Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας
Υφυπουργείο Έρευνας, Καινοτομιας Και Ψηφιακής Πολιτικής
Ανακοινώνεται η έναρξη Δημόσιας Διαβούλευσης της Εθνικής Στρατηγικής για την Τεχνητή Νοημοσύνη (ΤΝ), που εκπονήθηκε από την Εθνική Εξειδικευμένη Επιτροπή για την Τεχνητή Νοημοσύνη (National AI Taskforce), η οποία συστάθηκε με Απόφαση του Υπουργικού Συμβουλίου (αρ. απόφασης 97.538, ημερ. 22/1/2025), υπό την προεδρία του Επικεφαλής Επιστήμονα για Έρευνα, Καινοτομία και Τεχνολογία, και με έντεκα (11) μέλη προερχόμενα από τον δημόσιο και ιδιωτικό τομέα, την ακαδημαϊκή και ερευνητική κοινότητα.
Η Στρατηγική αποτελεί το ολοκληρωμένο εθνικό πλαίσιο πολιτικής της Κυπριακής Δημοκρατίας για την αξιοποίηση των δυνατοτήτων της ΤΝ, με όραμα, έως το 2032, η Κύπρος να αναγνωρίζεται ως ο αξιόπιστος κόμβος ΤΝ στην Ανατολική Μεσόγειο, ως μια αξιόπιστη ευρωπαϊκή δικαιοδοσία για την παροχή υπηρεσιών που αξιοποιούν την ΤΝ και ως γέφυρα μεταξύ της Ευρωπαϊκής Ένωσης και των γειτονικών περιοχών.
H Στρατηγική αναπτύσσεται γύρω από 8 αλληλένδετους Εθνικούς Στρατηγικούς Στόχους:
- Καθιέρωση της Κύπρου ως αξιόπιστης δικαιοδοσίας για την ΤΝ.
- Αύξηση της εθνικής παραγωγικότητας μέσω της υπεύθυνης υιοθέτησης της ΤΝ.
- Ανάπτυξη ενός ισχυρού και χωρίς αποκλεισμούς οικοσυστήματος ΤΝ.
- Μετασχηματισμό των δημόσιων υπηρεσιών μέσω της αξιοποίησης της ΤΝ.
- Ανάπτυξη, προσέλκυση και διατήρηση δεξιοτήτων και ανθρώπινου δυναμικού στον τομέα της ΤΝ.
- Διασφάλιση ασφαλών, κυρίαρχων και διαλειτουργικών δεδομένων και υποδομών.
- Εδραίωση ισχυρής διακυβέρνησης, δεοντολογίας και λογοδοσίας σε κάθε χρήση της ΤΝ.
- Ανάπτυξη κυρίαρχων εθνικών δυνατοτήτων μέσω στρατηγικών συνεργασιών.
Το προσχέδιο της Εθνικής Στρατηγικής για την ΤΝ βρίσκεται αναρτημένο πιο κάτω και καλούνται όλοι οι ενδιαφερόμενοι να υποβάλουν τα σχόλια, εισηγήσεις και παρατηρήσεις τους μέσω της πλατφόρμας «η-Διαβούλευση» μέχρι την 31η Αυγούστου 2026.
Όλες οι απόψεις και προτάσεις που θα υποβληθούν θα αξιολογηθούν και, όπου κριθεί σκόπιμο, θα ενσωματωθούν στην τελική έκδοση της Στρατηγικής.
Παράκληση όπως τα σχόλια γίνονται σύμφωνα με την πιο κάτω δομή:
Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο
Σχόλιο / Εισήγηση
Αιτιολόγηση σχολίου / Εισήγησης
Για οποιεσδήποτε διευκρινίσεις σχετικά με τη διαδικασία της διαβούλευσης, μπορείτε να επικοινωνείτε με το Υφυπουργείο Έρευνας, Καινοτομίας και Ψηφιακής Πολιτικής.
- Υπό επεξεργασία
- Αναρτήθηκε
20 Ιούλ 2026 @ 0:00 - Ανοικτή σε σχόλια ως
31 Αυγ 2026 @ 23:50 - 128 σχόλια
Περιεχόμενα
| 01 - ΕΘΝΙΚΗ ΣΤΡΑΤΗΓΙΚΗ ΓΙΑ ΤΗΝ ΤΕΧΝΗΤΗ ΝΟΗΜΟΣΥΝΗ ΤΗΣ ΚΥΠΡΙΑΚΗΣ ΔΗΜΟΚΡΑΤΙΑΣ | 9 σχόλια |
Submitted by Stavros Koutsangelas, Co-Founder and COO, Karisma. I am an EU founder relocating to Cyprus in 2027. I run a curated community of six and seven figure founders, I build operational AI systems for facility services companies, and I run an events business in tourism and hospitality. Comments on Entrepreneurship and Innovation, Government, and Talent.
