01 – ΕΘΝΙΚΗ ΣΤΡΑΤΗΓΙΚΗ ΓΙΑ ΤΗΝ ΤΕΧΝΗΤΗ ΝΟΗΜΟΣΥΝΗ ΤΗΣ ΚΥΠΡΙΑΚΗΣ ΔΗΜΟΚΡΑΤΙΑΣ
Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας
Μπορείτε να κατεβάσετε το κείμενο στo σχετικό υλικό
Τέλος
Μπορείτε να κατεβάσετε το κείμενο στo σχετικό υλικό
Τέλος
IBM Feedback on the Cyprus National AI Strategy 2032
IBM welcomes the opportunity to participate in the ongoing public consultation on the National AI Strategy 2032 of the Republic of Cyprus and appreciates the efforts of the Chief Scientist, the National AI Taskforce and the Deputy Ministry of Research, Innovation and Digital Policy in developing a comprehensive national vision for artificial intelligence. We also recognise and strongly support the significant effort undertaken by the Strategy Committee. The Strategy sets out an ambitious objective for Cyprus to become a trusted AI hub in the Eastern Mediterranean, a reliable European jurisdiction for AI-enabled services, and a bridge between the European Union and neighbouring regions by 2032.
IBM strongly supports the Strategy’s overarching goal of fostering trustworthy and responsible AI adoption and welcomes the Government’s commitment to engaging stakeholders through this public consultation process. In this spirit, we offer our recommendations with the objective of strengthening the Strategy’s contribution to innovation, competitiveness, cybersecurity, and the development of an open and globally connected AI ecosystem. In our comments, we highlight that the strategy should remain technology-neutral, risk-based, and aligned with the EU Single Market. Achieving the Strategy’s objectives will also require sustained investment in future-ready skills and close alignment between the Strategy’s AI ambitions and the evolution of hybrid cloud and quantum technologies, which together will underpin the next generation of secure and high-performance computing.
1. Coordinate AI, quantum computing and cybersecurity strategies
The AI Strategy should be implemented with holistic approach, in coordination with policies and investments in quantum computing, high-performance computing and cybersecurity. These technologies are increasingly complementary: AI can accelerate the design, calibration and operation of quantum systems, while quantum computing may open new avenues for machine learning, optimisation and scientific discovery. Policymakers should therefore foster integrated ecosystems in which AI, quantum processors and classical high-performance computing resources can be combined through open, interoperable and hybrid computing architectures. This should include coordinated investment in infrastructure, research, skills and early-stage industrial experimentation, as well as collaboration with international technology providers and research partners.
This coordination must also address the cybersecurity implications of quantum computing. Future cryptographically relevant quantum computers could undermine widely used public-key cryptography, while “harvest now, decrypt later” attacks already create risks for sensitive data with a long confidentiality life. Our recommendation is therefore to start integrating post-quantum cryptography into AI, cybersecurity and critical-infrastructure planning now, rather than treating quantum safety as a future issue. AI solutions can help critical organisations accelerate specific stages of the migration process, including the preparation of cryptographic asset inventories and quantum-risk assessments. Ultimately, these efforts should align with the EU’s coordinated PQC roadmap and internationally recognised standards, while accounting for supply-chain dependencies and the long lifecycle of operational technology and critical infrastructure.
2. Preserve technical approach and avoid origin-based sovereignty criteria
IBM supports the objective of strengthening digital sovereignty and trust in AI. However, sovereignty should be assessed based on the degree of technical, operational, and legal control exercised by customers over their data, systems, and business continuity, rather than provider’s nationality or headquarters location.
In particular, we welcome the Strategy’s focus on building partnerships in Section 3.7 – however, the approach should be clearer to avoid interpretations that discriminate companies based on their country of origin. Requirements should be based on verifiable security, resilience, transparency, and governance outcomes, ensuring open competition and access to best-in-class technologies.
3. Avoid national gold-plating beyond the EU AI Act
The strategy should build on existing EU legislation, including the AI Act, GDPR, and sectoral frameworks, without introducing additional national requirements that could create regulatory fragmentation. Consistency with EU rules will reduce compliance burdens, improve legal certainty, and support the development and deployment of AI solutions across the Single Market.
4. Accelerate AI adoption in priority sectors
IBM welcomes the Strategy’s focus on sectors in which Cyprus has established economic strengths and where AI can deliver significant productivity, competitiveness and public-value gains, as outlined in Section 3.5. We recommend that the Strategy translates into concrete sectoral roadmaps, supported by access to trusted data, secure hybrid-cloud infrastructure, skilling initiatives, testbeds and regulatory sandboxes. Particular attention should be given to the following sectors:
– Tourism and hospitality: AI can support demand forecasting, personalised visitor services, multilingual assistance, destination management, resource optimisation and more sustainable tourism.
– Healthcare and life sciences: AI can augment clinical decision-making, improve patient pathways and preventive care, support resource planning and accelerate research, subject to strong protections for sensitive health data, governance and human oversight.
– Financial services and fintech: AI can strengthen fraud detection, risk management, compliance, customer due diligence and operational efficiency.
– Energy: while this sector is not highlighted in the Strategy, we emphasise that AI can optimise grids and renewable-energy integration, forecast demand, improve asset maintenance and energy efficiency, and increase the resilience of critical infrastructure.
A coordinated approach across these sectors would create reusable capabilities and economies of scale, accelerate diffusion among smaller enterprises, and enable successful solutions developed in Cyprus to expand across the EU Single Market and internationally.
5. Foster innovation through proportionate governance
Trustworthy AI provides the foundation for sustainable innovation. At the same time, Governance mechanisms should be proportionate, risk-based, and targeted at high-risk use cases.
The strategy should encourage experimentation, AI sandboxes, public-private collaboration, and rapid adoption of beneficial AI applications. Excessive approval layers, mandatory certifications, or broad compliance obligations risk slowing deployment, increasing costs, and reducing the attractiveness of Cyprus as a destination for AI investment and innovation.
The Strategy should also recognise the shift from governance based primarily on policies, assessments, and periodic human review towards the technical enforcement of risk and compliance requirements at runtime. While not every control can be automated, this evolution is particularly important for agentic AI systems, where risks may emerge dynamically across multi-step workflows and cannot be addressed adequately through human processes alone. Section 3.3.2 should therefore explicitly promote the implementation of proportionate runtime controls to complement organisational governance and enable scalable, trustworthy deployment.
6. AI skills
IBM welcomes the Strategy’s strong focus on AI skills, workforce development, and lifelong learning. We particularly support the recognition that AI should be used to augment human capabilities and productivity, enabling people to work more effectively alongside AI systems rather than simply automating tasks.
To ensure that skills programmes remain aligned with rapidly evolving technologies and labour market needs, Cyprus should promote close collaboration between government, academia, and industry in the design and delivery of AI education, training, and reskilling initiatives. Such partnerships will be critical to developing a future-ready workforce and supporting the successful adoption of AI across the economy.
Conclusion
We recommend that the Strategy positions Cyprus as an open, innovation-friendly AI hub by combining strong security and governance with technology neutrality, support for AI development, interoperability with international standards, and full alignment with the EU Single Market.
It is suggested that the Research and Innovation focus areas be reviewed to consider the inclusion of Culture and Creativity as a dedicated Research Focus Area or strategic cross-cutting research domain. This could represent an area in which Cyprus has the potential to develop a distinctive position at European level.
Cyprus already has a strong foundation on which to build, including an established creative and cultural ecosystem, a growing games and digital creative industries sector, and a solid base of researchers, technologists and experts. Bringing these capabilities together could create a strong environment for applied research and innovation at the intersection of AI, culture, creativity, digital heritage, gaming and immersive technologies.
This direction is also increasingly aligned with EU research and innovation priorities. Initiatives such as the Culture Compass for Europe, Horizon Europe, the New European Bauhaus, EIT Culture & Creativity and S+T+ARTS increasingly recognise the convergence of culture, creativity, research and technology as an important driver of innovation, competitiveness and societal impact.
