EU targets cross-border crime cooperation

The European Commission has proposed new measures to strengthen EU cooperation against cross-border crime, organised criminal networks, terrorism and hostile actors.

The Commission said crime is becoming more sophisticated, international and digital, requiring closer cooperation between police, customs authorities, prosecutors and courts from the start of investigations through to final judgments.

The package would strengthen the roles of Europol and Eurojust, the EU agencies that support national authorities in cross-border criminal investigations and judicial cooperation.

For Europol, the proposal would enable faster and more automated information sharing to support real-time collaboration during investigations. It would also create Europol Support Offices, staffed by former Europol officers, to provide operational assistance to the EU countries.

The Commission also wants to establish a technology and innovation hub within Europol to map law enforcement capability needs across the EU and support the use of new tools against cross-border crime.

Eurojust would receive stronger operational powers, including the ability to act on its own initiative to identify links between cases. Its mandate would also expand into emerging areas of crime, including cybercrime and gender-based violence.

The package would strengthen cooperation between Europol, Eurojust and the European Public Prosecutor’s Office, while also expanding international cooperation with third countries.

The Commission is also proposing to update the European Investigation Order, the EU procedure for gathering evidence across borders in criminal cases. A new European Remote Participation Order would allow suspects, accused persons and victims to take part remotely in criminal court hearings from another EU country.

Why does it matter?

Cross-border crime is increasingly digital and difficult for national authorities to tackle on their own. The Commission’s proposal aims to make EU investigations faster and more coordinated by improving data sharing, evidence gathering and cooperation between police, prosecutors and courts. The cybercrime and technology-hub elements are especially relevant because law enforcement agencies need technical capacity, legal tools and cross-border coordination to respond to digital criminal networks.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

Spain moves closer to hosting one of Europe’s first AI gigafactories

Spain has taken another significant step in its effort to become a leading European hub for AI and advanced computing infrastructure.

The Council of Ministers has approved a €300 million voluntary contribution to the European High Performance Computing Joint Undertaking (EuroHPC), the body responsible for supporting Europe’s AI factories and the future development of AI gigafactories.

According to the Ministry for Digital Transformation and Public Administration, the contribution is a critical component of Spain’s bid to host one of the EU’s first AI gigafactories.

The government argues that access to large-scale computing infrastructure is becoming essential for researchers, universities, startups and businesses seeking to develop advanced AI systems and remain competitive in an increasingly AI-driven economy.

The investment builds on Spain’s existing role within Europe’s supercomputing ecosystem. The country already hosts AI factories at the Barcelona Supercomputing Center and the Galician Supercomputing Center, while the MareNostrum 5 supercomputer has supported projects ranging from genomic research to climate and digital twin initiatives.

The funding also aims to strengthen Spain’s position in quantum technologies, an area increasingly viewed as strategically important for Europe’s long-term technological autonomy.

The announcement reflects a wider European push to expand sovereign computing capabilities as demand for AI training infrastructure grows worldwide.

By seeking to host an AI gigafactory, Spain hopes to attract investment, support innovation, strengthen domestic technological capabilities and position itself as a central player in Europe’s next-generation AI ecosystem.

Why does it matter?

Access to large-scale computing infrastructure is becoming a strategic prerequisite for advanced AI development. Training frontier AI models, running large-scale simulations and supporting scientific research require computing resources that are increasingly concentrated among a small number of global technology providers. Spain’s investment seeks to strengthen both national and European capacity in this critical area.

The announcement also reflects the EU’s broader push for technological sovereignty. By expanding domestic AI and supercomputing infrastructure, Europe aims to reduce dependence on foreign computing resources, support innovation ecosystems and ensure that advanced technologies are developed within frameworks aligned with European values, regulations and industrial priorities. The competition to host AI gigafactories is therefore as much about economic competitiveness and strategic autonomy as it is about computing power.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

EU drops browser-based cookie consent proposal from Digital Omnibus

The European Commission had proposed replacing cookie banners with an automated browser-based privacy signal as part of its ‘Digital Omnibus’ package, a move that would have allowed devices to communicate users’ tracking preferences directly to websites. The plan, outlined in Article 88b of the GDPR, was intended to cut red tape and reduce the burden on consumers navigating consent requests across the web.