1. Annex C, Entrepreneurship and Innovation, and Section 5.2. The Strategy wants repeat founders and offers them only money.
The Strategy sets out to attract “experienced engineers, researchers, and repeat founders with real presence and knowledge transfer”, and to produce three unicorns. Both ambitions are right. The mechanism proposed for both is growth capital.
That will not do it on its own. Experienced founders do not choose a country for its funding instruments. Access to capital is close to borderless now, and a matching fund that requires an institutional lead is not a reason to move anywhere. Founders relocate for other founders: for the density of people at the same altitude, for the deals and hires that come out of those relationships, and for a reason to stay once the novelty of the tax position wears off.
The Strategy has no answer to that. Across 101 pages, “founder network” and “community of founders” do not appear. “Mentor”, “peer” and “convening” appear once each. Testbeds, sandboxes and funds are all supply side. None of them creates the thing that actually holds senior people in a small country.
Recommendation: name founder density as an explicit objective under the Entrepreneurship pillar, and treat convening as infrastructure rather than as an event budget. Concretely, that means a standing programme that brings experienced operators into the country and keeps them connected to local founders, measured on retention and on companies started or relocated, not on attendance.
2. Sections 2.2.1, 3.4.1 and 5.4. The adoption target depends on work the Strategy never describes.
The Strategy puts enterprise AI adoption at 9.27% against an EU average of 19.95%, and targets 75%. Getting there means ordinary mid-sized companies changing how they work day to day.
Procurement appears throughout the document, but almost always as a governance question: how the public sector should approve and buy AI. Section 3.4.1 gives one sentence to “the transition towards AI-first procurement models by 2032” and leaves it there, with no definition, no use case and nobody accountable. Public procurement is one of the largest document heavy processes government runs. Tendering, specification, calculation, bid evaluation, contract administration, compliance reporting: most of it still runs on email and spreadsheets. Facility services procurement across ministries, schools and hospitals is a concrete example, and it is absent. The words “tender” and “facility management” do not appear anywhere in the document.
Separately, the AI Sovereign Investment Matching Fund puts 75% of its capital into Series A and B rounds and invests only after an institutional investor commits. The companies producing the 9.27% figure are not raising Series A. For a 40 person facility services operator the problem is not funding. It is that there is nobody they can hire or buy from who will rebuild how their operation works.
Recommendation: name operational procurement as a use case family under 3.4.1, with a defined pilot, an owner and measurable outcomes. Add an implementation instrument for existing SMEs alongside the Matching Fund, redeemable against certified providers and measured separately from startup funding. Government both buys facility services and runs them, so one pilot can be tested from both sides.
3. Section 3.6.5. The talent chapter leaves out what Cyprus already has.
Section 3.6.5 says only that “specific incentives will be developed” to attract AI experts and startups. No instrument, no timeline, no measure.
Cyprus already has them. Non-dom status, the 50% income tax exemption on employment above EUR 55,000, and the IP Box regime covering copyrighted software. These exist today and for anyone weighing a move they are decisive. I am making that calculation this year, and none of the three appears in the talent section.
Recommendation: reference them directly in 3.6.5, so the offer is clear now rather than waiting on incentives still to be designed.
Offer of contribution.
I move to Cyprus in 2027 and I am building in two of the priority sectors. Happy to contribute free of charge on any of the above: on what actually makes experienced founders relocate and stay, on tender and calculation workflows in facility services, and on what mid-sized operators need before they can adopt anything at all.
Hi everyone and happy last day of summer. It was a pleasure to read the strategy and 120 pages of comments so far. Looks like this topic is truly important to organizations and residents of Cyprus. I’ll try to gather some practical review without relying solely on AI tools.
In general, I support this strategy. Cyprus shouldn’t compete on GPU capacity (especially with such electricity prices) or try to create another global ChatGPT (every country except US and China failed). Its advantages are a compact market, a strong service sector, EU membership, and the ability to quickly test. The “trusted AI hub for regulated industries” is a reasonable bet, and the education component is one of the strongest I’ve seen in a national strategy.