Such a focus could also have a direct positive impact on tourism, by enabling the development of new cultural experiences, immersive heritage applications, AI-enhanced visitor experiences and innovative ways of presenting Cyprus’s cultural assets. In this way, investment in culture and creativity could also contribute to strengthening the competitiveness and attractiveness of Cyprus as a destination.
Similarly, it could support the growth of the games industry by fostering the development and adoption of AI, immersive technologies, digital storytelling and creative technologies, while creating stronger links between research, talent and the emerging games and digital creative industries ecosystem in Cyprus.
First off, congratulations to the team of experts that put together this national AI strategy. It is the first of its kind, and while we will be commenting on points that might require clarification, we want to be clear that we support the effort as well as the prompt for public consultation before the strategy is enacted into law.
1. Comment 1 — National AI Authority: undefined legal basis and mandate
Αρ. Άρθρου και εδαφίου: Section 3.3.1.1 (National AI Authority), page 23–24; cross-referenced with Section 2.5.1, page 16
Comment:
The Strategy establishes the National AI Authority as “policy coordination and execution body” and “governance and control gatekeeper” with a “clear political mandate,” but does not specify the legal instrument creating it, its statutory powers, its enforcement or sanctioning authority, or its relationship to the AI Act’s designated competent and market-surveillance authorities. The only defined element of its establishment is procedural (designation by the President, ratified by the Council of Ministers) — a political appointment mechanism, not a legal competence framework. Section 2.5.1 compounds this by referring separately to oversight by “appropriate competent authorities as defined by the Government,” without reconciling this with the Authority’s own gatekeeper function.
Requested amendment: Before final adoption, the Strategy should specify (a) the legal act by which the Authority will be established (law, decree, or otherwise), (b) an exhaustive list of its powers, including whether it has binding decision-making, sanctioning, or only coordinating/advisory authority, and (c) an express statement of how its mandate is bounded relative to existing and AI Act-mandated competent authorities.
Grounds: A body given a “gatekeeper” label without a defined legal basis creates regulatory uncertainty for businesses and investors — precisely the opposite of the “trusted jurisdiction” outcome the Strategy seeks under Objective 1. This ambiguity also creates litigation and compliance risk for private-sector actors who cannot determine which body’s guidance is authoritative.
Comment 2 — Overlap between the National AI Authority and existing regulatory bodies
Αρ. Άρθρου και εδαφίου: Section 3.3.1.1, page 23; Legal Services pillar (NAICF), page 35; Section 2.5.1, page 16
Comments:
The Authority’s stated functions — “establishing common frameworks and standards” and “compliance oversight” — duplicate functions already assigned by law to sector regulators (e.g., CySEC for financial services, the Digital Security Authority for cybersecurity) and to the national standardisation body. Similarly, the proposed National AI Compliance Framework (NAICF) is described as supporting “certification, auditing, and regulatory oversight,” without clarifying how this sits against statutory conformity-assessment procedures under Regulation (EU) 2024/1689, or against the powers of national competent authorities under Article 74 of that Regulation.
Requested amendment: The Strategy should include an explicit division-of-functions table or section distinguishing (a) policy coordination and strategic direction (appropriate for the National AI Authority), from (b) statutory supervision, enforcement, and conformity assessment (which remain with existing competent authorities), and (c) standards development and adoption (which falls within the remit of the national standardisation body). NAICF’s certification and auditing language should be reframed as support tools that do not themselves constitute or replace formal regulatory determinations.
Grounds: Without this clarification, businesses face parallel or conflicting compliance expectations from multiple bodies, and there is a real risk that NAICF outputs could be mistaken for, or represented as, formal EU-recognised certification when they are not. This also risks institutional duplication and wasted public resources — a concern already raised independently by CYS and the Office of the Commissioner of Electronic Communications in this consultation, which supports treating it as a priority fix.
Comment 3 — Breach determination rests on the judgment of a single individual, with no institutional check (emphasis on this point):
Αρ. Άρθρου και εδαφίου: Section 1.7 (Methodology), page 7; Section 3.3.1.1 “AI Officers,” page 27; Section 3.3.2 “Control Framework,” page 27–28
Comments:
The Strategy repeatedly concentrates the responsibility for identifying non-compliance, ethical breaches, or governance failures in a single office rather than an institutional or collective mechanism:
The Chief Scientist for Research, Innovation and Technology is named the sole “accountable custodian” of the entire Strategy.
Each ministry is assigned one AI Officer, described as the “focal point for AI” who is personally responsible for “ensuring compliance with governance, legal, and ethical requirements.” The complementary AI Ambassador/Champion role is limited to adoption and promotion, not compliance determination — so, in practice, breach identification within each ministry rests on one individual’s judgment. The Control Framework (Section 3.3.2) requires “clear procedures for incident reporting, escalation, and remediation” but does not specify who makes the initial determination that a breach or failure has occurred, nor does it provide for any second-reviewer, peer-review, or independent verification step.
This is compounded by the fact that AI Officers are provided by, and functionally report to, the National AI Authority — the same body whose own conduct or initiatives they may need to flag.
Requested amendment: Replace single-officer breach determination with a documented two-step or panel-based process for any finding of non-compliance or incident above a defined risk threshold — for example, requiring sign-off or review by a second designated person or by the relevant oversight committee (e.g., the National Ethics and Values Committee or National AI Infrastructure Committee) before a breach finding is closed or escalated. The Strategy should also state explicitly how an AI Officer would report a concern involving the National AI Authority itself, to avoid a structural conflict of interest.
Grounds: Placing sole responsibility for detecting and calling out breaches on one person per ministry — without independent review, and without a defined channel for reporting concerns about the appointing Authority itself — creates a single point of failure in the entire governance and control architecture (Section 3.3), undermining the “robust governance and control mechanisms” the Strategy itself identifies as its intended outcome. This is a structural, not a resourcing, problem, and cannot be solved simply by staffing the role adequately.
Thank you to all for their contribution and to the Chief Scientist who spearheaded this initiative, which is aimed at improving the way we live, work and operate in today’s technological environment in Cyprus.
The National AI Strategy 2032 appropriately identifies Healthcare and Life Sciences as a priority domain and includes important directions such as national health-data infrastructure, AI-supported triage and care navigation, digital clinical support tools, interoperability, security and regulatory compliance. These provide a credible foundation. However, the health component remains primarily focused on the digital enhancement of the existing healthcare-delivery model. It could be strengthened by articulating a more integrated, preventive and scientifically advanced model in which AI supports precision health, biomedical innovation, population health and safer patient care.
Precision health and multimodal data
A key gap is the limited integration of precision-health principles. Future national health-data infrastructure should not be confined to electronic health records, prescriptions, laboratory results and imaging. Cyprus should develop a longitudinal, multimodal precision-health data infrastructure.
Digital Healthcare Twin
The proposed Digital Healthcare Twin also requires a clearer scientific and operational definition. A health digital twin should be more than an advanced electronic record or an AI-generated summary. It should represent a dynamic longitudinal model integrating clinical, biological, imaging, medication, behavioural and environmental data and should be subject to defined standards for scientific validation, clinical utility and regulatory oversight. Without these safeguards, there is a risk that the concept remains technologically attractive but clinically insufficiently defined.
Healthy ageing and longevity
The strategy would benefit from a more explicit focus on healthy ageing and healthy longevity. Population ageing, multimorbidity, polypharmacy and frailty will increasingly affect healthcare demand and system sustainability. AI can support the prediction of frailty and functional decline, early identification of cardiometabolic and neurodegenerative risk, optimisation of pharmacotherapy and deprescribing, and personalised preventive interventions.
Patient safety and quality of care
Patient safety and quality of care should be positioned as central objectives of health-related AI. Success should not be assessed only by speed, efficiency or cost savings, but by demonstrable improvements in clinical outcomes and reduction of preventable harm. AI could contribute to medication-safety surveillance, detection of adverse drug reactions and interactions, identification of clinical deterioration, reduction of diagnostic and prescribing errors, and improved continuity of care. High-risk applications should be subject to robust local clinical validation, human-in-the-loop oversight, transparent accountability, incident-reporting mechanisms and continuous post-deployment monitoring for bias, model drift and systematic error. AI should strengthen, rather than replace, professional judgement, accountability and the therapeutic relationship.
