WSIS Forum 2026
Rapport généré par l'IA

Making AI Safe in the Real World: From Governance Principles to Operational Tools

5 intervenants
Résumé

Résumé

Cette discussion portait sur le défi que représente la traduction des principes de gouvernance de l'IA en mise en œuvre concrète, en référence particulière à la Convention-cadre du Conseil de l'Europe sur l'IA, les droits de l'homme, la démocratie et l'état de droit (Convention 225, connue sous le nom de Convention de Vilnius) . Thomas Schneider a ouvert la séance en soulignant que des principes sans mise en œuvre ne restent que de simples aspirations, et que la session visait à explorer le fossé entre les engagements écrits et la pratique réelle . Il a ensuite expliqué que la logique fondamentale de la Convention n'est pas de réinventer les normes existantes en matière de droits de l'homme, mais de veiller à ce qu'elles s'appliquent dans les contextes où l'IA est déployée, tout en permettant à chaque pays de les mettre en œuvre selon ses propres traditions juridiques et institutionnelles . Il a également mis en avant la méthodologie Huderia comme un outil pratique à trois niveaux, développé en collaboration par des experts juridiques, techniques et académiques pour guider l'évaluation des risques et l'atténuation des impacts . Hoda Baraka a décrit l'expérience de l'Égypte comme un exemple concret d'un pays du Sud global passant de la stratégie à la pratique opérationnelle . L'Égypte a créé un Conseil national pour l'IA en 2019, élaboré deux éditions d'une stratégie nationale en matière d'IA, créé une Charte égyptienne pour une IA responsable, et fondé le Centre égyptien pour une IA responsable . L'Égypte a étudié 35 cadres de gouvernance, dont Huderia et la recommandation de l'UNESCO, afin de contextualiser une approche adaptée à sa propre culture et à ses institutions . Parmi les principales leçons tirées figurent l'intégration précoce d'une IA responsable, le traitement des marchés publics comme un outil stratégique de gouvernance, l'investissement dans le renforcement des capacités et la priorité accordée à la localisation . Peter Deussen a présenté le rôle complémentaire de l'ISO, en notant que les normes ISO/IEC portent sur la gestion des risques organisationnels et les processus de gouvernance, tandis que Huderia se concentre spécifiquement sur les impacts pour les individus et la société en lien avec les droits de l'homme, la démocratie et l'état de droit . Il a soutenu que rapprocher ces deux cadres pourrait aider les organisations à mettre en œuvre Huderia plus efficacement, les normes ISO fournissant un langage et des processus déjà familiers à l'industrie . Il a également identifié un manque d'orientations sur la manière dont les normes ISO peuvent être appliquées dans un contexte réglementaire ou d'élaboration de politiques . La discussion a conclu que le fossé entre les principes de gouvernance et la mise en œuvre concrète est comblable, à condition que les cadres normatifs, les normes techniques, le soutien financier et l'assistance technique soient combinés et poursuivis de manière collaborative .

Points clés
  • Points clés

  • Objectif général

  • La discussion avait pour objectif d'examiner comment les principes de gouvernance de l'IA peuvent être traduits en mesures concrètes, en allant au-delà des cadres théoriques et des instruments juridiques non contraignants. Elle a examiné plus précisément le rôle de la Convention-cadre du Conseil de l'Europe sur l'IA (Convention 225/Convention de Vilnius), l'expérience pratique de l'Égypte en matière de gouvernance de l'IA, et la contribution des normes techniques internationales pour combler le fossé entre les principes écrits et la pratique opérationnelle.
  • --
  • Principaux points de discussion

  • La Convention de Vilnius du Conseil de l'Europe comme ancrage normatif pour la gouvernance mondiale de l'IA. Thomas Schneider a expliqué que la convention ne réinvente pas les cadres existants en matière de droits de l'homme, mais veille à ce qu'ils s'appliquent dans les contextes liés à l'IA, quel que soit le système juridique d'un pays. Elle définit des principes et des mécanismes que les États doivent respecter tout en leur laissant une flexibilité quant aux modalités de mise en œuvre, créant ainsi une interopérabilité entre les différents systèmes nationaux. La convention est ouverte à tous les pays qui respectent les droits de l'homme, la démocratie et l'état de droit, et devrait générer une communauté de coopération plus large - à l'instar de la Convention de Budapest sur la cybercriminalité - une fois ratifiée. - Le parcours pratique de l'Égypte, des principes de gouvernance de l'IA à la mise en œuvre opérationnelle. L'Égypte a développé un « ensemble complet de gouvernance de l'IA responsable », en commençant par le Conseil national pour l'IA en 2019 et en progressant à travers deux éditions d'une stratégie nationale en matière d'IA, une Charte égyptienne pour une IA responsable, et la création du Centre égyptien pour une IA responsable. L'étude de 35 cadres de gouvernance internationaux, dont la Convention de Vilnius et la méthodologie Hudeira, a permis d'élaborer un cadre national localisé, fondé sur les risques et les droits. Parmi les principaux résultats concrets, on peut citer des lignes directrices relatives aux systèmes d'IA, un guide des marchés publics aligné sur les normes ISO, un guide sur la sécurité des enfants, ainsi qu'un grand modèle linguistique en arabe (Karnak) conçu pour s'adapter au contexte des pays arabes et africains - La méthodologie Hudeira comme pont pratique entre les principes et l'évaluation. Hudeira a été mise en avant comme particulièrement utile car elle fait passer la conversation de valeurs abstraites à une évaluation structurée et pratique, posant des questions concrètes sur le contexte, les parties prenantes et l'évaluation des impacts. Elle fonctionne à trois niveaux de détail - des fonctions générales à un guide de mise en œuvre sous forme de questionnaire de 80 pages - et a été développée en collaboration par des communautés juridiques, techniques, académiques et commerciales, testée sur des cas réels. L'Égypte a explicitement mis en correspondance les processus Hudeira avec les normes ISO pertinentes dans ses guides de marchés publics, permettant aux agents publics de comprendre quelles normes appliquer lors de l'acquisition de systèmes d'IA. - Le rôle complémentaire des normes internationales ISO/IEC pour combler les lacunes en matière de gouvernance technique. Peter Deussen a présenté les travaux du SC42 de l'ISO/IEC sur la gestion des risques liés à l'IA, une norme de système de management de la gouvernance (42001), et une nouvelle norme sur l'évaluation de l'impact des systèmes d'IA couvrant les impacts sur les individus et la société. Il a décrit les normes ISO et Hudeira comme complémentaires, l'ISO fournissant l'intégration des processus organisationnels et un langage compris par l'industrie, tandis que Hudeira se concentre sur les impacts relatifs aux droits de l'homme, à la démocratie et à l'état de droit. Une lacune clé identifiée est l'absence d'orientations sur la manière dont les normes ISO peuvent être utilisées dans un contexte réglementaire ou d'élaboration de politiques, un document de liaison ou de mise en correspondance étant suggéré comme une voie utile à suivre. - Le financement du développement et l'infrastructure de calcul comme dimensions critiques mais insuffisamment prises en compte de la mise en œuvre de la gouvernance de l'IA. Si l'assistance technique d'organismes tels que la Banque mondiale et la GIZ peut soutenir le renforcement des capacités, l'élaboration de politiques et la conception de programmes, le matériel informatique et l'infrastructure de calcul demeurent un défi majeur pour des pays comme l'Égypte. Le laboratoire d'audit de l'IA en Égypte est actuellement limité à des ordinateurs de bureau équipés de GPU plutôt qu'à un environnement sandbox complet basé sur le cloud en raison de contraintes de financement, et des mécanismes de financement alternatifs sont activement explorés. Le panel a noté que la dimension du financement du développement est rarement abordée dans les discussions sur la gouvernance de l'IA et l'a identifiée comme un domaine important nécessitant des sessions futures dédiées. ---
  • Ton général