What the document still lacks is a plan for achieving the goal: funding, responsible parties, and a sequence of actions. I write this as a practitioner. I run more than a dozen of AI implementation projects in Cyprus, have implemented projects based on publicly available Cypriot data, and worked on speech recognition in Cypriot Greek. I also discussed the project with several colleagues from the local AI industry, so these points are based on practical experience. So, what will be great to add:
1. A three-year implementation plan with costing. A short working document of 15-20 actions for 2027-2029. Each action should be carried out by a single responsible person and include launch and operating costs, funding source, baseline plan, target date, and scaling or termination conditions. Costs should cover the entire lifecycle: licenses, integration, security, training, and support. A pilot project that lacks future funding will remain a pilot.
2. One set of numbers.The adoption target is presented in three versions (50% by 2032, 75% by 2032, 75% by 2030). Ministry AI strategies are updated both “annually” and “every three years.” “3,000 AI specialists” are three different concepts in three different places. A unified KPI dictionary with baseline metrics and data sources solves this problem. Essentially, 75% by 2030, instead of the current 9.27%, is unrealistic; 50% by 2032, considering only systems in actual productive use, would be a plausible and still ambitious target. But it was mentioned a lot of times.
3. Easier control. A dozen new councils, committees, and centers is a lot for a country of this size. One small central team with a budget and authority to unblock ministries, one person responsible for each initiative, one AI coordinator per ministry. Expert committees as temporary working groups. The team driving implementation should not conduct self-audits; oversight should be left to existing regulatory bodies. Publish a quarterly report (what has already been implemented, how much it cost, what has been stopped) and report to parliament once a year. Fighting bureaucracy with AI can be a good goal too.
4. Three missions for the first wave, not sixteen flagships. It’s OK. I also like setting 10 different highest priority KPIs for the quarter, so need someone to reduce this to at most three (my wife is the best of this). First, a unified platform for public services: identification, payments, document searches, manual data transfer, with municipalities using the same components. Second, artificial intelligence in the maritime sector, where Cyprus holds a real position: the third-largest fleet in the EU and the largest ship management center in Europe in Limassol. Third, robust AI for regulated services (finance, legal, healthcare), where the rapid and transparent application of EU regulations could become an export product. Other sectors remain in the portfolio and will move to the next stage once the data, owner, and budget are ready.
5. Pay for working software, not just for consultations. I’ve attended several dozens of AI conferences. Most of them are just nice presentations, or talks about ChatGPT wrappers… For a small company, the barrier is licensing, setup, and CRM integration, not a lack of research. A voucher of up to €15,000–€20,000 is offered, covering the first year of subscription, setup, and training. This voucher includes an application for micro-enterprises and payment to the vendor upon system launch. It’s possible to measure how many companies continue to pay for the system themselves after a year. And it will be great to measure real usage and transformation of AI, not just amount of presentations generated.
6. Real access to public procurement for Cypriot SMEs. One large tender for the creation of a national platform will go to an international integrator, and the know-how will go with the contract. Divide the initial procurement into lots that can be completed by a company of 2-30 people, add an expedited process for smaller projects, and track the share of AI contract value won by local SMEs. Terms should be equal for everyone, and conflicts of interest should be disclosed; simply avoid formulating terms that deliberately exclude the entire local market. And guys, you need to do something with tenders. It’s not possible to do something meaningful if after 30.000 euro contract you need years of struggles and court fights.
7. Correct the data before purchasing the equipment. Based on my own experience working with publicly available data in Cyprus, the problem isn’t a lack of well-designed models, but fragmented datasets, inconsistent registries, and undocumented interfaces. There are ZERO good-quality datasets for Cypriot speech! The one you find on HuggingFace was created by us. It’s not possible to create speech services for cypriots without data. It’s not possible! Even with all money of the world. Let’s start with just finding what is available and at the data level: named owners for each dataset, machine-readable formats, documented APIs, and quality guidelines. We’ll integrate ministries in stages, based on their actual maturity. Healthcare requires an EHDS-compatible environment, not just a repository.
8. Test knowledge of the Greek language instead of relying on the statement “we support the Greek language.” Before funding a sovereign programming language training program, open datasets for assessing Greek and Cypriot Greek through Pharos-CY must be published: accuracy, imitation, human transfer, as well as terminology for public administration, tourism, law, healthcare, and maritime affairs. From my experience working with Cypriot language, I know that the phrase “the model supports Greek” alone means little. Without common benchmarks, the state will be purchasing machine translation at the price of a language system. This will cost several million dollars and will pay for itself with every conversational service planned for implementation under the strategy.