From a data repository to a learning health system
The proposed national health-data infrastructure should also evolve beyond the concept of a repository towards a National AI-enabled Learning Health System. In such a model, routine care, research data, intervention outcomes and AI-supported analysis form a continuous learning cycle in which new evidence is systematically returned to clinical practice and policy. This would allow the health system itself to become progressively more evidence-generating and adaptive.
Population health and capacity planning
Another gap is the relatively limited emphasis on AI for population-health intelligence and long-term health-system planning. AI can support disease-burden forecasting, epidemiological surveillance, modelling of healthcare demand, workforce and capacity planning, analysis of geographical inequalities and assessment of the consequences of demographic ageing. A national Population Health and Capacity Intelligence capability could therefore provide strategic support to the sustainability and future planning of the health system.
Life sciences, regulatory science and validation
Finally, the Life Sciences dimension should be broadened beyond healthcare delivery. AI is increasingly relevant across drug discovery and development, clinical-trial design and matching, real-world evidence, pharmacovigilance, pharmacogenomics, medication safety, HTA and regulatory science. Cyprus could consider a national Health AI Regulatory Science and Clinical Validation Sandbox, bringing together the requirements of the AI Act, MDR/IVDR, the European Health Data Space and bioethical governance. Such an environment could support controlled evaluation, local validation and post-market monitoring of AI-enabled health technologies and position Cyprus as a credible European testbed for responsible innovation.
Conclusion
Overall, the Strategy provides a strong basis for the digital transformation of healthcare. Its scientific and policy value would be enhanced by moving from a primarily digital-health perspective towards an integrated framework encompassing precision health, prevention, healthy longevity, patient safety, population intelligence, biomedical sciences and regulatory science. This would enable Cyprus to use AI not only to improve existing services, but to redesign future healthcare around safer, more personalised, preventive and learning-oriented care.
Prof. Christos C. Petrou
petrou.c@unic.ac.cy
General comment
I support the overall direction of the National Artificial Intelligence Strategy 2032, particularly its emphasis on responsible adoption, compliance by design, lifecycle governance and human accountability. My detailed written submission focuses on the intellectual-property and copyright aspects of implementation. The principal recommendations are summarised below.
1. Annex G – Definition of Artificial Intelligence
Comment / suggestion:
For legal and compliance purposes, the Strategy should expressly use the definition of an “AI system” in Article 3(1) of Regulation (EU) 2024/1689. Annex G may retain a plain-language explanation, but it should not narrow or expand the EU definition and should expressly include content generation among possible outputs.
Justification:
A parallel national formulation could create avoidable uncertainty in procurement, compliance and lifecycle assessment. Alignment with the directly applicable EU definition provides a common legal baseline.
2. Compliance by Design and the AI Use Case Lifecycle
Comment / suggestion:
The National AI Compliance Framework and lifecycle control gates should include a proportionate intellectual-property review covering, where relevant, copyright and related rights, database and software rights, trade secrets, confidentiality, contractual restrictions, and ownership and licensing of AI-related assets.
Projects materially relying on third-party material should document relevant sources, acquisition methods, licences or other asserted legal bases and applicable rights reservations.
Justification:
The Strategy already requires legal and risk assessment. Making intellectual-property questions explicit would use the existing governance structure rather than create a new regulatory layer, while addressing issues that are considerably harder to reconstruct after procurement, training or deployment.
3. Public procurement and model governance
Comment / suggestion:
Public-sector AI procurement should include model contractual provisions addressing the roles of providers and deployers, source information, ownership and permitted reuse of government material, confidentiality, evidence preservation, complaint handling, remediation, liability, portability and exit arrangements.
Generative systems presenting a material risk of reproducing protected expression should also undergo proportionate, model-specific testing before deployment and following substantial updates.
Justification:
Public accountability cannot depend solely on supplier assurances. Contractual allocation, documentation and testing make the Strategy’s lifecycle obligations operational and enforceable.
4. Cyprus legal language model
Comment / suggestion:
The proposed Cyprus legal language model should have a project-specific corpus and rights-governance plan covering authoritative sources, privately authored legal material, licences and access terms, citation and source verification, updating, ownership, portability and restrictions on reproduction of protected publications.
Justification:
A national legal AI system must be reliable, current and capable of showing the authority and lawful basis of the material on which it relies. The submission treats this as a suitable flagship project for responsible public-sector AI governance.
5. Legal Services Pillar – “AI Judge Capability”
Comment / suggestion:
The term “AI Judge Capability” should be removed and replaced by an AI-Assisted Small Claims Administration Programme. AI may support filing, triage, administrative calculations, document completeness, drafting and settlement processes, but findings of fact, legal determinations and final orders should remain with human judicial officers.
Justification:
The objective of improving the efficiency of low-value claims is legitimate, but the value of the claim does not remove questions of jurisdiction, evidence, procedural fairness or legal responsibility. The Strategy should preserve an unambiguous distinction between technological assistance and judicial adjudication.
6. Computer-generated works
Comment / suggestion:
The objective of providing “improved protection for computer-generated works” should be reframed as providing greater legal certainty regarding human-authored AI-assisted works, contractual ownership, licensing, provenance and evidence.
Justification:
The current wording appears to assume that additional proprietary protection for autonomously generated output is desirable before resolving questions of human authorship, originality and the limits imposed by EU copyright law. Cyprus can protect investment and contractual certainty without creating a national quasi-copyright for machine-generated material.
7. AIREG
Comment / suggestion:
AIREG should be described as a voluntary, technology-neutral provenance, timestamping and rights-information service. Registration should expressly be non-constitutive and without prejudice to judicial determinations of authorship, originality, copyright subsistence, ownership or infringement.
Justification:
A national registry can provide useful evidence of dates, development history, claimed ownership and licensing, but it cannot itself create copyright or establish an EU-wide presumption of ownership. This reframing preserves the useful evidentiary and investor-confidence objectives of AIREG without overstating its legal effect.
8. European AI Certification Lab
Comment / suggestion:
The proposed European AI Certification Lab should be recast as a Cyprus AI Assurance, Testing and Regulatory Readiness Centre. It may provide testing, benchmarking, documentation reviews, sandbox support and standards mapping, while formal conformity assessment or certification should remain with bodies legally competent to perform the relevant procedure.
Justification:
The concepts of “pre-certification” and “dual recognition” may otherwise suggest formal regulatory authority or international legal equivalence that has not been established.
Closing comment
These recommendations do not seek to create a separate Cypriot copyright regime for artificial intelligence or to predetermine legal questions currently governed by EU copyright law and the courts. The objective is more practical: to ensure that public-sector AI projects identify the rights and sources they use, preserve evidence, allocate contractual responsibility, test foreseeable risks and retain human accountability.
A fuller written submission setting out the legal analysis, comparative material and proposed implementation roadmap is being provided separately.
Article/Section number(s) the comment refers to
Sections 2.5.5 – Objective 5: Develop, attract and retain AI-related skills and talent; 3.3.1.6 – National AI Misinformation and Security Council; 4.1.3 – Human Capital and Workforce Development; as well as the related provisions of the Strategy on Ethics, Fundamental Rights, Transparency and Explainability, and information integrity.
Comment / Recommendation
Strengthening the dimension of journalism, news media, and information integrity in the National AI Strategy
The National Strategy rightly acknowledges the need to address misinformation and disinformation amplified through AI, as well as the need to strengthen information integrity while respecting freedom of expression. It also provides for the establishment of a National AI Misinformation and Security Council and the development of AI literacy and sector-specific competencies.
In this context, it is proposed that the Strategy be further strengthened with more specific provisions for the journalism and information ecosystem, namely:
Specialised training for journalists and media professionals. Journalists and media professionals should be explicitly included in sector-specific AI skills development and professional training programmes. Such training could cover the responsible use of AI tools in journalistic work, content verification, the detection of synthetic or manipulated content, and issues of algorithmic bias, data protection, ethics and transparency.
This proposal can be incorporated into the Strategy’s existing framework, which already provides for basic AI literacy, advanced technical skills and sector-specific competencies, as well as upskilling and reskilling within the context of lifelong learning.
