sovereignty by investing in stronger infrastructure resilience. The new hubs are expected to act as coordination centres for faster incident response, improved preparedness and enhanced situational awareness in the face of emerging threats.

Why does it matter?

Submarine cables are a critical component of modern digital and energy infrastructure, carrying the vast majority of international internet traffic while also supporting financial transactions, cloud services and cross-border energy connectivity. Disruptions to these networks can have immediate economic, security and operational consequences that extend far beyond the affected region.

The initiative also reflects a broader shift in European security policy. As concerns grow over geopolitical tensions, hybrid threats and infrastructure sabotage, the EU is increasingly treating undersea cables as strategic assets that require coordinated protection, monitoring and rapid repair capabilities. Strengthening resilience in these networks is becoming an important element of Europe’s broader agenda on digital sovereignty, critical infrastructure security and collective resilience.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our chatbot!

Spain moves closer to hosting one of Europe’s first AI gigafactories

Spain has taken another significant step in its effort to become a leading European hub for AI and advanced computing infrastructure.

The Council of Ministers has approved a €300 million voluntary contribution to the European High Performance Computing Joint Undertaking (EuroHPC), the body responsible for supporting Europe’s AI factories and the future development of AI gigafactories.

According to the Ministry for Digital Transformation and Public Administration, the contribution is a critical component of Spain’s bid to host one of the EU’s first AI gigafactories.

The government argues that access to large-scale computing infrastructure is becoming essential for researchers, universities, startups and businesses seeking to develop advanced AI systems and remain competitive in an increasingly AI-driven economy.

The investment builds on Spain’s existing role within Europe’s supercomputing ecosystem. The country already hosts AI factories at the Barcelona Supercomputing Center and the Galician Supercomputing Center, while the MareNostrum 5 supercomputer has supported projects ranging from genomic research to climate and digital twin initiatives.

The funding also aims to strengthen Spain’s position in quantum technologies, an area increasingly viewed as strategically important for Europe’s long-term technological autonomy.

The announcement reflects a wider European push to expand sovereign computing capabilities as demand for AI training infrastructure grows worldwide.

By seeking to host an AI gigafactory, Spain hopes to attract investment, support innovation, strengthen domestic technological capabilities and position itself as a central player in Europe’s next-generation AI ecosystem.

Why does it matter?

Access to large-scale computing infrastructure is becoming a strategic prerequisite for advanced AI development. Training frontier AI models, running large-scale simulations and supporting scientific research require computing resources that are increasingly concentrated among a small number of global technology providers. Spain’s investment seeks to strengthen both national and European capacity in this critical area.

The announcement also reflects the EU’s broader push for technological sovereignty. By expanding domestic AI and supercomputing infrastructure, Europe aims to reduce dependence on foreign computing resources, support innovation ecosystems and ensure that advanced technologies are developed within frameworks aligned with European values, regulations and industrial priorities. The competition to host AI gigafactories is therefore as much about economic competitiveness and strategic autonomy as it is about computing power.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

FIFA World Cup 2026 faces growing AI and cybersecurity threats

The FIFA World Cup 2026 is not only a football tournament. It is one of the largest digital security tests ever associated with a global public event.

With 48 teams, 104 matches and 16 host cities spread across the USA, Canada and Mexico, the ongoing tournament creates a vast network of stadium systems, ticketing platforms, broadcasters, hotels, transport providers, mobile applications, public Wi-Fi networks, payment systems, and connected devices.

The scale of digital interconnection is unprecedented in the history of international sport.

The Canadian Centre for Cyber Security has warned that the event will almost certainly attract cybercriminals, state-sponsored actors and other threat groups because of its visibility, infrastructure complexity, and broad supplier ecosystem.

Similar concerns have been raised by cybersecurity researchers, government agencies and intelligence analysts, all of whom view the tournament as a high-value target.

Canada warns FIFA World Cup 2026 could face cyberattacks, scams and AI-driven disinformation.

What makes the World Cup 2026 particularly significant is the growing role of AI.

AI will support crowd management, threat detection, cybersecurity operations, content moderation, logistics planning, and fan engagement. Ironically, the same technologies will provide attackers with powerful new tools to automate phishing campaigns, generate convincing deepfakes, conduct fraud operations and spread disinformation at an unprecedented scale.

Perhaps paradoxically, the result is a tournament where AI functions simultaneously as a defensive capability and an offensive weapon.

The largest entertainment attack surface in history

Cybersecurity experts have described the FIFA World Cup 2026 as the ‘largest global entertainment attack surface in history’. The description reflects not only the size of the tournament but also the complexity of its digital ecosystem.