According to digital rights organisation noyb, cookie banners were not created by data protection law but emerged as a mechanism for the online advertising industry to obtain users’ consent for data sharing with third parties. Studies suggest only 3 to 10 per cent of users actually wish to be tracked, yet so-called dark patterns, such as hidden ‘no’ buttons and pre-ticked boxes, allow the industry to achieve consent rates of up to 90 per cent. Across more than 450 million EU citizens, this results in billions of unnecessary clicks each year.

According to noyb, a lobbying document submitted by Google argued that removing cookie banners would effectively halt all online advertising, citing figures that the European Commission has since described as highly exaggerated. The Commission had made clear that consent would still be possible on a per-website and per-purpose basis, meaning users could grant access to specific outlets while withholding it from others. Google’s paper also claimed that media outlets would be harmed, despite the fact that they are explicitly exempt from the proposed provision.

According to noyb, the lobbying campaign appears to have influenced the legislative process. In the Council’s position paper of 18 June 2026, Article 88b was removed entirely from the Digital Omnibus. Noyb added that Germany, France, and Poland were among the member states supporting the article’s removal following lobbying by the online advertising industry.

The outcome is particularly striking given that many of the same member states have long called on the EU to simplify regulation and cut red tape. noyb, the European digital rights organisation, has described the result as a victory for lobbying over public interest, noting that the majority of EU citizens have consistently expressed frustration with cookie banners.

The European Parliament has not yet taken a position on Article 88b, and negotiations between the Parliament and the Council are ongoing. Noyb has urged the European Parliament to support reinstating Article 88b during the next stage of negotiations.

Why does it matter?

The debate highlights the growing tension between digital simplification efforts, privacy protection and the economic interests of the online advertising ecosystem. Browser-based privacy signals have long been discussed as a way to reduce repetitive consent requests while preserving users’ ability to decide when and how their personal data may be used.

The proposal’s removal also illustrates the influence that industry stakeholders can have during the EU legislative process. Whether Article 88b is reinstated during negotiations with the European Parliament could shape the future of online consent management in Europe, affecting digital advertising, user experience and the practical implementation of data protection rules.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot

Google expands financial ad verification across EU and EEA

Google has announced the expansion of its financial services advertiser verification programme to every country in the EU and European Economic Area, extending requirements aimed at reducing fraudulent financial advertising.

The rollout will cover 24 additional countries and builds on an existing programme already active in six EU member states and the United Kingdom.

Under the programme, advertisers seeking to promote financial products or services must complete an additional verification process showing that the relevant national regulator authorises them. Google said it will check credentials against official registries across the EU and EEA.

The requirements will be introduced in phases. Businesses will have 30 days to complete the process after notification, and unverified advertisers will have their financial services ads restricted until verification is completed.

Google said the additional requirements build on its wider advertiser identity verification programme, which it says already covers more than 98% of ads seen across the EU. The company also said its systems blocked or removed more than 1.6 billion ads in the EU last year.

The expansion comes amid continuing concern over online financial scams, including fraudulent ads that impersonate legitimate financial services providers or promote misleading investment products.

Why does it matter?

Financial scams increasingly rely on digital advertising to reach consumers at scale. Google’s expansion adds another gatekeeping layer for financial advertisers across Europe by linking ad eligibility to authorisation in official regulatory registers. The measure also shows how large platforms are being pushed, by regulators and reputational pressure, to take more responsibility for the trustworthiness of high-risk advertising categories such as finance.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

EU launches ADACities for autonomous driving

The European Commission has launched the Autonomous Drive Ambition Cities initiative to support the deployment of autonomous driving technologies in cities across the EU.