  • Le ton général de la discussion était constructif, collaboratif et prudemment optimiste. D'emblée, les intervenants ont cadré la discussion comme étant de nature pratique et axée sur les solutions plutôt que théorique, Thomas Schneider donnant le ton en soulignant le fossé entre les principes et la mise en œuvre. Ayisha Piotti a maintenu tout au long un style de modération encourageant et inclusif, faisant ressortir des exemples concrets et valorisant les contributions. La contribution de l'Égypte, présentée par Hoda Baraka, a introduit un registre nettement ancré dans la réalité et franc - initialement positif et détaillé lors de la description des réalisations , mais évoluant vers un ton plus sobre lorsqu'il s'est agi d'aborder l'infrastructure de calcul et les contraintes de financement. Ce moment de franchise a apporté un réalisme bienvenu à ce qui avait été jusqu'alors un compte rendu optimiste des progrès accomplis.
  • La contribution de Peter Deussen était mesurée et technique, reconnaissant à la fois les points forts des travaux de normalisation existants et leurs lacunes, sans exagérer ni les uns ni les autres. Les remarques de clôture d'Ayisha Piotti ont ramené le ton à un optimisme tempéré, affirmant que le fossé entre les principes de gouvernance et la mise en œuvre concrète est comblable, à condition que les dimensions normatives, financières et d'assistance technique soient abordées conjointement. Tout au long de la discussion, les échanges sont restés respectueux, collégiaux et ciblés, sans tension ni désaccord notable entre les participants.
Intervenants
TS
Thomas Schneider
161 wpm · 13 min
AP
Ayisha Piotti
183 wpm · 11 min
HB
Hoda Baraka
127 wpm · 14 min
PD
Peter Deussen
132 wpm · 7 min
A
Audience
121 wpm · 1 min

Résumé élargi : Rendre l'IA sûre dans le monde réel - Des principes à la mise en œuvre

#

Contexte et objectifs de la session

La discussion s'est tenue dans le cadre d'une semaine consacrée à la gouvernance de l'IA à Genève, réunissant des participants présents en personne et en ligne un vendredi matin . La session a été organisée par le Secrétariat CDNet du Conseil de l'Europe et animée par Ayisha Piotti, associée directrice de RegHorizon et responsable de l'AI Policy Summit à l'EPFZ . Thomas Schneider, Directeur des affaires internationales à l'OFCOM Suisse, ancien président du Comité sur l'intelligence artificielle du Conseil de l'Europe de 2022 à 2024, et principal responsable de l'organisation du Sommet mondial sur l'IA prévu en 2027 à Genève, a ouvert les travaux en posant le défi central : les principes sans mise en œuvre ne restent que de simples aspirations, et la session visait à explorer si des outils existent désormais pour combler l'écart entre les engagements écrits et la pratique réelle . Le panel comprenait également Dr Hoda Baraka, conseillère auprès du ministre au sein du ministère égyptien des Communications et des Technologies de l'information et professeure d'ingénierie informatique à l'Université du Caire, ainsi que Peter Deussen, expert en normalisation internationale ayant largement contribué aux travaux de l'ISO et de l'IEC .

#

Les quatre dimensions du défi de mise en œuvre

Ayisha Piotti a structuré la discussion autour de quatre dimensions du défi de mise en œuvre . La première était la dimension normative - plus précisément, le rôle de la Convention-cadre du Conseil de l'Europe sur l'IA, les droits de l'homme, la démocratie et l'état de droit, ainsi que la méthodologie Huderia qui l'accompagne . La deuxième était la dimension de la mise en œuvre nationale, illustrée par l'expérience nationale de l'Égypte . La troisième était la dimension des normes - l'infrastructure technique pouvant aider les gouvernements et les organisations à mettre en œuvre de manière cohérente les exigences en matière d'évaluation d'impact, de gestion des risques et de gouvernance . La quatrième, qui n'a pas pu être pleinement abordée en raison de l'absence d'un panéliste dédié, était la dimension du financement du développement et de l'assistance technique, bien qu'Ayisha Piotti ait noté que cette question demeurait centrale et insuffisamment explorée dans les discussions sur la gouvernance de manière générale .

#

La Convention-cadre du Conseil de l'Europe sur l'IA comme ancrage normatif

Thomas Schneider a présenté en détail la Convention-cadre du Conseil de l'Europe sur l'IA, officiellement connue sous le nom de Convention 225 ou de Convention de Vilnius après avoir été ouverte à la signature à Vilnius en septembre 2024 . Il s'agit de la convention-cadre sur l'IA, les droits de l'homme, la démocratie et l'état de droit, qui avait déjà recueilli 21 signatures à l'échelle mondiale au moment de la session, dont une de l'Union européenne au nom de ses 27 États membres . Thomas Schneider a indiqué que l'UE avait ratifié la Convention le mois précédent et a exprimé l'espoir que d'autres ratifications suivraient pour lui permettre d'entrer en vigueur .

Thomas Schneider a expliqué que la logique fondamentale de la Convention n'est pas de réinventer les cadres existants en matière de droits de l'homme, mais de garantir que les normes établies, couvrant les droits de l'homme, la démocratie et l'état de droit, s'appliquent dans les contextes où l'IA est déployée, quel que soit le système juridique d'un pays . La Convention ne fait référence à rien d'explicitement européen ; elle renvoie à l'ensemble des normes nationales et internationales, ce qui en fait un instrument véritablement mondial accessible à tout pays respectant les droits de l'homme, la démocratie et l'état de droit . Elle définit des principes et des mécanismes que les États doivent respecter pour les acteurs publics et ceux agissant en leur nom, tout en engageant les États à garantir des protections équivalentes pour les acteurs privés utilisant l'IA . Il est important de noter que la Convention ne prescrit pas exactement la manière dont les États doivent mettre en œuvre ces exigences, laissant à chaque pays la liberté de le faire conformément à ses propres traditions institutionnelles et juridiques . En définissant des principes communs et des mécanismes requis sans imposer un modèle unique, la Convention crée un degré d'interopérabilité entre différents systèmes nationaux tout en permettant différentes façons d'atteindre les mêmes objectifs .