Every match involves interactions between permanent stadium infrastructure, temporary commercial suppliers, cloud service providers, telecommunications operators, transportation networks, emergency services, broadcasters, and millions of fans. Unlike previous tournaments, many of these systems are deeply integrated through digital platforms and real-time data exchanges.

Researchers have noted that the attack surface extends far beyond FIFA’s own networks. Airlines, hotels, payment processors, media organisations, local authorities, ride-sharing platforms and tourism providers all become part of the broader security environment. A successful attack on any of these entities could create disruption that affects the tournament itself.

The Center for Strategic and International Studies (CSIS) has divided the World Cup attack surface into three layers. The first includes direct tournament infrastructure such as stadiums, ticketing systems, and broadcasting operations.

The second includes supporting infrastructure such as telecommunications networks, transportation systems and cloud providers. The third consists of millions of individual devices belonging to players, officials, journalists, sponsors and supporters.

Consequently, a cyber incident does not need to compromise FIFA directly to have significant consequences. A ransomware attack affecting a hotel chain, a denial-of-service attack against a transportation provider, or a breach of a ticketing partner could undermine public confidence and create operational disruption in multiple host cities.

AI-driven cybercrime and financial fraud

The most immediate threat facing supporters is financially motivated cybercrime. Major sporting events have historically attracted fraud schemes, but AI significantly increases their sophistication and reach.

Criminal groups are expected to exploit public interest through phishing campaigns, social engineering operations, fake ticket sales, fraudulent travel packages, malicious mobile applications and counterfeit livestreaming services.

The Canadian Centre for Cyber Security highlighted research indicating that more than 4,300 suspicious World Cup-related domains had already been identified by August 2025.

Generative AI allows attackers to produce convincing communications in multiple languages within seconds. Emails can imitate official FIFA announcements, airline notifications, hotel confirmations or ticketing updates with remarkable accuracy. AI-generated text can eliminate many of the grammatical errors that have traditionally exposed phishing attempts.

The personalisation capabilities of AI further increase effectiveness. Information gathered from social media profiles can be used to create tailored messages targeting specific individuals.

A supporter who has publicly discussed attending a World Cup match may receive a realistic-looking email containing details of a stadium, flight, or accommodation booking.

Cybersecurity researchers also warn about AI-powered chatbots designed to engage victims in extended conversations, gradually building trust before directing them towards malicious websites or fraudulent payment portals.

Such attacks represent an evolution beyond traditional phishing because they can adapt dynamically to the victim’s responses.

Deepfakes, disinformation and information warfare

One of the most significant AI-related concerns surrounding the World Cup is the potential use of deepfake technology and synthetic media.

Deepfakes can generate highly realistic audio, video, and images depicting events that never occurred. During a tournament watched by billions of people, such content could spread rapidly before verification mechanisms have time to respond.

 Ball, Football, Soccer, Soccer Ball, Sport, Adult, Male, Man, Person, Computer, Electronics, Laptop, Pc, Cup, Screen, Computer Hardware, Hardware, Accessories, Formal Wear, Tie, Monitor, Phone, Electrical Device, Microphone, Mobile Phone, Book, Publication, Blackboard, People, Face, Head, Gianni Infantino, Lionel Messi

A fabricated video appearing to show a national team manager criticising players, a fake government announcement warning of security threats, or an AI-generated recording supposedly involving FIFA officials could create confusion and damage reputations.

Even brief circulation of false information may influence public perception, financial markets, or security decisions.

Threat actors are very likely to employ AI-generated articles, images and videos during the World Cup tournament. Furthermore, state-sponsored influence operations remain possible, particularly if geopolitical tensions involving participating nations intensify.

The risk is not limited to political manipulation. Criminal groups may use deepfakes to support fraud operations, impersonate public figures or create fake emergency announcements designed to generate panic.

The speed of modern social media platforms means that misleading content can reach millions of users before fact-checking efforts can become effective.

The World Cup, therefore, represents a major test for digital information resilience. Governments, media organisations and technology platforms will need rapid verification capabilities to distinguish authentic content from increasingly sophisticated synthetic media.

Critical infrastructure and operational technology risks

The World Cup’s dependence on critical infrastructure creates another layer of cybersecurity concern.

Electricity grids, water systems, telecommunications networks, transportation infrastructure and emergency communications all support tournament operations. Any disruption affecting these systems could have consequences extending far beyond football matches.

Security researchers have warned that operational technology environments often remain less protected than traditional information technology networks. Many infrastructure systems were designed decades ago, long before cybersecurity became a primary concern.

As digital connectivity expands, vulnerabilities within such systems become increasingly attractive targets.