The initiative, known as ADACities, was announced by Executive Vice-President Henna Virkkunen during the first international forum of the European Connected and Autonomous Vehicle Alliance in Brussels.

The Commission said ADACities will serve as a mobility flagship under the Apply AI Strategy, allowing selected EU cities to become real-world deployment sites for autonomous mobility innovation.

The initiative will support technologies such as robo-taxis, car-sharing services, autonomous shuttles for multimodal urban mobility and advanced self-driving cars. Participating cities will target fleets of 100 or more autonomous vehicles by 2030.

The Commission said partnerships supported by ADACities should be EU-centric, with European vehicle manufacturers and technology providers at the core, while still allowing international collaboration.

The initiative is also linked to the EU Technological Sovereignty Package. The Commission said autonomous driving deployment will draw on European capabilities in semiconductors, sovereign cloud and data infrastructure, AI Factories and open-source technologies.

ADACities builds on a joint declaration of intent to create a cross-border testbed for automated vehicle deployment. The Commission has opened a call for expressions of interest and will hold an online information session for cities and stakeholders.

Why does it matter?

ADACities shows how the EU is treating autonomous driving as part of AI deployment, urban mobility and industrial competitiveness, not only as a transport technology. By linking autonomous mobility to sovereign cloud, semiconductors, data infrastructure and AI Factories, the Commission is framing city-level deployment as a test of Europe’s ability to turn AI and automotive expertise into scalable public services. The initiative also raises governance questions around safety, liability, infrastructure readiness, data use and public trust.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

EU agrees tougher child protection rules against AI-generated abuse

The agreement between the European Parliament and the Council updates legislation first adopted in 2011, reflecting the growing role of digital technologies and AI in facilitating abuse.

Under the revised directive, designing, adapting or distributing AI systems intended to generate child sexual abuse material would become a criminal offence. The updated rules would also cover deepfake abuse material, livestreamed child sexual abuse, sexual extortion, and the possession or distribution of instructions on how to commit such crimes.

The agreement also strengthens rules on consent. It clarifies that consent must be given voluntarily, cannot be inferred from silence, lack of resistance or a previous relationship, and can be withdrawn at any time.

Grooming offences would be expanded to cover situations involving coercion, threats or deception, including cases where offenders falsely present themselves as peers of the child.

Victim protection would also be strengthened through access to healthcare, legal aid, helplines, accommodation support and compensation mechanisms. The agreement also extends limitation periods, recognising that many victims need years or decades before reporting abuse.

The revised directive still requires formal adoption by the European Parliament and the Council before entering into force.

Why does it matter?

The agreement shows how EU criminal law is being adapted to AI-enabled and online forms of child sexual abuse. Criminalising AI systems designed to generate abusive material is especially significant because it targets not only harmful content but also the tools used to produce it. The revised directive also strengthens victim support and prosecution timelines, addressing the reality that many survivors report abuse years after it occurred.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!  

EU selects EUROPA consortium to build multilingual frontier AI model

The European Commission has selected the EUROPA consortium, led by Italian company Domyn, as the winner of its Frontier AI Grand Challenge. The project will develop a large-scale open-source AI model capable of operating across all 24 official languages of the EU.

Launched in February 2026, the competition challenged European AI innovators to propose a frontier model exceeding 400 billion parameters, a scale typically associated with some of the world’s most advanced AI systems.

The Commission said the initiative demonstrates Europe’s capacity to develop advanced AI using its domestic talent, infrastructure and industrial capabilities.

The EUROPA model will be openly accessible and designed to support businesses, researchers, public institutions and developers across the EU. By covering every official EU language, the project aims to address Europe’s linguistic diversity while expanding access to advanced AI technologies.

The Commission views the project as a strategic step towards greater technological sovereignty, strengthening Europe’s AI ecosystem while promoting openness, trust and European values in AI development.

Why does it matter?