Thomas Schneider a également mis en avant la méthodologie Huderia comme un outil pratique à trois niveaux conçu pour combler l'écart entre les principes abstraits et l'évaluation opérationnelle . Le premier niveau couvre les fonctions générales ; le deuxième est un document de 20 pages expliquant les différents éléments du modèle ; et le troisième est un document de 80 pages contenant des questionnaires détaillés pour une mise en œuvre approfondie . Il a souligné que Huderia a été développée non pas uniquement par des juristes, mais par une équipe multidisciplinaire comprenant des experts en normalisation technique, des universitaires et des praticiens du monde des affaires, et qu'elle est testée sur des cas concrets . Thomas Schneider a établi une analogie avec la Convention de Budapest sur la cybercriminalité, qui a suscité l'adhésion d'environ 150 pays bien qu'elle ne compte que 80 signataires environ, laissant entendre que la communauté de coopération qui verra le jour une fois que la Convention sur l'IA entrera en vigueur pourrait revêtir une importance aussi grande que l'instrument conventionnel lui-même .

#

Le parcours de l'Égypte en matière de gouvernance nationale de l'IA : de la stratégie à la pratique opérationnelle

Hoda Baraka a présenté l'expérience de l'Égypte comme exemple concret d'un pays du Sud global traduisant les principes de gouvernance de l'IA en pratique opérationnelle . Elle a commencé par formuler une intuition fondatrice qui a façonné l'ensemble de l'approche égyptienne : la gouvernance de l'IA ne peut pas rester un ensemble de principes de haut niveau ou un document de politique, mais doit faire partie intégrante de la façon dont le gouvernement conçoit, acquiert, déploie, surveille et évalue les systèmes d'IA, ancrée dans les institutions, les processus d'approvisionnement, la mise en œuvre sectorielle, le renforcement des capacités et les décisions quotidiennes des fonctionnaires .

Le parcours de l'Égypte a débuté en 2019 avec la création du Conseil national pour l'intelligence artificielle . Cela a été suivi par deux éditions d'une stratégie nationale en matière d'IA - la première relativement simple, la seconde complète et lancée en janvier 2025 - ainsi que par l'élaboration d'une Charte égyptienne pour une IA responsable, alignée sur les principes de l'OCDE et les recommandations de l'UNESCO, et par la création du Centre égyptien pour une IA responsable . Une étape précoce déterminante a été une étude du cadre de gouvernance dans laquelle l'Égypte a examiné 35 cadres de gouvernance différents, notamment la Convention-cadre du Conseil de l'Europe, la méthodologie Huderia, la recommandation de l'UNESCO, les principes de l'OCDE sur l'IA et le processus d'Hiroshima . L'objectif n'était pas de copier un modèle unique, mais de comprendre l'ensemble du paysage pour ensuite localiser et contextualiser une approche adaptée à la culture, aux normes et aux institutions propres à l'Égypte .

Sur cette base, l'Égypte a développé un cadre national de gouvernance de l'IA fondé sur les risques et les droits, s'appuyant sur l'AI Act de l'UE pour la catégorisation des applications selon les risques et sur le Conseil de l'Europe et CDNet pour l'approche fondée sur les droits, incluant la participation des parties prenantes . Huderia s'est révélée particulièrement utile dans ce processus, car elle fait passer la discussion des valeurs abstraites à une évaluation structurée, posant des questions pratiques sur le contexte, les parties prenantes et l'évaluation de l'impact . L'Égypte a intégré des éléments de Huderia - notamment ceux relatifs à la gestion des parties prenantes, aux phases pré- et post-déploiement, et à l'intégration des principes d'IA responsable dans la phase de conception - dans ses lignes directrices sur les systèmes d'IA .

Un autre résultat concret a été l'élaboration de lignes directrices en matière d'approvisionnement, que Hoda Baraka a décrites comme un outil stratégique de gouvernance . Les fonctionnaires avaient du mal à traduire les lignes directrices générales sur les systèmes d'IA en étapes concrètes, ce qui a conduit l'Égypte à créer une correspondance entre chaque processus de la méthodologie Huderia et les normes ISO pertinentes, afin que les fonctionnaires sachent quelles normes appliquer lors de l'acquisition de systèmes d'IA . L'Égypte développe également une ligne directrice sur la sécurité des enfants en collaboration avec l'Autorité nationale de régulation des télécommunications, ciblant les parents et les éducateurs dans l'enseignement pré-universitaire . Sur la question de la localisation, l'Égypte a développé un grand modèle de langage en arabe appelé Ozkarnak (Karnak en abrégé) par l'intermédiaire de son Centre d'innovation appliquée, conçu pour refléter les valeurs et les normes culturelles égyptiennes, et est en discussion avec des pays africains pour étendre ce modèle au contexte africain .

Hoda Baraka a tiré quatre leçons clés du parcours de l'Égypte. Premièrement, l'IA responsable doit être intégrée dès le début, avec une conception du gouvernement comme orchestrateur équilibrant la protection des droits de l'homme avec l'innovation et le développement économique . Deuxièmement, l'approvisionnement est un outil stratégique de gouvernance, et l'Égypte crée un laboratoire d'audit de l'IA pour former les fonctionnaires à ce que signifient la gouvernance et l'IA responsable dans la pratique . Troisièmement, le renforcement des capacités est essentiel pour tous les segments de la société, des enfants aux personnes âgées en passant par les fonctionnaires . Quatrièmement, la localisation et la coopération internationale sont toutes deux essentielles, l'Égypte se positionnant comme un pont entre l'Afrique, le monde arabe et la Méditerranée .

#

Le rôle complémentaire des normes internationales ISO/IEC

Peter Deussen a présenté les travaux du comité conjoint ISO/IEC sur l'intelligence artificielle, SC42, qui a élaboré un ensemble de normes complémentaires . Celles-ci comprennent une norme sur la gestion des risques liés à l'IA - pour laquelle Peter Deussen a exercé les fonctions d'éditeur - une norme générale sur les systèmes de management de l'IA (ISO 42001) définissant les exigences relatives à la manière dont les organisations devraient mettre en place des processus pour traiter de manière responsable le développement et l'utilisation de l'IA, ainsi qu'une norme plus récente sur l'évaluation de l'impact des systèmes d'IA, axée explicitement sur les impacts sur les individus, les groupes d'individus et la société . Peter Deussen a noté que les normes ISO se concentrent traditionnellement sur les risques organisationnels - financiers, réputationnels, etc. - et qu'il existait une lacune concernant les risques imposés par la technologie aux individus et à la société, lacune que la nouvelle norme sur l'évaluation de l'impact était conçue pour combler . Il a également noté que la norme sur l'évaluation de l'impact porte à la fois sur les impacts positifs et négatifs, ce qui lui confère une portée quelque peu plus large que Huderia, qui se concentre uniquement sur les impacts négatifs.