A cyber-attack on public transportation networks could delay tens of thousands of supporters travelling to World Cup matches. Disruptions affecting telecommunications systems could interfere with emergency coordination, media coverage and public communications.

Attacks targeting stadium access systems could create safety concerns if spectators are unable to enter or exit venues efficiently.

The multinational structure of the tournament further increases its complexity. The US, Canada and Mexico operate under different legal frameworks, cybersecurity standards and regulatory environments.

Effective protection, therefore, requires unprecedented levels of coordination between public authorities and private sector partners in the three countries.

Protecting fan data and digital identities

The FIFA World Cup generates enormous volumes of personal data. Ticket purchases, accommodation bookings, transportation arrangements, mobile applications, loyalty programmes and payment systems all collect information about supporters.

Such datasets are highly attractive to cybercriminals. Personal information can be used for identity theft, financial fraud, account takeovers or targeted phishing campaigns. The concentration of large numbers of international visitors further increases the value of collected data.

Digital ticketing systems present both opportunities and risks. While electronic tickets reduce certain forms of fraud and improve operational efficiency, they also create new attack vectors. Compromised accounts, stolen credentials and fake ticket marketplaces can all exploit digital ticketing ecosystems.

The use of biometric technologies introduces additional challenges. Facial recognition systems may be employed for security screening, venue access or identity verification. Although such technologies can improve efficiency and security, they also raise questions about privacy, consent, data retention, and oversight.

 Person, Electronics, Mobile Phone, Phone, Adult, Male, Man, Computer Hardware, Hardware, Monitor, Screen, Guard, Face, Head, Mattia De Sciglio

Maintaining public trust requires transparency regarding how personal information is collected, stored, and protected. Strong cybersecurity measures must be accompanied by clear governance frameworks and accountability mechanisms.

Online abuse and AI moderation

Cybersecurity during the World Cup extends beyond technical attacks. Online abuse, harassment and hate speech represent significant digital risks affecting players, officials and supporters.

Experience from previous tournaments illustrates the scale of the problem. FIFA reported that one in five players participating in the 2023 Women’s World Cup experienced online abuse. Through the Social Media Protection Service, nearly 117,000 comments were hidden or blocked during the competition. Almost half of the abusive messages were classified as sexist, sexual, or homophobic.

The scale of online interaction surrounding the men’s World Cup is expected to be substantially larger. Social media platforms, therefore, face significant pressure to prevent abuse while preserving legitimate expression.

Ofcom has already warned platforms about their responsibilities under the UK Online Safety Act. The regulator expects companies to maintain effective reporting systems, sufficient moderation resources and rapid responses to illegal content.

Tech companies face scrutiny during the FIFA World Cup as Ofcom monitors compliance.

AI will play a central role in content moderation efforts.

Machine learning systems can analyse vast quantities of user-generated content and identify harmful material much faster than human moderators alone. However, AI moderation remains imperfect. Algorithms may struggle with sarcasm, cultural context, local languages or rapidly evolving forms of abuse.

Balancing safety and freedom of expression will remain one of the most challenging governance issues during the World Cup.

AI as a cybersecurity enabler

Despite the risks, AI has become an essential component of modern cybersecurity strategies.

Security operations centres generate enormous volumes of alerts, logs and threat intelligence data. Human analysts alone cannot process this information effectively. AI enables organisations to identify patterns, prioritise risks, and respond more rapidly to emerging threats.

Machine learning systems can detect unusual network behaviour that may indicate malicious activity. AI tools can analyse phishing campaigns, identify fraudulent domains and uncover relationships between seemingly unrelated attacks.

cybersecyrity AI

Automated systems can isolate compromised devices and block suspicious traffic before significant damage occurs.

AI is also becoming increasingly important for threat intelligence. Security teams use machine learning models to analyse information from global threat feeds, identify emerging attack techniques and predict potential risks. During an event as large as the FIFA World Cup, such capabilities may provide critical advantages.

Beyond cybersecurity, AI supports broader security operations. Computer vision systems can monitor crowd movement, identify congestion points, and assist with emergency planning. Predictive analytics can help authorities allocate resources more effectively and improve incident response capabilities.

Nevertheless, AI should be viewed as a force multiplier rather than a replacement for human expertise. Automated systems can produce false positives, miss novel attack methods or be manipulated through adversarial techniques. Human oversight remains essential, particularly when decisions affect public safety and civil liberties.

International cooperation and long-term implications

The cybersecurity challenge facing the World Cup cannot be addressed by FIFA alone. Effective protection requires collaboration among governments, intelligence agencies, law enforcement organisations, cloud providers, telecommunications companies, stadium operators, and cybersecurity firms.

Information sharing will be particularly important. Threat intelligence must move rapidly across organisations and national borders. Attack indicators identified in one host city may become relevant to another within minutes.