The EUROPA project reflects Europe’s growing determination to develop advanced AI capabilities within its own technological ecosystem. As AI becomes increasingly important for economic competitiveness, public services and scientific research, access to large-scale models is emerging as a strategic capability alongside semiconductors, cloud infrastructure and high-performance computing.

The initiative is also notable for its focus on linguistic diversity and open access. By developing a frontier model capable of operating across all 24 official EU languages and making it openly available, the project aims to broaden participation in AI innovation while reducing dependence on a small number of predominantly US-based providers. Its success could become an important test of Europe’s ability to combine technological sovereignty with open and collaborative AI development.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

EU and OECD launch AI literacy framework for schools

The European Commission and the OECD have presented a new AI literacy framework for primary and secondary education, aimed at helping schools prepare learners for a world increasingly shaped by AI technologies.

The AI Literacy Framework was unveiled on 18 June during the European Digital Education Hub flagship event in Brussels. The event, titled ‘Collaborate for Impact: Advancing European Digital Education and Skills’, brought together policymakers, educators, experts, and stakeholders from across Europe.

Developed with support from international experts, including CodeAI, the framework provides a common reference point for integrating AI literacy across education systems. It is accompanied by practical classroom examples for primary and secondary levels to help educators translate AI literacy into learning experiences.

The framework defines AI literacy as the combination of technical knowledge, durable skills and future-ready attitudes needed to participate effectively in a world influenced by AI. It aims to help learners engage with, create with, manage, and shape AI while critically evaluating its benefits, risks, and ethical implications.

The European Commission said AI is reshaping how people learn, work, communicate, and make decisions. It said education systems need to prepare young people to navigate AI in daily life and use it responsibly.

The framework defines AI literacy as the combination of technical knowledge, durable skills and future-ready attitudes needed to participate effectively in a world influenced by AI.

According to the Commission, 68% of teenagers already use AI tools, yet many education systems still lack structured approaches for integrating AI into teaching and learning. Addressing these barriers could help learners use AI more creatively, ethically, and effectively.

The framework is intended for teachers, education leaders, policymakers, and learning designers. It offers guidance on curriculum integration, school-level AI literacy initiatives, policy development, and the design of educational content and teacher training materials.

The framework is structured around four dimensions that describe how learners engage with, create with, manage, and shape AI. It also includes 19 competences organised around knowledge, skills, and attitudes, along with learner expectations, learning scenarios, and classroom examples.

The Commission said the framework supports the EU’s ambition to deliver high-quality, inclusive, and future-oriented digital education. It also contributes to the Digital Education Action Plan and the Union of Skills by helping learners develop competences for a digital and AI-driven society.

The framework complements several European initiatives and policy priorities, including the PISA 2029 Media and AI Literacy assessment, the Digital Education Action Plan 2021-2027, updated ethical guidelines for educators on AI use, the AI Act, and the European Digital Competence Framework.

Why does it matter?

AI is rapidly becoming a foundational digital skill, comparable to information literacy or internet literacy. As AI tools become increasingly integrated into education, work and everyday life, schools face growing pressure to help students understand not only how to use these technologies, but also how to evaluate their outputs, recognise their limitations and engage with them responsibly.

The framework also represents an important step towards harmonising AI education across Europe. By providing common competences, classroom examples and guidance for educators, it creates a bridge between AI policy objectives and practical teaching. This could help ensure that future generations develop the skills needed to participate in an AI-driven society while supporting broader European goals related to digital skills, innovation and trustworthy AI.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

EDPS and EU data protection officers focus on AI, cybersecurity and compliance

The European Data Protection Supervisor (EDPS) and data protection officers (DPOs) from EU institutions, bodies, offices and agencies met in Brussels on 18 June to discuss emerging data protection priorities and compliance challenges.

The 58th meeting of the EDPS-DPO network was hosted by the Executive Agencies of the European Commission. The meeting brought together DPOs from across the EU administration at a time of significant regulatory and technological change.