Peter Deussen a décrit les normes ISO et Huderia comme complémentaires plutôt que redondantes : deux faces d'une même réalité . Les normes ISO établissent le lien avec ce que les organisations devraient effectivement faire en interne, en précisant les cycles de révision, les processus d'approbation et les exigences de documentation, tandis que Huderia se concentre sur la substance des impacts sur les droits de l'homme, la démocratie et l'état de droit . Il a soutenu que combiner les deux pourrait constituer une très bonne approche, facilitant la mise en œuvre de Huderia par les organisations tout en permettant l'utilisation des normes ISO dans un contexte réglementaire . Un avantage clé des normes ISO à cet égard est qu'elles fournissent un langage et des meilleures pratiques industrielles que les organisations comprennent déjà, ce qui en fait un pont efficace entre les principes de gouvernance et la pratique industrielle .

Peter Deussen a également identifié une lacune importante : l'ISO n'a pas encore produit de guide sur la manière dont ses normes peuvent être utilisées dans un contexte réglementaire ou d'élaboration de politiques, car elles sont rédigées dans un langage et des concepts propres à l'industrie . Il a suggéré qu'un document d'orientation ou une correspondance entre les normes ISO et le monde réglementaire constituerait une voie utile à suivre . Cette observation est particulièrement notable étant donné que Hoda Baraka avait déjà dit que l'Égypte entreprenait précisément ce type d'exercice de correspondance dans la pratique .

#

Financement du développement et infrastructure de calcul : la dimension insuffisamment prise en compte

Lorsque la discussion s'est tournée vers le financement du développement, Hoda Baraka a adopté un registre plus direct et plus sobre. Si le capital humain et les capacités politiques de l'Égypte sont solides, et si les politiques, les lignes directrices, le renforcement des capacités et le développement de cas d'usage peuvent être financés par des ressources nationales, l'infrastructure de calcul représente un défi majeur . L'assistance technique d'organisations multilatérales telles que la Banque mondiale et la GIZ peut soutenir le renforcement des capacités, le développement des programmes d'études et la révision des politiques, mais ne répond pas aux besoins en matériel . En conséquence, le laboratoire d'audit de l'IA en Égypte se limite actuellement à un modeste ensemble d'ordinateurs de bureau équipés de GPU plutôt qu'à un environnement sandbox d'IA entièrement basé sur le cloud, en raison de contraintes de financement . L'Égypte explore activement des mécanismes de financement alternatifs et des modèles économiques pour combler cette lacune .

Ayisha Piotti a renforcé ce point dans ses remarques de clôture, notant que la dimension du financement du développement est rarement abordée dans les discussions sur la gouvernance de l'IA et appelant à des sessions futures dédiées pour explorer comment les mécanismes de financement institutionnel peuvent être mieux connectés à la mise en œuvre d'une gouvernance de l'IA fondée sur les droits . Elle a présenté cela comme l'un des principaux enseignements de la session, aux côtés de l'ancrage normatif fourni par la Convention du Conseil de l'Europe et du rôle de pont joué par les normes techniques .

#

Contribution du public : le déficit d'infrastructure informationnelle

Un membre du public a soulevé une dimension supplémentaire qui n'avait pas été explicitement abordée par les panélistes : l'absence d'informations standardisées et transjuridictionnelles sur les endroits et les modalités d'utilisation de l'IA dans les différents secteurs et entreprises, ainsi que sur le niveau de supervision humaine par rapport à l'autonomie de l'IA dans chaque cas . L'argument avancé était que sans cette information fondamentale, une gouvernance et une prise de décision efficaces restent impossibles . Peter Deussen a reconnu la légitimité de cette lacune, notant que si la norme ISO 42500 de l'ISO fournit une bonne approche pour documenter les systèmes d'IA et leurs risques, elle ne fournit pas de catalogue ou de base de données de toutes les applications industrielles . Il a suggéré que la normalisation pourrait fournir la structure d'une telle base de données - en définissant quelles informations devraient être enregistrées et comment elles devraient être organisées - mais que la renseigner avec des données réelles dépasse le cadre de la normalisation . Cet échange a mis en lumière un déficit d'information systémique qui se situe en dessous de tous les cadres de gouvernance existants.

#

Thèmes clés et conclusions

La discussion a révélé un degré élevé de consensus sur le défi central et la direction générale des solutions. Tous les intervenants ont convenu que les principes sans outils de mise en œuvre ne sont que des aspirations , que Huderia et les normes ISO sont complémentaires et devraient être utilisées conjointement , et que la coopération internationale et les approches multipartites sont essentielles . La Convention du Conseil de l'Europe a été soutenue non seulement par Thomas Schneider, mais aussi par Hoda Baraka, comme un instrument véritablement utile pour les États non membres, l'Égypte l'ayant volontairement intégrée, avec la méthodologie Huderia, dans son cadre national de gouvernance .

La discussion a également fait ressortir des contrastes importants entre les perspectives des différents intervenants. La présentation de Thomas Schneider a présenté la Convention, Huderia et les normes ISO comme un ensemble cohérent et largement suffisant , tandis que Hoda Baraka a clairement indiqué que même avec des cadres de gouvernance sophistiqués en place, l'incapacité à financer une infrastructure basée sur le cloud représente un obstacle fondamental à la mise en œuvre complète . L'identification par Peter Deussen d'une lacune entre les normes ISO et le monde réglementaire a encore souligné la distance qui subsiste entre les cadres formels et la pratique sur le terrain, d'autant plus que l'Égypte avait déjà partiellement comblé cette lacune grâce à son propre exercice de correspondance .

Dans ses remarques de clôture, Ayisha Piotti a synthétisé les principales conclusions de la session avec un optimisme mesuré. Elle a affirmé que l'écart entre les principes de gouvernance et la mise en œuvre dans le monde réel peut être comblé , mais a souligné que cela nécessite que les dimensions normative, financière et d'assistance technique soient abordées ensemble et en collaboration . Elle a souligné que l'expérience de l'Égypte démontrait que les pays n'avaient pas besoin d'attendre un consensus international pour aller de l'avant , que la Convention du Conseil de l'Europe constituait un cadre normatif ouvert à tous , et que les normes techniques fournissaient le langage compréhensible par les acteurs du secteur, nécessaire pour relier les cadres de gouvernance à la pratique . Son appel final était en faveur d'une collaboration continue, d'une volonté d'agir même face à l'incertitude, et d'un travail futur dédié à la dimension du financement du développement que la session avait identifiée comme critique mais insuffisamment prise en compte .