Involvement of media-sector expertise in mechanisms addressing misinformation. Within the framework of the National AI Misinformation and Security Council, it is proposed that the participation of, or structured consultation with, representatives of the journalistic community, media and information literacy specialists, fact-checking organisations, and researchers with expertise in the relationship between AI, news media, and the information ecosystem be ensured.
The Strategy itself assigns to this Council the task of addressing misinformation, disinformation, and related risks, and of providing guidelines and policy recommendations to the competent authorities.
Guiding principles for the use of AI in the information and journalism ecosystem. It is proposed that, in cooperation with the relevant professional and academic bodies, guiding principles be developed for the responsible use of AI in the production and dissemination of news content. Particular emphasis could be placed on transparency regarding the use of AI, human oversight, clear editorial responsibility and accountability, as well as on addressing the risks posed by synthetic and manipulated content.
This proposal is consistent with the Strategy’s existing principles on transparency and explainability, and with its provisions for mechanisms to strengthen information integrity, while respecting freedom of expression.
Justification
Generative AI is transforming not only the economy, employment, and public services, but also the way information is produced, distributed, and consumed.
The ability to generate synthetic text, images, audio, and video at scale creates new challenges for information verification and public trust. The National Strategy itself already acknowledges that AI can amplify misinformation and disinformation, and provides for mechanisms to protect information integrity.
At the same time, AI offers significant opportunities for journalism and the media, including in data analysis, research, the processing of large volumes of information, and the development of new forms of producing and delivering news content.
For this reason, journalism and the media should not be treated merely as another professional sector affected by technological transformation. The quality and integrity of the information environment are directly linked to public trust and the functioning of democratic society.
Including specialised training for media professionals, drawing on relevant journalistic and academic expertise within misinformation-response mechanisms, and developing clear guiding principles could therefore strengthen the Strategy’s existing objectives on AI literacy, information integrity, transparency, accountability, and public trust. The Strategy already establishes governance, ethics, and accountability as a horizontal strategic objective for every use of AI.
Maria Constantinou Journalist | AI and Media Researcher
These recommendations would also strengthen Cyprus’s alignment with the Digital Decade Policy Programme 2030, under which the European Union and Member States are expected to pursue a digitally skilled population and highly skilled digital professionals with the aim of achieving gender balance, including by promoting women’s access to ICT professions.
Comment 1
Article/paragraph reference:
Section 2.5.5, Objective 5 “Develop, attract and retain AI-related skills and talent”
Comment/Recommendation:
The Strategy commits to developing a skilled AI workforce of approximately 3,000 professionals by 2032 but sets no gender composition target or measure for this workforce, nor for the leadership layer above it. We recommend Objective 5 be amended to include an explicit target or monitoring measure for women’s representation in AI leadership and senior technical roles, alongside the existing workforce-size target, and that this be tracked by the National AI Skills Observatory (Section 3.3.1.7) as a standard indicator.
Justification:
Cyprus-specific data indicates the current gap is concentrated at leadership level rather than at entry. The European Institute for Gender Equality’s 2025 Cyprus factsheet records women at 24% of ICT specialists and 26% of management positions, but only 11% of board members at major listed companies — evidence of a leadership transition point, not an entry-point problem. Eurostat places women at 20.1% of ICT specialists in Cyprus in 2025, in line with the EU average of 19.5%. A workforce target without a leadership-composition measure risks growing the base of the pipeline while leaving its narrowest point unaddressed.
Comment 2
Article/paragraph reference:
Section 2.5.3, Objective 3
“Build a strong and inclusive AI ecosystem”
Comment/Recommendation:
The Strategy defines “inclusive” in this objective in terms of SME and non-technology-sector access to AI capabilities. We recommend this definition be extended to explicitly include gender diversity at leadership and governance level within AI-driven organisations, and that capacity-building measures under this objective include AI governance literacy and board-readiness training targeted at women already working in the sector.
Justification:
An inclusive AI ecosystem depends on the diversity of who makes strategic and governance decisions about AI, not solely on access to tools and infrastructure. Given that Objective 7 (Section 2.5.7) assigns governance, ethics and accountability a dedicated national objective, and that AI governance capacity is currently concentrated among a narrow demographic in Cyprus (11% female board representation per EIGE, cited above), broadening this specifically strengthens the resilience and quality of judgement in the governance functions the Strategy identifies as critical.
Comment 3
Article/paragraph reference:
Section 3.5, Priority Sector 6 (Education and Human Capital Development) FutureAI CY flagship programme; and Section 2.5.8, Objective 8, human capital development paragraph
Comment/Recommendation:
FutureAI CY is structured around six priority groups, including “executive leadership” and “senior leadership” tiers, and Objective 8 separately commits to training programmes for “senior leadership” and “mid-management” across sectors. Neither reference includes a gender-specific track or design consideration. We recommend the executive/senior leadership tiers of FutureAI CY explicitly incorporate a leadership-pipeline track for women already in technical or management roles, covering AI governance literacy, board readiness, and scaling into executive positions, delivered in partnership with organisations experienced in this area.
Justification:
Without a targeted design element, general leadership upskilling programmes tend to reach those already closest to promotion, who in Cyprus’s ICT sector are disproportionately male given the 26% management representation versus 11% board representation gap cited above. A specific track addresses the documented transition point directly rather than assuming general leadership training closes it. This recommendation is informed by [Czech partner]’s delivery experience on two prior EU-funded projects addressing tech leadership and women on boards specifically.
Comment 4
Article/paragraph reference:
Section 3.11, “Measuring Impact and National KPIs”; Annex F, Talent and Skills Indicators; and Section 3.3.1.7, National AI Skills Observatory
Comment/Recommendation:
We recommend that the Strategy’s talent and workforce indicators be reported on a sex-disaggregated basis and that the National AI Skills Observatory monitor not only participation in AI education and employment, but also progression, retention and representation across technical, management and senior leadership levels.
At minimum, the monitoring framework should include women’s representation among AI-related professionals, FutureAI CY participants and completers, senior and executive AI roles, and relevant AI governance positions.
Justification:
The Strategy already establishes the National AI Skills Observatory as a mechanism for monitoring the education-to-labour pipeline and provides a national framework for measuring talent and skills outcomes. Incorporating sex-disaggregated indicators into these existing mechanisms would allow Cyprus to assess whether increased investment in AI skills translates into progression and representation across different levels of responsibility.
This is particularly important because aggregate participation figures alone may show growth in the AI talent pool while concealing persistent underrepresentation at senior leadership and decision-making levels. Adding these indicators would provide a clearer evidence base for future policy adjustments, programme design and funding decisions.
Comment 5
Article/paragraph reference:
Section 3.3.1, Governance Structure, particularly Sections 3.3.1.3 to 3.3.1.7
Comment/Recommendation:
We recommend that gender balance be included as a consideration in the composition of the national AI governance, advisory and oversight bodies established under the Strategy, and that the composition of these bodies be monitored and transparently reported.
This should apply particularly to bodies influencing AI ethics, talent and workforce policy, strategic priorities, skills development and national AI implementation.
Justification:
The Strategy recognises that AI governance extends beyond technical implementation and encompasses ethics, accountability, societal impact, workforce transformation and public trust. The bodies responsible for shaping these areas should therefore reflect a sufficiently broad range of leadership perspectives and professional experience.
Current Cyprus data shows that women remain significantly underrepresented at senior economic decision-making level. Incorporating gender balance into the governance structures created under the Strategy would translate the Strategy’s principles of inclusion, fairness and equality into implementation practice.
This recommendation does not require the creation of an additional institution or programme. It can be incorporated into the appointment, monitoring and reporting processes of the governance bodies already envisaged under the Strategy.
Comment 6
Article/paragraph reference:
Section 2.5.3, Objective 3, “Build a strong and inclusive AI ecosystem”, and the related implementation measures concerning AI adoption by SMEs and non-technology sectors
Comment/Recommendation:
We recommend that the Strategy complement access to AI infrastructure, technical capabilities and training with a structured AI Business Readiness and Value Realisation Framework, particularly for SMEs and organisations in traditional, non-technology sectors.