European Data Protection Supervisor Wojciech Wiewiórowski opened the meeting by emphasising the importance of safeguarding DPO independence in practice. He pointed to recent EDPS action, guidance, and procedures intended to safeguard the role of DPOs across EU institutions.

Wiewiórowski also reviewed key developments from 2025, including the closure of the EDPS investigation into the European Commission’s use of Microsoft 365, a rise in complaints, and the growing impact of AI-generated submissions. He noted that regulatory simplification should reduce unnecessary administrative burdens without undermining fundamental rights protections.

Thomas Zerdick, Head of the EDPS Supervision and Enforcement Unit, introduced a follow-up tracker designed to maintain continuity between EDPS-DPO meetings. The first tracker focused on EDPS supervisory guidance on the role of DPOs in EU institutions and the EDPS decision on prior consent to DPO dismissal.

Zerdick also presented recent developments in supervision and enforcement, including complaint handling, compliance issues affecting several EU institutions, and practical guidance on international transfers and data protection impact assessments. The update also covered work linked to the Area of Freedom, Security and Justice, including audits, opinions, and preparations for upcoming systems.

Luis Velasco, Head of the EDPS Technology and Privacy Unit, outlined initiatives to help EU institutions meet compliance requirements for automated systems and AI. He announced that an updated version of the EDPS guidance on risk management for AI systems is expected to be published later this summer.

Velasco also referred to a practical checklist on human intervention, intended to help organisations establish effective safeguards for automated systems. He warned that cyberattacks targeting EU institutions pose a growing threat and pose serious risks to individuals’ personal data.

The discussion also addressed the response to a personal data breach. Velasco stressed that individuals affected by a personal data breach should be informed without undue delay when a breach is likely to pose a high risk to their rights and freedoms.

A practical workshop focused on developing a common data protection impact assessment template under the EU Data Protection Regulation. Participants tested a draft template through a case study and discussed issues, including necessity, proportionality, and risk assessment.

The afternoon sessions included a discussion of the 2024 data breach at the European Agency for Law Enforcement Training. The CEPOL DPO and the EDPS Data Breach Notification Team shared lessons with the wider DPO community, highlighting that major data breaches create organisational and human challenges as well as compliance obligations.

The meeting also included a session on privacy and data protection case law, presented by Zerdick. The session focused on the EDPS’s interpretation of recent judgments and their practical implications for supervisory work and controllers.

Participants also received an update on the EDPS Website Compliance Awareness Campaign. Following pilot phases in 2024 and 2025, the Technology and Privacy Unit presented preliminary findings from the first wave of the campaign’s second phase, which involved automated scans of public-facing websites of EU institutions.

The EDPS said the meeting demonstrated the value of bringing together the EU’s DPO community to address shared challenges, exchange practical experience and strengthen compliance across institutions. The discussions focused on practical cooperation, support for compliance, and stronger data protection safeguards across the EU administration.

Why does it matter?

The meeting highlights how data protection within EU institutions is evolving beyond traditional compliance issues toward broader challenges involving AI governance, cybersecurity, automated decision-making and digital service oversight. As public administrations increasingly adopt AI-enabled systems and process larger volumes of personal data, data protection officers are playing a more strategic role in managing operational and regulatory risks.

The discussions also illustrate a growing emphasis on practical implementation. Common templates, coordinated guidance and shared lessons from data breaches can help institutions apply data protection rules more consistently across the EU administration. This is particularly important as regulators seek to align privacy requirements with emerging frameworks governing AI, cybersecurity and digital public services.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

Google Cloud urges changes to EU tech sovereignty plans

Google Cloud has urged EU policymakers to revise parts of the European Commission’s Tech Sovereignty Package, arguing that some proposed cloud sovereignty measures could unintentionally isolate the European digital market.

In a policy statement, Giorgia Abeltino, Head of Government Affairs and Public Policy for Google Cloud in EMEA, said Europe requires significant investment in digital infrastructure to strengthen competitiveness, security and technological sovereignty. She said the EU is considering how to expand its digital footprint across chips, cloud adoption, and AI data infrastructure.