Thomas Schneider
Should we start? Did you get him? Not yet. Okay, so we'll see. So good morning everyone. Physically present here on a Friday morning in Geneva as well as online. My name is Thomas Schneider. I work for the Swiss government, but I also have been working in the Council of Europe for many years. And so I'm very happy to on behalf of the Council of Europe, welcome you to what I think is an important discussion that we should be having here in Geneva during this. important AI governance week where we heard a lot about AI governance principles and we think that the Council of Europe has contributed with the convention that has the number 225. It is now called Vilnius Convention because it was put up for signature in Vilnius in September 24. It is the framework convention on AI, human rights, democracy and rule of law. It has already gotten since then 21 signatures globally, one signature of which is from the European Union, so that counts for 27 member states. And it has last month been ratified by the EU on behalf of these 27 member states and of course we hope that more ratification will happen. It will come soon that it can enter into force. very soon. So the convention singles out a number of principles, but of course principles without implementation are just aspiration. And what we're here today to discuss is the distance between the two and whether tools now exist to close the gap between principles written on paper and actually implemented. So we have in the room a number of people who contributed to this. We'll hear from states building AI governance frameworks under real institutional and capacity constraints from the Council of Europe perspective where treaty obligations are being translated into practical methodology and from the international standards community where technical tools for implementation are being developed. Development finance is also part of this picture even if it is not represented as a separate voice on the panel today. but it is already present in the country cases that we'll discuss, digital transformation projects, AI readiness work, technical assistance, and the difficult question of how rights -based governance is embedded into real public sector reform. So this is the conversation that in our view matters, and I'm very delighted to have a hand over the floor to Ayesha Pioti, managing partner of Rego Horizon and head of the AI Policy Summit that she's been organizing for many years now at the ETH Zurich, which she built from scratch and which is now one of Europe's leading global AI policy platforms, drawing participants from over 100 countries. And she also sits on the ITU UNESCO Broadband Commission's Expert Committee on AI Capacity Building and has spent 20 years doing what very few people in this space actually do, which is to say that she's been a member of the ETH Zurich ETH Group and she's been a member of the ETH Zurich ETH Group and she's been a member of the ETH Zurich ETH Group and she's been a member of the ETH Zurich ETH Group and she's been a member of the ETH Zurich ETH Group and she's been a member of the ETH Zurich ETH Group and she's been a member of the ETH Zurich ETH Group and she's been a member of the ETH Zurich ETH Group and she's been a member of the ETH Zurich ETH Group and she's been a member of the ETH Zurich ETH Group and she's been a member of the ETH Zurich ETH Group and she's been a member of the ETH Zurich ETH Group and she's been a member of the ETH Zurich ETH Group around concrete policy solutions rather than abstract principles. She is also, as you will hear, an excellent moderator. So let me hand over to you, Ayesha. Thank you.
Ayisha Piotti
Thank you so much. Thank you. I mean, I wasn't expecting such a wonderful introduction, so thanks a lot. So some of the things I wanted to say have already been said, but first of all, I'd like to just welcome everybody to today's discussion on making AI safe in the real world and how we move from principles to implementation. The session is organized by the Council of Europe CDNet Secretariat, so thanks very much to all of them to have taken putting us all together. Now, in terms of the problem statement that's already been pointed out by Thomas, so I shall not basically go into it, but essentially what we're looking at is very much the implementation side of all the principles and guidelines that we already have. So in today's session, we'd like to explore, in fact, four dimensions of the implementation challenge. I'm not sure whether we will be able to do all of that since we don't have everybody here, but we will try nonetheless to have a conversation and then we can try to also bring in some of the views that you have in order to make the discussion complete. So first and foremost, we'd like to look at the normative dimension. And what I mean by that is what is the role of the Council of Europe's Convention on AI that has been just mentioned by Thomas? And of course, the subsequent Houdiera methodology, of course, frameworks that provides concrete assessment and governance tools for human rights, democracy and the rule of law commitments. The second one we'd like to explore is the country implementation dimension. So essentially, we will have from Egypt with regards to. The national context, both for working from strategy to how it actually goes into the real institutional practice. So, in this context, we will have from Egypt with regards to the country implementation dimension. third is the standards dimension and that's the technical infrastructure that can help governments and organizations to implement the impact assessment, risk management and governance requirements consistently and the fourth in fact was supposed to be finance and technical assistance dimension we had hoped to in fact include that perspective directly today but unfortunately that's not been possible but we still think that this issue is very central and I'm very I'm glad that this is something that has been raised. I have to say that I've been in many many discussions so far in governance and that the whole institutional basically development finance angle is not that much that's covered so we hope that we can in fact build something around that and have some takeaways that can be taken away from this one so before I start I would also like to introduce my fellow panel panelists and And Thomas has said good words about me, so I'll start with the master, Thomas Schneider. And for everybody, he is director for international affairs at Ofcom, Switzerland, vice chair of the CDNet. But also he was the chair of the Council of Europe's Committee on Artificial Intelligence from 2022 to 2024. And some of you might not know, but he's a very sought after person. Also, because he is the main lead for the organization of the Global AI Summit scheduled for 2027 in Geneva. So welcome, Thomas, and somebody with great depth in this area. We also have Dr. Hoda Baraka, one of principal architects of Egypt's National AI Journey. She's advisor to the minister at Ministry of Communication, Information Technology in Egypt and a professor of computer engineering at Cairo University. So welcome. on my right I have Mr. Peter Doyson from EXPERT from the world of international standards with over 15 years of experience and active, very involvement international standard bodies included ISO, IEC and I think the list goes on the list goes on pleasure to have you here with us we were meant to be also having Mr. James Cobber but I understand that he hasn't been able to make it maybe he's going to join us and if he does we'll just bring him into the conversation so without any further ado I would probably like to start with Dr. Hoda Baraka about Egypt and what I'd like to say is Egypt didn't really wait for the international community, my understanding is that you decided to move forward, you decided to move forward with the national AI strategy you created the National Council for Artificial Intelligence and of course the Egyptian Center for Responsible AI You've also, and I think that was very interesting, cited Hudi 'ira as one of the inspirations for you to have done and taken those steps, and I think that's very, very interesting. So my question would be, ow was Egypt able to translate these principles into operational practice first and foremost, and what hurdles particularly did you face when you tried to make safe AI a reality in a government context?
Hoda Baraka