The framework should support organisations in assessing, before significant AI investment or deployment:
• strategic fit and the business problem to be addressed;
• prioritisation of AI use cases according to expected business value and feasibility;
• process, data and organisational readiness;
• workforce and role implications;
• governance, accountability and regulatory considerations;
• implementation capability and change readiness; and
• the expected return and measurable business outcomes of AI adoption.
For publicly supported AI adoption initiatives, we further recommend the use of baseline and post-implementation indicators that measure outcomes such as productivity improvement, cost reduction, revenue impact, service quality, process efficiency, workforce impact and actual organisational adoption.
Justification:
Increasing the number of businesses using AI should not in itself be treated as evidence of successful adoption. The strategic objective should be productive and responsible use of AI that creates measurable economic and organisational value.
A business may acquire an AI solution while lacking the processes, data, internal capability, governance or strategic clarity required to generate value from it. In such cases, technology adoption can increase expenditure and organisational complexity without producing the expected productivity or competitiveness gains.
A national readiness and value-realisation framework would therefore strengthen the connection between AI investment and business outcomes. It would also allow Cyprus to distinguish between technology uptake and meaningful transformation, identify where businesses encounter implementation barriers, and direct future support towards the areas producing the strongest economic impact.
The framework should encourage multidisciplinary implementation, combining technological expertise with business strategy, organisational transformation, governance and sector-specific knowledge, so that technology selection follows a clearly defined business need rather than becoming an objective in itself.
Submitted by:RSEVEN with input informed by WhomLab’s delivery experience on EU-funded (KA210) leadership and governance programmes
Date: 12/08/26
CONTRIBUTION TO THE PUBLIC CONSULTATION ON THE NATIONAL ARTIFICIAL INTELLIGENCE STRATEGY 2032
Strengthening the Execution, Assurance and Measurable Impact of Cyprus’s National AI Strategy
Submitted by: Christina Ioannou
Founder & CEO, Areté Strategy AI Ltd
Global Governance & Regulatory Execution Intelligence Expert
Date: 30 July 2026
The National Artificial Intelligence Strategy 2032 provides an ambitious and important foundation for positioning Cyprus as a trusted, competitive and forward-looking jurisdiction for Artificial Intelligence. The Strategy establishes eight interconnected national strategic objectives covering trusted AI, productivity, ecosystem development, public-sector transformation, talent, secure and interoperable data and infrastructure, governance and accountability, and sovereign national capabilities. These priorities provide a strong strategic direction for Cyprus’s AI transition.
My principal recommendation is therefore not to introduce another standalone initiative or duplicate existing strategic priorities. It is to strengthen the Strategy with a National AI Execution, Assurance & Performance Architecture that connects strategic objectives with implementation, regulatory requirements, institutional accountability, dependencies, measurable outcomes and continuous adaptation.
The central challenge for Cyprus through 2032 will not be AI adoption alone. It will be the ability of the Republic of Cyprus to manage multiple technological, regulatory, financial, institutional and operational dependencies simultaneously while maintaining strategic coherence, accountability and measurable national value.
The Strategy should therefore be designed not only to define what Cyprus wants to achieve, but also to provide a structured mechanism for understanding how national AI priorities are being executed, where dependencies and risks are emerging, whether initiatives are ready to scale, and whether they are producing measurable value.
The proposed architecture would provide this additional execution layer:
Strategy → Portfolio → Dependencies → Regulation → Execution → Assurance → Impact
2. STRENGTHS OF THE NATIONAL AI STRATEGY 2032
The Strategy provides several strong foundations on which Cyprus can build.
2.1 Clear National Direction
The 2032 horizon provides continuity beyond individual projects, funding cycles and technology developments. The ambition to position Cyprus as a trusted European AI jurisdiction and a regional bridge between the European Union and neighbouring regions provides a clear strategic identity for the country.
2.2 Whole-of-Government and Whole-of-Economy Perspective
AI will affect public administration, businesses, research, education, infrastructure, data, cybersecurity, employment and society simultaneously. The Strategy’s broad national approach is therefore appropriate and necessary.
2.3 Responsible and Human-Centred AI
The emphasis on trust, governance, accountability and human control is particularly important as AI systems become increasingly capable and embedded in institutional and economic decision-making. This direction is also consistent with the EU’s risk-based regulatory framework under the AI Act.
2.4 National Infrastructure and Capability
Secure data, infrastructure, computing capacity, digital connectivity, cybersecurity and specialised talent are fundamental components of national AI capability. Cyprus is already advancing initiatives in areas including AI infrastructure, the AI Factory ecosystem, public-sector AI adoption and national digital infrastructure. The strategic opportunity is now to ensure that these capabilities operate as interconnected components of one national system.
2.5 Strong Implementation Orientation
The Strategy’s value will ultimately depend on implementation. The European Commission’s 2026 Digital Decade assessment identifies implementation of the new national AI strategy as an important priority, particularly in accelerating AI adoption by businesses and SMEs. This reinforces the importance of strengthening the execution dimension of the Strategy from the outset.
3. AREAS FOR FURTHER STRENGTHENING
The following observations are intended not as criticism of the Strategy’s strategic direction, but as recommendations for strengthening its implementation architecture.
3.1 National Execution Visibility
As the number of AI initiatives increases, decision-makers will require consolidated visibility over:
Strategic priorities
Implementation status
Dependencies
Risks
Resources
Regulatory readiness
Performance
Outcomes
Individual initiatives may progress successfully while the wider national portfolio becomes fragmented or develops unmanaged dependencies. A national execution mechanism would provide visibility not only over individual projects, but over how projects interact with the broader national AI system.
3.2 Strategic Dependency Management
AI initiatives increasingly depend on interconnected capabilities including:
Data
Cloud
Compute
Cybersecurity
Procurement
Skills
Regulation
Funding
Technology Providers
Critical Public Systems
These dependencies can extend across ministries, sectors and individual projects. A structured mechanism for identifying and monitoring critical dependencies would enable bottlenecks and systemic risks to be identified before they become delivery failures.
3.3 From Project Completion to Value Realisation
The completion of an AI project does not necessarily represent strategic success.
The more important question is whether the initiative generates measurable improvements in:
Productivity
Public Services
Economic Performance
Resilience
Citizen Outcomes
Institutional Capacity
The Strategy should therefore progressively move from measuring activity and project completion towards measuring realised value.
3.4 Lifecycle Assurance
AI assurance should not operate solely as a final compliance checkpoint.
The regulatory environment increasingly requires consideration of risk management, data governance, documentation, traceability, human oversight, accuracy, robustness and cybersecurity throughout the lifecycle of relevant AI systems.
Cyprus can turn this requirement into an institutional strength by embedding assurance into the lifecycle of AI initiatives rather than treating compliance as an administrative endpoint.
3.5 Continuous Strategic Adaptation
AI technology, geopolitical conditions, European regulation, infrastructure requirements and business models evolve significantly faster than traditional strategic planning cycles.
The Strategy should therefore incorporate an evidence-based mechanism for continuous review and adaptation while preserving its long-term 2032 direction.
4. PROPOSED SOLUTIONS AND POLICY RECOMMENDATIONS
4.1 Establish a National AI Execution, Assurance & Performance Architecture
The Strategy could be strengthened through a complementary National AI Execution, Assurance & Performance Architecture.
This should not create another governance body or duplicate existing institutional responsibilities.
Instead, it should provide an execution layer connecting:
Strategy → Decisions → Portfolio → Dependencies → Regulation → Execution → Assurance → Outcomes
Every significant national AI initiative should be traceable across its lifecycle, from strategic prioritisation through implementation, monitoring, scaling and impact assessment.
The purpose would be to create a common national language for execution.
4.2 Establish National AI Portfolio Management
A consolidated National AI Portfolio could provide decision-makers with a common view of significant public-sector and strategically relevant AI initiatives.
Each major initiative could have a standardised execution profile covering:
Strategic objective
Expected value
Institutional ownership
Accountability
Required data and infrastructure
Regulatory dependencies
Technology dependencies
Risk profile
Budget and resources
Milestones
KPIs
Deployment readiness
Scaling requirements
Measured impact
This would shift the performance question from: “How many AI projects have been launched?” to: “How many strategic AI initiatives are producing measurable national value?”