 Adult, Male, Man, Person, Astronomy, Outer Space, Body Part, Hand, Globe, Planet, Handcuffs

The World Cup also serves as a preview of the future challenges facing large-scale public events. As AI becomes increasingly integrated into infrastructure, transportation, communications and security operations, future tournaments will become even more dependent on digital technologies.

The lessons learned from 2026 are therefore likely to influence cybersecurity planning for future Olympic Games, continental championships, political summits and other international gatherings.

Conclusion

The FIFA World Cup 2026 demonstrates how deeply sport has become intertwined with the digital world. Football remains the centrepiece of the tournament, but its success depends equally on cybersecurity, AI governance and operational resilience.

AI will help protect infrastructure, support threat detection, improve crowd management, and strengthen cyber defence capabilities. At the same time, it will enable more sophisticated phishing campaigns, more convincing deepfakes, more effective disinformation operations and increasingly personalised fraud schemes.

The central challenge is not whether AI should be used. The challenge is how it can be deployed responsibly, securely and transparently within one of the most complex public events ever organised.

Success will depend on balancing innovation with security, automation with human oversight and efficiency with public trust.

The real test for FIFA, host governments and technology providers will be resilience. Cyber incidents are almost inevitable given the scale and visibility of the tournament. What will matter most is the ability to detect threats quickly, limit disruption, recover effectively and maintain public confidence.

Ultimately, the FIFA World Cup 2026 may be remembered as the first truly AI-era World Cup, where cybersecurity, misinformation and digital resilience have become as important as events on the pitch.

As citizens, supporters and digital users, we each have a role to play in protecting the integrity of the information and technologies that increasingly shape our lives.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

Greece drafts national framework to implement the EU AI Act

Greece has opened a public consultation on a draft law to implement the EU AI Act and create a national framework for AI governance.

The Ministry of Digital Governance and Artificial Intelligence said the draft law has been under public consultation since 21 June 2026, with comments open until 6 July. The proposal aims to introduce the national mechanisms needed to apply the AI Act in Greece while supporting innovation, competitiveness and the protection of fundamental rights.

Under the draft law, the Hellenic Data Protection Authority would become the central market surveillance authority and national contact point for AI Act implementation. The Hellenic Telecommunications and Post Commission would act as the notifying authority for conformity assessment procedures.

The proposal would also establish an Artificial Intelligence Coordination and Expertise Centre to support the implementation of the new framework.

It would create an AI regulatory sandbox, allowing startups and small and medium-sized enterprises to develop and test innovative AI applications in real-world conditions with support from the state.

The draft law also introduces a complaint-handling mechanism, an administrative sanctions system and a unified registry of AI systems used by public-sector bodies. The registry is intended to strengthen transparency, accountability and public trust in government use of AI.

The proposal would also reinforce the role of Greece’s Artificial Intelligence Observatory in monitoring the implementation of the National AI Strategy.

Why does it matter?

Greece’s proposal shows how the EU AI Act is moving from Brussels-level legislation into national enforcement structures. The draft law would assign supervisory roles, create a national AI coordination centre, establish a regulatory sandbox and require a public-sector AI registry. Such measures could shape how AI systems are monitored, tested and deployed across both government and the private sector, while giving startups clearer pathways for compliance.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

Cloudflare and beehiiv add AI crawler controls for newsletter publishers

Cloudflare and beehiiv have added AI crawler controls to the beehiiv newsletter platform, giving publishers more visibility over how AI bots access their content.

The integration embeds Cloudflare’s AI Crawl Control technology into beehiiv, allowing newsletter operators to monitor AI crawler activity and decide whether to allow or block access to their work.

The companies said the tool is designed for creators choosing between two strategies: increasing discovery through AI search engines and agents, or protecting content archives for future monetisation and licensing opportunities.

The new dashboard will show which AI crawlers attempt to access a publisher’s content, which are blocked, and how much referral traffic those crawlers send back to the newsletter.

AI Crawl Control will be available to all beehiiv users in beta. beehiiv Max customers will also be able to block AI crawlers and set permissions for how their content is accessed across the AI ecosystem.

Cloudflare and beehiiv said the integration eliminates the need for publishers to manually manage technical settings, such as robots.txt files and firewall rules. The system is also expected to update as new AI crawlers emerge.

Why does it matter?

The partnership shows how AI content access is becoming a practical governance issue for smaller publishers, not only large media companies. As AI search engines and agents change how online content is discovered and reused, creators need tools to see who is crawling their work, what traffic is returned, and whether access supports or undermines their business model. The integration also reflects a broader shift towards permission-based content access in the AI era.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!