Well, thank you very much, Aisha, and thank you, Ambassador Thomas, and thank you, of course, for the Council of Europe and CZNet to convene this important and very practical discussion. I mean, this is maybe the last day in Oasis, and everyone has heard a lot about all the challenges that encounter AI governance, and I think what Egypt is bringing here is a very important challenge. is more a practical experience of the global South countries. I think how to translate AI governance principle into operational practice, this is a very, very important question, and it's not an easy journey, actually, but it is really a journey that needs to start slowly but firmly so that we can really reach a real objective and impact from what we are implementing in the field of AI. For Egypt, the starting point was a clear recognition. AI governance cannot really remain like just a set of high -level principles or a policy paper. It has to become part of how government designs, procures, deploys, monitors, and evaluates. And that's what we're trying to do with AI systems. It has to be embedded also in institutions, in our procurement processes, in our sectoral implementation, in capacity building, and in the daily decisions of our public officials. And I think public officials, this is one of the important parts that we need to focus very much on if you want really to move with AI in a responsible and ethical way. That's why Egypt has been working on what we describe a full responsible AI governance stack. So as you mentioned, Aisha, we started with the National Council for AI, and this was back in 2019. And then we had developed our national AI strategy. We actually had two editions of the national AI strategy. The first one was very simple, and the second one is very comprehensive. It has been launched in January 2025. And we developed the Egyptian Charter for Responsible AI, very much aligned with the OECD principles and also the UNESCO. And we established what we call the Egyptian Center for Responsible AI. I think this was just last year, and it was a milestone for the government to realize the importance of having a center. We have another center for implementation and for use cases, but the part of policies, governance, capacity building is actually embedded inside the Egyptian Center for Responsible AI. One of the important steps that we undertook to start was a governance framework study. So this was really a very important point where we studied like 35 different governance frameworks. Of course, including the council. of Europe's Framework Convention, or AI, the Huderia, the UNESCO recommendation, the OCG AI principles, Hiroshima. We had 35 different governance frameworks. And our objective was not to copy, of course, any of these models, but to understand all of this and then make sure that we can localize it and contextualize it to our Egyptian culture and norms and institutions. So this study helped us actually to shape our national AI governance framework. And this was one of the first steps that we have done that is around a risk -based and rights -based approach. Importantly, very, very important that we understand how to make sure that it's a risk -based approach. Of course, we looked at the EU AI Act for this point and how we can identify four different approaches. We looked at the different categories of applications. And also on the same time, with the Council of Europe and CZNET, we also understand what does it mean to make sure that we have the rights -based approach, how to include human rights and how to make sure that we are involving the stakeholders actually as part of our process. Huderia has been particularly useful because it helps move the discussion from the very abstract value to structured assessment. And it asks practical questions. What is the context? Who are the stakeholders? How can you actually evaluate the impact? What we have done is that we actually took some of Huderia principles and included in our second important document, which was the AI system guidelines. This was the AI system workflow. And we took... We took a little bit... from Hodaria related to the part of the stakeholder management, of course, the part of the pre -deployment and the post -deployment phase, how to make sure that we include responsible AI principles in the design phase, and then include it also in the post -deployment to monitor and to audit the AI systems implementation. This took us to an important guideline, which is the procurement guideline, because we found out that all the public officials struggle in understanding. It's very nice, Dr. Hahn, that you put for us for AI system guidelines, but at the end of the day, we don't know how to realize these guidelines. So we put together, this is still a work under process. The procurement guideline, and inside the procurement guideline, we actually also are very actively working. with the ISO and we wanted to make this link and we were happy actually to find out one of the sessions here where we bring it together, the ISO from one side and Huderia from the other side. Why? Because we realized when we were writing our procurement guideline is that it's fine that we have the Huderia, this is a framework, but how can we implement it? And we did this kind of mapping between every process in the Huderia methodology and what kind of ISO standards well mapped into so that we can provide the public officials with the standards that they have to realize while procurement their AI system. One final also document we are currently working on is the AI child safety. because, again, it's not only about the procurement, the public officials, but actually at the end of the day we have the society, and we want to make sure that children are protected. So we are currently working with our regulator, the National Telecom Regulatory Authority, on making sure that we have also a guideline for parents, for educators, especially for pre -university education on the child protection. So one thing also that we have maybe put into practice is the conceptualization. Egypt, of course, is an Arabic -speaking country, and definitely we want to have our language model related to our culture, our values, our norms, and that's why our Applied Innovation Center has worked on an Arabic, Arabic LLM, Ozkarnak. and we are very proud that we can provide this LLM also to the Arab countries from one side and also to contextualize it for African countries. We are talking now with a number of African countries on how to take Karnak to the African world and I think this is also something important to understand how can we contextualize and localize foundational models. So I think this is more or less what we have done to bring things to practice and maybe one last part is related to what lessons we have learned from this journey that has been going maybe for the last two years very aggressively with all our partners. First of all, responsible AI must be embedded very early. And we need to have this concept from the beginning, from the early beginning, if you want really to move in a very steady manner and to make sure that we are definitely having this kind of orchestrating. We call it government as orchestrator, balancing between protection rights, human rights, and also on the other side, innovations, small and medium enterprises, boosting the economy. Second, procurement definitely is a strategic governance tool. And I think one of the things that we are doing now is establishing an AI sandbox, an AI audit lab to train public officials on tools of what does it mean governance and what does it mean responsible AI. Third, capacity building. Of course, we've heard a lot of capacity building going on and capacity building on different segments from children up to elderly up to public officials. And the fourth lesson is, of course, localization. I think international cooperation and what we have seen in this Geneva AI Governance Week is definitely important. Our collaboration with CGNet, with ISO, with all different other organizations. I think this is crucial. This kind of international collaboration and multi -stakeholder approach is really very important. And Egypt is always ready to to act as a bridge between Africa, between the Arab region, between also the Mediterranean, the EU. I think our location is really in the middle of everything. So we are happy to help and to provide, to exchange our experience in this important emerging technology. Thank you.
Ayisha Piotti
Thank you so much. I was really not aware how much Egypt was doing, so bravo. It's fantastic and it's great to see that you're able to take all of these instruments and then look at your local needs, adapt them to that and then move forward with really concrete steps. So thanks for sharing that experience. In the interest of time, I think we'll build on that point and I'm going to come to Thomas now and coming back to the convention, which is now, of course, as you said, attracting a lot of signatures, ratifications. But of course, there are many, many states outside of the Council of Europe and they are obviously looking for guidance as well. And the question really is, and that could be in Africa, Asia and many other countries. the question really is if they actually have accession to the convention, what does it really give them that they cannot get anywhere else and also what does the Council of Europe really commit to them in terms of giving them back and that would be very useful Thanks Thomas.
Thomas Schneider
Thank you Ayesha and it's during this week when you listen to the discussions there are many people that express the needs that we need more clear guidelines, guardrails regulatory frameworks, whatever it is called in detail and that this is something that is missed there is a lot around like a lot of soft law from the OECD work to UNESCO's recommendation, also Council of Europe soft law which is a lot of it is sectorial from the media field to health etc. etc. and there are many self-regulatory business associations, guidelines and so on and so forth you have the G7 process, the Hiroshima process and other frameworks but this is all soft law or self-regulation And then, of course, we have technical standards that we mentioned that need to play together with this. And this call for we need some clear guidelines that are reliable, that are clear, is issued not just by governments or by civil society, but it's also coming from the developers, from the technical community themselves, that they are looking for clear guidelines in the sense that what is it that they can orient themselves to, and also coming from businesses. We've heard probably Brad Smith from Microsoft also calling for a clear framework. And the thing is, I think, and this is the first answer, and we've already heard it from you, this convention gives a core element, at least, of this guidance, and it does it in a fairly intelligent way in the sense that it refers to existing standards, all the European standards. And it's a key of its convention, number 225 of the Council of Europe. it doesn't replace it doesn't try to reinvent the wheel it doesn't replace anything that is there before it refers to it but not just to the European it doesn't refer to