International evidence supports the importance of structured monitoring and KPIs in national AI strategies.
4.3 Create a National AI Execution and Dependency Map
A National AI Execution and Dependency Map could provide an integrated view of the critical dependencies affecting strategic AI initiatives.
The map could connect:
Data → Infrastructure → Compute → Cloud → Cybersecurity → Regulation → Procurement → Funding → Talent → Technology Providers → Public Systems
This would enable early identification of:
Cross-project dependencies
Bottlenecks
Resource constraints
Single points of failure
Vendor concentration
Regulatory dependencies
Infrastructure gaps
Skills gaps
The objective would be to move from individual project management towards national system management.
4.4 Introduce AI Lifecycle Assurance Gates
Significant AI initiatives could follow proportionate evidence-based stages:
Identify → Assess → Design → Test → Validate → Approve → Deploy → Monitor → Scale → Review
Each stage should incorporate appropriate requirements for:
Regulatory compliance
Data governance
Cybersecurity
Risk assessment
Technical readiness
Human oversight
Documentation
Traceability
Operational resilience
Procurement readiness
Value realisation
The purpose would not be to create additional bureaucracy.
The purpose would be to create evidence-based decision gates determining whether an initiative should proceed, be redesigned, paused, scaled or discontinued.
4.5 Establish a National AI Value Realisation Framework
A National AI Value Realisation Framework should connect:
Investment → Adoption → Operational Performance → Public Value → Economic Impact
For significant initiatives, expected value should be defined before implementation and assessed after deployment.
Potential measures could include:
Productivity improvement
Cost reduction
Service quality
Citizen experience
Economic output
Time savings
Institutional efficiency
Risk reduction
Resilience
Innovation and spillover effects
This would ensure that national AI investment is evaluated according to outcomes rather than activity alone.
4.6 Establish a National AI Readiness & Execution Index
A National AI Readiness & Execution Index could provide a consistent mechanism for measuring national and institutional readiness and execution progress.
Potential dimensions could include:
Infrastructure Readiness
Data Readiness
Regulatory Readiness
Institutional Capacity
Talent
Adoption
Security
Execution Performance
Economic Impact
The Index should function as a decision-support mechanism rather than simply a reporting instrument.
It could allow decision-makers to identify where resources, technical assistance, policy intervention or strategic adjustment are required.
This would complement international approaches to measuring national AI capability and implementation.
4.7 Create a Defined Pathway from Pilot to Scale
A major strategic challenge is ensuring that experimentation leads to sustainable deployment.
Strategic AI initiatives should follow a defined pathway:
Research → Experimentation → Validation → Assurance → Procurement → Deployment → Scaling → Impact Measurement
Clear stage gates would reduce the risk of fragmented pilots that do not progress into production.
Scaling decisions should be based on evidence of:
Technical readiness
Regulatory adequacy
Operational viability
Security and resilience
Institutional readiness
Economic or public value
This is particularly relevant to SMEs, where AI adoption continues to lag behind larger enterprises.
4.8 Establish a National AI Strategic Risk and Dependency Register
Cyprus should consider establishing a National AI Strategic Risk and Dependency Register for critical national AI capabilities.
It could monitor:
Technology dependencies
Vendor concentration
Cloud and compute dependencies
Critical data dependencies
Skills dependencies
Regulatory dependencies
Cybersecurity exposure
Supply-chain risks
Geopolitical risks
Emerging systemic AI risks
This would provide an early-warning mechanism for strategic vulnerabilities and allow intervention before risks become structural.
4.9 Introduce Strategic AI Foresight and Continuous Adaptation
The Strategy should operate as a living national framework.
A continuous feedback loop could be established:
Evidence → Performance → Risk → Foresight → Decision → Strategy Adjustment
An annual National AI Strategic Review could assess:
Technological developments
Geopolitical developments
Regulatory changes
National dependencies
Investment priorities
AI adoption
Strategic project performance
Emerging risks
Economic and societal outcomes
New opportunities
This would allow the Strategy to evolve without losing its long-term direction.
5. LEGISLATIVE IMPLICATIONS AND REGULATORY REQUIREMENTS
The proposed architecture does not necessarily require extensive new legislation.
The immediate priority should be to ensure that existing European and national requirements are translated into practical, interoperable and operational mechanisms.
5.1 AI Act Implementation
The EU AI Act introduces requirements relating to risk management, data governance, documentation, traceability, transparency, human oversight, accuracy, robustness and cybersecurity for relevant AI systems.
Cyprus should seek to translate these requirements into practical national lifecycle governance.
Compliance should become an embedded operating process rather than a final administrative checkpoint.
5.2 Regulatory Interoperability
AI governance should connect with:
Data Protection
Cybersecurity
Digital Identity
Public Procurement
Critical Infrastructure
Administrative Law
Sectoral Regulation
This would reduce regulatory fragmentation and make compliance more predictable for institutions and businesses.
5.3 Evidence, Traceability and Accountability
Significant AI systems should maintain appropriate evidence throughout their lifecycle so decision-makers can establish:
What was assessed
What risks were identified
What controls were applied
Who approved deployment
What was deployed
What changed
How the system performed
This would strengthen accountability and support responsible AI deployment.
5.4 Proportionate Regulation and SME Accessibility
Regulation should remain proportionate to the risk, scale and societal impact of AI applications.
This is particularly important for SMEs and innovative companies.
Cyprus should seek a regulatory environment that is:
Predictable
Interoperable
Risk-Based
Evidence-Based
Innovation-Enabling
5.5 Regulatory Foresight
The national framework should incorporate mechanisms to anticipate emerging technologies, risks and European regulatory developments.
The objective should be to move from reactive compliance towards:
Regulatory Foresight → Preparedness → Assurance → Responsible Innovation
6. POTENTIAL CYPRIOT IMPLEMENTATION CAPABILITY AND STRATEGIC CONTRIBUTION
Successful implementation of the National AI Strategy 2032 will require not only public-sector leadership and institutional coordination, but also access to specialised expertise capable of translating policy, regulation and strategic priorities into structured execution.
Cyprus has an opportunity to develop and retain such capabilities domestically.
In this context, Areté Strategy AI Ltd, a Cyprus-based policy, governance and regulatory execution intelligence company, has developed specialist expertise at the intersection of:
AI Policy
Regulatory Intelligence
Governance
Strategic Execution
Institutional Transformation
Assurance
Areté’s work is particularly relevant to the proposed execution layer because it focuses on translating complex strategic and regulatory requirements into structured implementation frameworks, governance mechanisms, execution controls, evidence and measurable outcomes.
Arete has developed the concept of Regulatory Execution Intelligence (REI™), approaching regulation and policy not only as requirements to be interpreted, but as systems that can be translated into:
Decisions → Responsibilities → Controls → Evidence → Execution → Outcomes
Within the national AI context, this capability could potentially contribute to areas such as:
National AI Portfolio Structuring
Mapping strategic AI initiatives, objectives, dependencies, responsibilities, risks, milestones and expected outcomes.
AI Regulatory and Governance Mapping
Translating applicable European and national requirements into operational governance requirements, lifecycle controls and institutional responsibilities.
AI Execution Assurance
Supporting stage-gated approaches through which AI initiatives can be assessed for readiness, risk, governance, implementation and scaling.
Strategic Dependency Intelligence
Mapping relationships between data, infrastructure, cloud, cybersecurity, procurement, regulation, skills, technology providers and institutional capabilities.
AI Readiness and Execution Measurement
Supporting structured assessments of institutional readiness, execution progress and value realisation.
Executive Decision Intelligence
Providing decision-makers with structured intelligence concerning implementation status, emerging risks, dependencies, strategic bottlenecks and opportunities for intervention.
Arete could therefore contribute, where appropriate and subject to applicable institutional, legal, procurement and competition requirements, as a specialist Cypriot implementation and strategic execution capability supporting selected components of the National AI Strategy 2032.
This contribution does not seek to replace the responsibilities of Government, competent authorities, public institutions or national AI governance structures.