Google Cloud said it supports the Commission’s emphasis on openness, partnerships and fair competition, particularly measures aimed at interoperability and reducing vendor lock-in. It welcomed measures on interoperability, efforts to address vendor lock-in, an open source strategy for the public sector, and faster data centre deployment.

However, the company said certain elements of the proposed Cloud and AI Development Act should be changed to avoid unintended market isolation. Google Cloud said trusted global partners should be able to continue supporting Europe’s security and scaling goals under an open framework.

The company said its vision of technological sovereignty is based on verifiable technical controls, customer choice and continued investment in European digital infrastructure. It pointed to its sovereign cloud services, including standard public cloud configurations with European data boundaries, independently operated regional cloud services, and air-gapped solutions for sensitive public-sector operations.

Google Cloud also highlighted partnerships with European companies, including S3NS in France; Thales, Schwarz Group, and T-Systems in Germany; PSN in Italy; Clarence in Luxembourg; and Telefónica in Spain. It said these partnerships support operational resilience and jurisdictional controls under existing national tech sovereignty frameworks.

The company said the S3NS offering in France has been qualified under SecNumCloud 3.2. It also said Clarence and S3NS, together with Mistral, offer services approved by the EU Directorate-General for Digital Services for use by EU institutions with sovereign cloud needs.

Google Cloud also raised concerns about the proposed Union Assurance Levels within the Cloud and AI Development Act. It said harmonising sovereignty criteria across Member States is useful, but argued that the proposed criteria could limit or exclude global providers regardless of the security safeguards they offer.

The company said EU rules should allow technical approaches to sovereign control rather than relying too heavily on geographic criteria. The company cited its Cloud External Key Manager as an example of a technical sovereignty mechanism that allows customers to retain control of encryption keys outside Google’s infrastructure.

Google Cloud also called for the Cloud and AI Development Act to follow a more balanced approach similar to the proposed Industrial Accelerator Act. The company said trusted non-EU partners should be able to operate as EU-origin under clear conditions, backed by trade rules and safeguards.

The company also backed the package’s goal of promoting interoperability and reducing vendor lock-in. It said tech sovereignty should increase user choice and argued for reforms allowing users to move software licences freely, ensuring fair pricing for legacy software, and guaranteeing that software runs equally well on any cloud platform.

Google Cloud said physical compute infrastructure is central to digital tech sovereignty. It welcomed the ambitions of Chips Act 2.0 and the proposed 30 billion investment in European semiconductor research and development, but said Europe also needs regulatory conditions that attract large-scale compute infrastructure investment.

The company said it operates 13 European cloud regions and has recently invested in Germany, Belgium, and Sweden. It welcomed proposed special project status for data infrastructure projects to streamline permitting, grid access, and power purchase agreements.

Google Cloud said fast-track permitting should prioritise highly sustainable infrastructure projects. It also called for national sustainability criteria to align with the upcoming EU-wide rating scheme and said acceleration zones should not artificially restrict where new data centres can be built.

The company said Europe has an opportunity to build a resilient, competitive and open digital future. It said global innovation and European values can be advanced together through open source software, sovereign cloud partnerships and collaboration with European policymakers and regional partners.

Why does it matter?

The debate highlights a central challenge in Europe’s digital policy agenda: how to strengthen technological sovereignty without undermining openness, competition and access to global innovation. As the EU seeks greater control over critical digital infrastructure, cloud services and AI capabilities, policymakers must decide whether sovereignty should be defined primarily by ownership and geography or by technical safeguards and operational control.

The outcome could have significant implications for the future European cloud and AI market. Rules governing sovereign cloud services, data infrastructure and assurance standards will influence investment decisions, public-sector procurement, competition among providers and Europe’s ability to develop advanced AI capabilities. The discussion also reflects broader tensions between strategic autonomy and international technology partnerships that are increasingly shaping digital policy worldwide.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!