anything explicitly European it refers to all national and international standards so it's a global instrument also all the UN and other all the compacts and all the soft law and the conventions of all the other institutions and what it does it makes sure it tries to make sure that the existing standards no matter where in which region in the world you are that you have on protecting human rights democracy and rule of law also apply to environments where AI comes into play and I think this is the very simple but very intelligent logic of this tool that it says okay we have developed over the last century a number of standards let's make sure that these apply we don't change them but we try to make sure that these apply to AI no matter in which country you are no matter what your legal system is no matter how exactly you interpret the right to freedom of expression or right to privacy where you have differences even within between Europe and the US and other continents is not human rights and all of this is not a homogeneous thing. Even in Europe, even in the EU, you have some diversity in how countries due to their history and so on see these rights and organize them. And so this is the intelligent move to build an existing framework to fill one precise gap to make sure that this all is applicable to AI and also to make this convention accessible to all countries in the world that respect human rights, democracy, and rule of law. It states the principles that states need to make sure that are fulfilled for public actors. It defines a number of mechanisms and functions that need to be in place so that people can actually exercise their rights, that they have access to documentation, that there needs to be an instance that they can go to to say my rights have not been respected. But it doesn't tell governments exactly how they need to do it. So it is up to every state to do this based on their institutional and legal history so that they can do it in the way it works for them. At the same time, by defining the same principles and requesting the existence of mechanisms with the same function, it creates a certain level of another buzzword that we hear all over the place of interoperability between different systems. So it brings everyone on the same level while allowing different ways of doing this. And it also, although the principles apply the way they are written, states are obliged to use them on public actors and those acting on behalf of the public. States also commit to, and even in a more free way, but they commit to make sure that the same level of protection is also applied when it comes to interoperability. To public, private actors using AI. So it's not just focusing. on public actors. It makes a differentiation in terms of the responsibility of the actors for protecting human rights and democracy and rule of law, which makes sense because it's true, but it includes also a responsibility for states to make sure that people's rights and democracy and rule of law is also protected when it comes to private actors. So it's a very simple but compelling logic, I think, that can be applicable in every country and allows every country to do it in their way. And Egypt is a very good example about you look at all the options and you think that this is actually a very good way of doing things. And as you said, one thing is to have these principles and the mechanisms and the intended functions on paper. The other thing is, and this is not trivial, to actually make sure that this is being implemented in a way that any regulator, any authorities that will be responsible understand how it's going to work. How this should be done, how these risks can be assessed and if they are occur or impacts, if they occur, can be mitigated. But this is also important for the industry, for the developers, that they understand, okay, what is actually my responsibility and what is maybe not my responsibility, but the responsibility of those that deploy a system in a particular machine or bigger application, what may be the responsibility of those that use this. So this Huderia methodology and model is really a useful tool, whether or not you have signed or ratified the Council of Europe Convention, everyone will need, every public, every state will need to have assessment mechanisms for risks and mitigation mechanisms for negative impact. And this Huderia model gives a very understandable guidance on how you can do this, and it has three levels. One is very general functions. The second level is the 20-page document that explains the different elements of the Huderia model also in a very general way. and then if you want to go deeper, you have like an 80-page document that really has questionnaires and goes into detail about how you could implement this, so it is really thought through, and you also realize when you read it that it hasn't developed by lawyers, by human rights lawyers, only it has been developed by people from the technical standardization community, you have academics, you have business people, and it's being tested on concrete cases. So this is a package that is really unique, and then the third thing, which is going to come as soon as we have the five ratifications, now we have one, unfortunately it's one that goes for 27 countries, though it is only one signature in the new situation of the EU, but now that the EU, the biggest block is there, the others will hopefully come soon. The other element is the cooperation. the whole community that will emerge as soon as the convention is in place. And we saw this with, and I'll stop with this, we saw this with the Cybercrime Convention, the Budapest Convention, which is also a good predecessor. It's a convention by the Council of Europe that has around 80 signatures globally, but there are around 150, so almost all countries are somehow participating in the cooperation and exchange of experience and best practice exercises around the convention. And as soon as this convention, the AI convention, is ratified, you will have the same that countries and all other actors, whether they have ratified or not, will engage, and that space is equally important than the convention itself. Thank you so much.
Ayisha Piotti
Thank you so much. So you mentioned a few things, and I think that was quite interesting, because first thing you said. You said, which I thought was very, very... the Council of Europe's Convention is really a clear instrument which is targeted for something specific, which is human rights, democracy, and rule of law. And I think that is very key. So we have instruments that are there that can be binding as well, but if they are focused and targeted. I think that's clear. You talked about interoperability and technical community, which brings me straight to Peter. So Peter, of course, as we are seeing that the countries are trying to have their national strategies, they're also looking at what's happening for the Council of Europe's Convention. And the question there is what is really the role of international standards? And in your opinion, essentially, when you look at the current landscape, and as you know, there's many, there's ISO, there's NCELEC, there's NIST, and all of them. To what extent do you think they're able to really fill the gaps when it comes to the technical aspects, and what could be some of the ways forward for the countries?
Peter Deussen
Thank you. Thank you, Ashi, and let me try to address these questions. So, what ISO has established is a committee for artificial intelligence it is actually a joint committee between ISO and IEC and that committee has developed various documents that might be of interest here. First one would be a document on risk management a couple of years ago. I had the honor to serve as an editor for this document. Then, after checking that, you know, after understanding how we could deal with risks for artificial intelligence we went to the question how to define a general governance framework for AI which led us to the development of what we call the Standardization and Management System Standard for 2001 is the number here which provides you with, you know, general requirements on how to set up processes within an organization on how to deal responsibly with artificial intelligence, with the development and use of AI systems. And then we notice we have a gap. The gap is, you know, ISO standards usually look into organizational risks, you know, risks for the organization itself, financial risks, for instance, risk of reputations and so on. They don't look that much beyond that to risks that are imposed by, you know, technology to individuals, groups of individuals, individual society. So, that was a gap that we also had in that standardization work of SC42. So, we decided to, you know, to fill that gap and to develop a standard on AI system impact assessment, which explicitly focused on impact of AI systems systems. to persons, to individuals, to group of individuals, and to society in general. That document focuses on positive impacts as well as negative impacts, so it's a little bit broader than Houdaria, which focuses on negative impacts only. It also talks a little bit more generic about impacts, while Houdaria focuses on human rights, democracy, rule of law. That's included, but you know, the document that we have developed in the Standardization Committee is not specific to that. What that document gives you, what's not in Houdaria, is how to tie the impact assessment to your internal, to your organizational processes. It talks about what kind of review cycle do you need? What kind of approval processes do you need? What kind of documentation would be appropriate to understand this? So this is the work that ISO has done in that context. And I believe, you know, if you look into this document, I felt it's very complementary