Rather, it highlights the potential value of developing domestic Cypriot capabilities that can complement public-sector capacity where specialised execution, governance and regulatory intelligence are required.
Any future engagement, pilot, technical assistance, research collaboration or procurement of services should be considered independently through the appropriate institutional and legal mechanisms.
The broader objective should be to:
Build National Capability → Test in Cyprus → Measure Results → Institutionalise What Works → Develop Exportable Expertise
This would enable Cyprus not only to adopt AI, but potentially to develop internationally relevant expertise in AI governance, regulatory execution and responsible national implementation.
7. NEXT STEPS
The recommendations could be translated into practice through a phased implementation pathway.
Step 1 — Establish a National AI Execution Baseline
Conduct a structured baseline assessment of existing AI initiatives, governance mechanisms, infrastructure, data capabilities, regulatory requirements, dependencies, resources and performance indicators.
Step 2 — Establish National AI Portfolio and Dependency Mapping
Create a consolidated view of strategic AI initiatives and their critical interdependencies across Government and relevant sectors.
Step 3 — Define the Assurance and Stage-Gate Framework
Develop common and proportionate evidence requirements for assessing significant AI initiatives from design through deployment and scaling.
Step 4 — Establish Value and Performance Metrics
Define common KPIs and outcome measures connecting AI investment with measurable public, economic and strategic value.
Step 5 — Pilot the Execution Architecture
Apply the proposed architecture to a limited number of strategically important AI initiatives.
The pilot should test:
Portfolio Visibility → Dependency Mapping → Regulatory Readiness → Assurance Gates → Execution Monitoring → Value Measurement
Step 6 — Establish Continuous Strategic Review
Create an annual evidence-based review mechanism through which implementation performance, risks, technological developments and emerging opportunities inform adjustments to the Strategy.
Step 7 — Develop a National AI Execution Dashboard
Subject to appropriate governance, security and data-access requirements, establish an executive-level dashboard providing decision-makers with consolidated visibility over:
Strategic initiatives
Execution status
Dependencies
Risks
Assurance status
KPIs
Investment
Value realisation
The dashboard should function as a decision-support mechanism, not merely a reporting tool.
Step 8 — Establish a Cyprus AI Execution Capability Pilot
Following adoption of the Strategy and subject to appropriate governance and procurement procedures, Cyprus could consider a controlled pilot bringing together relevant public-sector expertise, academia, technology providers and qualified Cypriot specialist firms.
The purpose would be to test the proposed execution architecture under real institutional conditions before determining which capabilities should subsequently be institutionalised.
This would allow Cyprus to:
Test Before Scaling → Measure Before Institutionalising → Build National Capability → Avoid Permanent External Dependency
8. CONCLUSION
Cyprus does not need to compete with larger states solely through the scale of infrastructure, compute or financial investment.
It can create strategic advantage through the quality, agility, coherence and execution capacity of its national AI architecture.
The National AI Strategy 2032 already provides the strategic direction.
The opportunity now is to strengthen the mechanisms through which that direction becomes measurable national capability.
The success of the Strategy should therefore not be measured solely by the number of AI initiatives launched, pilots completed or investments made.
It should ultimately be measured by whether Cyprus has developed the institutional capacity to:
Prioritise → Decide → Execute → Assure → Scale → Measure → Adapt
its AI investments and capabilities.
The proposed National AI Execution, Assurance & Performance Architecture would provide a complementary execution layer connecting:
AI Policy → Regulation → Data → Infrastructure → Investment → Governance → Execution → Impact
Its purpose is not to create another programme or governance body.
Its purpose is to strengthen the ability of the Republic of Cyprus to operate AI as a coherent, measurable and continuously adaptive national system.
The strategic advantage for Cyprus may therefore lie not in attempting to replicate the scale of larger AI economies, but in becoming exceptionally capable at connecting policy, regulation, governance, infrastructure, innovation and execution within one trusted national framework.
By 2032, the strongest measure of success would be a Cyprus that is not only an adopter of AI, but a country capable of designing, governing, deploying, assuring, scaling and measuring AI responsibly and consistently.
The National AI Strategy 2032 can provide the direction.
The proposed execution architecture can help ensure that Cyprus has the institutional intelligence and operational discipline required to deliver it.
SUBMITTED BY Christina Ioannou Founder & CEO of Arete Strategy AI Ltd
Expert of Global Policy, Governance & Regulatory Execution IntelligenceTM
Specialist contribution: National AI Execution, Regulatory Intelligence, Governance, Assurance, Strategic Execution
Submission to the Public Consultation on the National AI Strategy of Cyprus 2032: Recognising Property, Land and the Built Environment as a Strategic AI Domain
Executive recommendation
Cyprus should recognise Property, Land and the Built Environment as a cross-cutting national AI application domain and establish a Cyprus Property Intelligence Data Space and Testbed.
This would connect the Strategy’s priorities in government, financial services, tourism, infrastructure, climate and public policy through one of Cyprus’s most economically important and data-intensive systems.
The proposal directly supports four national objectives:
* Increasing national productivity
* Transforming public services
* Ensuring secure, sovereign and interoperable data
* Developing national capability through public-private partnerships
It also addresses the Strategy’s identified challenges relating to fragmented institutional data, limited interoperability and immature data governance.
Comment 1: Recognise property as a cross-cutting national AI domain
Relevant Strategy sections:
Sections 1.3 and 1.4.2 concerning priority sectors and data as a national asset.
Recommendation
Add Property, Land and the Built Environment as a cross-cutting domain supporting the Strategy’s existing priority sectors, rather than as an additional standalone sector.
The Strategy states that priority sectors were selected partly because of their high contribution to national GDP. On that basis, the omission of property and the built environment is material.
Economic importance
Construction generated approximately €1.73 billion and real-estate activities approximately €3.12 billion in 2024.
Combined, these activities generated approximately €4.85 billion, representing 15.7% of Cyprus’s gross value added.
Financial stability
At 31 December 2023, lending to households and non-financial companies secured by immovable property represented 63.7% of the banking sector’s loan portfolio.
The value of this exposure was equivalent to approximately 317% of the banking sector’s Common Equity Tier 1 capital.
The Central Bank of Cyprus has highlighted that adverse developments in residential and commercial property markets could negatively affect the banking sector.
Property data, valuations and risk analytics are therefore directly relevant to:
* Credit risk
* Collateral management
* Capital adequacy
* Financial supervision
* Non-performing exposure management
* Climate and insurance risk
Population and housing
The population in the government-controlled areas reached approximately 983,000 at the end of 2024, increasing by 1.7% during the year.
Net migration was 13,588, while long-term immigration reached 40,471.
These demographic changes increase the need for reliable intelligence on:
* Housing supply
* Rental affordability
* New development activity
* Local infrastructure requirements
* School and healthcare capacity
* Population concentration
* Urban expansion
* Demand by municipality and neighbourhood
Tourism and residential accommodation
Cyprus received approximately 4.04 million tourists and generated approximately €3.21 billion in tourism receipts in 2024.
At the same time, short-term accommodation is increasingly interconnected with the residential housing market.
Short-stay guest nights booked through major online platforms increased by 22.3% year-on-year in Cyprus during the first quarter of 2026.
This creates a clear policy need to understand the interaction between:
* Tourism demand
* Short-term accommodation
* Long-term rental supply
* Housing affordability
* Seasonal infrastructure demand
* Municipal services
* Development planning
Rationale
Property data is not relevant only to the real-estate industry.
It is foundational to:
* Banking and collateral risk
* Housing affordability
* Tourism and destination management
* Taxation and municipal revenues
* Urban planning and infrastructure
* Energy efficiency
* Insurance
* Climate resilience
* Social policy
* Public-sector investment
Recognition of the built environment as a cross-cutting domain would align the Strategy with its economic selection criteria and with its stated focus on policy design and evidence-based decision-making.
Comment 2: Build a governed national property data layer
Relevant Strategy sections:
Sections 3.2.4 and 3.2.5 concerning data-by-design, capability and infrastructure.
Recommendation
Create a Cyprus Property Intelligence Data Space within the proposed National Intelligent Digital API Fabric.
The State should establish:
* Common property identifiers
* Interoperability standards
* Data governance rules
* Secure access mechanisms
* Authoritative source registers
* Audit and accountability requirements
The State should not attempt to build a single monolithic commercial application.
Instead, it should provide the trusted data infrastructure and governance framework upon which public institutions and qualified private providers can develop applications.
Subject to legal permissions, the initial data model should connect:
* Cadastral parcels
* Ownership rights
* Property transactions
* Addresses
* Buildings and individual units
* Planning zones
* Development rights
* Planning applications
* Building permits
* Building characteristics and use
* Energy performance information
* Utility connections
* Aggregated utility consumption
* Climate and environmental exposure
* Natural-hazard data
* Registered leases
* Short-term accommodation registrations
* Property taxation
* Municipal charges
* Public infrastructure
Access should be tiered:
* Public datasets should be reusable
* Regulated and commercially sensitive data should be purpose-limited
* Access should be role-based
* All access should be logged and auditable
* Personal data should be anonymised or accessed through privacy-preserving environments
* Data owners should remain accountable for accuracy, quality and update frequency
International precedents
Cyprus can adapt proven European models rather than create an entirely new architecture.
Greece
Greece is implementing a Unified Property Registry designed to integrate information held by the Hellenic Cadastre, the tax authority, the electricity network operator, planning authorities and other public systems.
The initiative has a reported budget of approximately €8.29 million.
It is intended to cover:
* Buildings
* Land
* Infrastructure
* Ownership
* Leases
* Tax obligations
* Property characteristics
Changes recorded in one authoritative database are intended to update the wider public administration, reducing duplication and inconsistencies.
This supports:
* Better tax compliance
* Reduced undeclared property use
* Faster transactions
* More efficient public administration
* Improved planning
* Better-quality national property data
Source:
Greek Ministry of Economy and Finance, Unified Property Registry
https://minfin.gov.gr/sto-tameio-anakampsis-to-eniaio-mitroo-akiniton/
Denmark
Denmark operates a Data Distribution Platform that provides standardised access to core public registers, including:
* Addresses
* Buildings
* Dwellings
* Businesses
* Geospatial information
* Administrative boundaries
The platform is treated as critical national infrastructure and is used by public authorities, private companies and financial institutions.
Denmark’s model demonstrates how authoritative public data, common identifiers and standardised access can:
* Reduce duplication
* Improve data quality
* Lower administrative costs
* Support private innovation
* Enable better planning
* Improve public-service delivery
Source:
Danish Agency for Climate Data, Data Distribution Platform
https://www.eng.klimadatastyrelsen.dk/data/the-data-distribution-platform
Netherlands
The Netherlands links cadastral information, buildings, addresses and municipal property valuations through a coordinated national system.
Municipalities assess properties annually through the WOZ system.
The resulting values are used for:
* Municipal property taxes
* National income tax
* Corporate tax
* Inheritance tax
* Water-board charges
* Official statistics
* Notarial functions
* Social-housing rent controls
Residential property values and core property characteristics are also publicly accessible.
This demonstrates how a common property data infrastructure can support multiple government functions without requiring each institution to create a separate system.
Source:
Netherlands Council for Real Estate Assessment
https://www.waarderingskamer.nl/en/for-residents/explanation-woz-value
Common lessons from these jurisdictions
The international examples share four principles:
* Authoritative source registers
* Common identifiers
* Interoperability
* Controlled public and private reuse
Comment 3: Add a Property Intelligence Testbed
Relevant Strategy sections:
Section 3.8.5 and the initiatives relating to government, financial services, tourism and hospitality.
Recommendation
Include a Property Intelligence Testbed among the Strategy’s national AI testbeds.
The testbed should initially cover three measurable pilot programmes.
Pilot 1: Collateral and valuation risk
Develop and test:
* Explainable automated valuation models
* Valuation confidence ranges
* Comparable evidence
* Independent model validation
* Portfolio monitoring
* Early-warning indicators
* Climate-risk overlays
* Model drift monitoring
* Human review workflows
Primary users would include:
* Banks
* Credit-acquiring companies
* Servicers
* Insurers
* Regulators
* Government valuation authorities
Pilot 2: Housing and tourism intelligence
Develop a national monitoring framework covering:
* Housing supply
* Housing affordability
* Rental levels
* Vacant stock
* New construction
* Migration-driven demand
* Long-term rental availability
* Short-term accommodation
* Tourism capacity
* Demand by municipality
* Infrastructure pressure
This would enable the Government to assess how tourism, migration, development activity and short-term rentals affect local housing markets.
Pilot 3: Planning, compliance and public revenue
Connect, where legally permissible:
* Planning permissions
* Building permits
* Registered property use
* Ownership records
* Lease registrations
* Tax records
* Utility indicators
* Short-term rental registrations
The objective would be to:
* Identify inconsistencies between approved and actual property use
* Improve permitting and inspections
* Detect undeclared rental activity
* Reduce tax leakage
* Improve municipal revenue collection
* Monitor unauthorised development
* Support infrastructure planning
Rationale
These pilots directly operationalise the Strategy’s priorities in:
* Fraud detection
* Compliance
* Risk modelling
* Smart tourism
* Destination management
* Resource allocation
* Public-sector productivity
* Evidence-based policymaking
They would create reusable national capabilities rather than isolated demonstrations, reducing the Strategy’s identified risk of AI theatre.
Comment 4: Define ownership, timing and measurable outcomes
Relevant Strategy sections:
Sections 1.5 and 3.3 concerning governance, implementation and measurement.
Recommendation
Assign strategic delivery responsibility to the proposed National AI Authority.
The Department of Lands and Surveys, relevant ministries, planning authorities and municipalities should act as operational owners.
A multidisciplinary working group should include:
* Department of Lands and Surveys
* Planning and building-control authorities
* Tax Department
* Municipalities
* Deputy Ministry of Tourism
* Central Bank of Cyprus
* Financial institutions
* Insurers
* Universities
* Research organisations
* Qualified property-data and technology providers
Implementation timetable
Months 0 to 8:
* Appoint institutional owners
* Map available datasets
* Identify legal bases for data sharing
* Assess data quality
* Agree a common property identifier
* Define governance standards
* Select pilot projects
* Agree baseline measurements
Months 6 to 12:
* Deploy secure APIs
* Create controlled testing environments
* Launch the initial pilots
* Implement independent model validation
* Establish audit and monitoring processes
Months 12 to 24:
* Evaluate pilot results
* Scale successful applications
* Integrate operational systems
* Publish performance outcomes
* Extend data coverage
* Introduce additional public and private use cases
Key performance indicators
The programme should measure:
* Percentage of properties linked across registers
* Dataset coverage
* Dataset accuracy
* Update frequency
* API availability
* API response performance
* Reduction in valuation time
* Reduction in permitting time
* Reduction in policy-analysis time
* Model accuracy
* Model confidence
* Model drift
* Number of inconsistencies identified
* Number of undeclared uses identified
* Public-sector cost savings
* Additional public revenues
* Number of pilots transferred into production
* Number of government departments using the infrastructure
* Number of approved private-sector applications
Proposed contribution from Ask Wire
Ask Wire would be willing to contribute practical experience in:
* Property-data integration
* Automated valuation
* Portfolio and collateral risk
* Market intelligence
* Housing analytics
* Climate-risk analytics
* Model governance
* Data quality controls
* Institutional implementation
Any participation should take place through transparent, competitive and outcome-based mechanisms.
The State should retain ownership of sovereign data, standards and governance.
Qualified providers should compete on applications, analytics, innovation and service quality.
Conclusion
Cyprus cannot implement credible AI in banking, taxation, housing, tourism, climate resilience or urban planning without a governed and interoperable property-data foundation.
Property, Land and the Built Environment should therefore be recognised as a cross-cutting national AI domain.
The proposed Cyprus Property Intelligence Data Space and Testbed would:
* Strengthen financial stability
* Improve housing policy
* Support sustainable tourism
* Reduce tax leakage
* Improve planning and permitting
* Strengthen climate resilience
* Increase public-sector productivity
* Enable private-sector innovation
This would translate the National AI Strategy from a high-level framework into a practical national capability with measurable economic and social outcomes.