to what we have done in ISO. It's, you know, like two sides of the same things. ISO gives you more like the connection to what to do actually within your organization, you know, and how this ties into the processes that you have there, while Hedaria focuses more on the matter as such, on, you know, impacts or risks on human rights, democracy and rule of law. And it gives you very precise and very good guidance on how to implement, you know, and how to understand risks in this context. My feeling is that bringing these two things together You know, like, you know, bridging between those two things might be a very good approach, you know, to, you know, to make ISO standards, you know, use them also in a regulatory context and, you know, make it better, you know, make it more easy for organizations to implement your dairy, actually. Because, you know, these documents provide you with language that industry understands. It provides you with industry best practices. So, if you want to talk about companies who, you know, developing or, you know, bringing AI in the market, that's the language they understand. So, I think, you know, it's a perfect match, actually. So, what's missing? What are the gaps? Well, good question. ISO has provided comprehensive framework on how to deal with artificial intelligence in a responsible way. What I believe they have not done yet. Yet is. to describe how these documents can be used in a regulatory context, how these documents can be used by policymakers. So they are concentrating on industry -specific language, right? They have concepts that are specific to industry. They have terminology that's used there. You know, my feeling is having some kind of guidance document, some kind of mapping that, you know, bridging between those documents and the regulatory world. That might be a very useful way
Ayisha Piotti
Thanks very much. I think what I really liked was what you said with regards to standards providing the language that the industry really understands. This is a new one, and I think this is very, very key, and I think that's really the real core role, I believe, of the international standard bodies as well. We have a little bit of time. I think we started late, but I was just thinking, is anybody in the room having a question? Yes. Thank you. We can hear you.
Audience
Thank you very much for this detailed presentation of what is going on in the different parts of the boards and the association right now. My question is addressed to Mr. Peterson about the gaps. We do have a lot of, in different institutions, a lot of guidances. But in the gap, we don't have a language that gives the information. Because every kind of decision in our particular lives, in our working activity, or on the governmental level, based on the information, if we don't have it, we can't make any decisions or govern anything. So particularly what information I do mean to say. We don't have information where exactly is used AI. in any different industries and companies, how particularly they are using, and what is the interaction between the human oversight and AI as an autonomy level. So what do you think, would this kind of information in a standardized way, of course, because it should be across all the jurisdictions and industries, can build the gap of foundation for governance and for action taking? Thank you.
Peter Deussen
Well, what 42 ,500 gives you is, you know, a very good approach on how to document your AI system and the risk that's imposed by it. It does not give you, you know, some kind of catalog or database or something like this where you put in all those information. It's actually beyond standardization, right? But my question is, you know, my feeling is that having such, you know, catalog or database might be, you know, actually useful. And what ISO can provide is the structure of such a database, explaining what kind of information put into this database and how to maintain it, how to organize it. I think this is what standardization can do. Of course, standardization cannot provide you with a catalog about all industry applications of artificial intelligence.
Ayisha Piotti
Any other questions on the floor? No? I have a question, actually, and it's one topic that we didn't really get into and I know that we were planning to. It's about development finance. And I was just wondering, so very specifically for Egypt, of course, you've done so much. To what extent have you, in fact, made use of some of those tools, I mean, World Bank, so on and so forth, and what has been the experience, if any?
Hoda Baraka
Thanks. maybe my first part was optimistic positive part but this question always brings the pessimistic part of the case so definitely compute infrastructure for us is a big challenge so maybe we have the minds in Egypt we have a big human capital so when we talk about policies guidelines development use cases implementation capacity building all of these parts can be really done by our local national funds but when we talk about compute infrastructure then this is becoming one of our biggest challenges in order to move forward with AI and with exploiting all the benefits that AI can bring it doesn't mean that all the other parts of our national AI strategy does not involve funding. But when we tap on, for example, the World Bank or GIZ or any multilateral organization, always we have the technical assistance part. So with technical assistance, you can do some work related to capacity building, developing the curricula, having the national standards, having the policies. They can help us in the reviewing, the revision, even with CDNet. This was a process that we are definitely seizing the opportunity for this kind of assistance. But when we talk about hardware, for example, our initial step was to establish the AI sandbox. So we couldn't actually fund a cloud -based sandbox. So we just make the AI, we call it even AI audit lab, to be humble and moderate, because it's just a lab with a number of desktops with GPUs, but we cannot make until now the full -fledged cloud -based AI sandbox because, of course, of funding. So currently we are exploring different ways of funding. And financing mechanisms so that it can help us in the full implementation of the strategy. So we hope that you can find solutions, business models, and all of that.
Ayisha Piotti
Thank you so much. I think we're running out of time now, so I'll quickly – anything, we wrap up? Is that okay? Yeah. So we're going to wrap up. So thank you so much. Thank you, everybody, for being here. It's been a great pleasure. I'm not going to do a very long sort of conclusion, just a few words. So I think what we've heard today, the very – first thing is that there are countries that are not really waiting. They're moving forward. There is enough out there for countries to move forward, and Egypt has really been a great example of that. And the question of course now is, if you really want to look at implementation, the first thing we should do is start trying. Take whatever we have, start working with that. So I think that has been wonderful, and it's great to see that. Well, I think I'll just follow on to what you just said. So it looks like the development and finance, and there can be much more that can be done there. And I think that is actually a takeaway that we should take away from this session as well, and I think this is a topic that I don't see very much being dealt with, and I think it would be great to have some more sessions on that to really see how we can build the bridge there for implementation. The third one I think, which I think is very, very important, is of course the Council of Europe's Treaty. It's really there. It's a normative anchor. I think it's something that can be reused. It's open for all, and I think that was a big takeaway. More and more, it could be something that can be used as as in the case of Egypt, also as an inspiration for many other countries and their support that is available also at the Secretariat if needed to move forward with that. And last but not least, I think it's, of course, the role of the technical standards. And I think what is very key is the interoperability side, the fact that we need that. And I think what I really liked today was also that it's not only allowing the interoperability, but also making the link with industry, and which is what really is what is required as well. So we can come up with anything, but if the industry is not able to implement or move forward with it, that doesn't help us very much. So I think with that, I would just say that, you know, we came here, of course, to ask whether the gap between governance and principles in the real world implementation was bridgeable. And what I hear and what I see is, yes, it is. But, of course, in order for us to do that really, really well, we will need the normative side. We will need, of course, the financial, but we will also need the technical assistance side. And if we do that together in collaboration, the way we have this kind of session here today as well, and we discuss that and move forward with that. try, and even if we fail, still try, take the risk. I think that's the way forward. So with that, I would just say thank you so much for being here. Thank you for the session. Thank you to the Secretariat for the Council of Europe for organizing it, and I wish you all the rest of the day a really nice day and a good weekend. It was a pleasure.

Avertissement : Il ne s'agit pas d'un compte rendu officiel de la session. DiploAI génère ces ressources à partir d'enregistrements audiovisuels ; elles sont présentées telles quelles, y compris d'éventuelles erreurs. En raison de contraintes logistiques (audio/vidéo ou transcriptions), les noms peuvent être mal orthographiés. Nous nous efforçons d'être aussi précis que possible.