9. Open standards, not Cypriot ones. The strategy mentions interoperability and product-specific alignment, but doesn’t name any standards. The rule should be: use open international standards and never create local variants where they already exist. Specific protocols should be described in a brief technical description, which the development team will review annually; the field is evolving too rapidly to commit protocol names to a 2032 document. The two planned AI registries should be merged, or at least a single schema with a public API should be created for them, so that the registry also serves as a catalog of verified systems. But this was mentioned several times already.
10. Ensure proportionality in compliance with the Artificial Intelligence Law. Most systems required by small and medium-sized businesses pose low risk. A short checklist is sufficient for a chat assistant or document search: disclose AI information, maintain a log, ensure human control is transferred, specify the data location, require confirmation of important actions, and specify the owner and complaints channel. Compliance with these requirements guarantees a presumption of compliance with all government agencies. Cyprus is becoming a reliable jurisdiction through rapid implementation of EU regulations, not through the addition of a national certificate. It will be great if government help here, not just flood startups with all new best-in-the-world AI regulation.
11. Specific rights of citizens. Two publicly available documents: a registry of government AI systems (purpose, owner, provider, cost, risk class, oversight, incidents) and brief, clear instructions on what to do if you’ve been notified of the presence of AI, how to obtain an explanation, request a human review, file a complaint, and how to quickly receive a response. In healthcare, social benefits, employment, education, lending, and justice, the final decision rests with humans. Government contracts must guarantee access to event logs, data portability, and a plan for terminating cooperation with the vendor. It will be great to have a sandbox for testing different systems by people before the public release.
12. Talent: Reasons to stay, not just courses completed. This component takes into account trained specialists; the more difficult task is retaining them. Add recruitment and retention rates, expedited visa processes for AI specialists and founders (the long-discussed visa reform for startups is relevant here), paid internships, and professional development obligations for recipients of tax incentives and large contracts. Schools should also teach how to detect deepfakes, voice cloning, and phishing, and not just through AI. It should be very easy for a talented guy to move, find job and/or create a company here.
13. Measure demand before you start “sovereign” calculations. Cyprus already has access to Pharos-CY and EuroHPC. Before investing significantly, it’s necessary to determine which workloads truly cannot leave the country and how much they cost in terms of electricity and water. Reasonable distribution: processing important data on the island, large-scale training at European AI centers (European AI Factory). For a small country, sovereignty lies in control of critical data, rules, and logs, not in owning every server. Datacenters can be blessing, but not with this temperature, electricity cost and water scarcity, sorry.
A few things I would reconsider. Replace the “three unicorns” with metrics the state can influence: export revenue, jobs, and intellectual property retained in Cyprus. Require AI strategies only from companies using high-risk or regulated systems; for everyone else, it will be just paperwork. Avoid registers and certifications that duplicate the EU database and the AI Law’s compliance assessment. And regarding the “AI judge,” even in small, uncontested cases: let the AI prepare the materials, but the decision must be made and signed by a human.
In short: maintain the foundation (robust AI, industry specialization, common components, data as infrastructure, human participation) and add an implementation mechanism: one responsible person, a three-year budget, three initial missions, a single set of metrics, and a public progress report. Cyprus doesn’t need to promise to become the largest AI hub in the region. It’s enough to be the place where AI is most quickly applied in real-world projects, and the rules are clearly defined. I’d be happy to participate in any working group where the input of practitioners would be beneficial.
Thanks a lot for this opportunity. And good luck!
Our full submission is available here: https://www.ai-3.org/blog/cyprus-national-ai-strategy-submission
The AI Integrity Institute (AI³) is a non-profit organisation working on AI governance. We connect research, industry, the public sector and civil society so that AI is developed and used responsibly and in ways that work in practice. Cyprus is the starting point for our international work.
We regard the draft Strategy as a serious and candid document. The comments below are intended to strengthen it rather than to redirect it.
We set out twenty-six comments. Each names the sections of the Strategy it affects, states what the draft currently says, sets out the change we recommend, and explains the reasoning. Fourteen of the twenty-six require no new institution and no significant new expenditure.
Comment 1
Affected sections: 1.1, 1.4.8, 2.5.7, 3.1.2, 3.4.3, 3.9.3 to 3.9.6, Annex A, Annex F
The Strategy already contains most of the substance of citizen rights. Section 3.9.6 embeds rights to explainability, contestation and human review in health, credit, employment and social benefits, and states that no system whose decisions significantly affect individuals should operate without human oversight.
Our observation concerns form rather than substance. Section 3.9.6 frames these as mandates on organisations. A mandate on an organisation and an entitlement of a person are not the same instrument. A mandate is discharged through compliance documentation and is visible to a regulator. An entitlement must be findable, intelligible and enforceable by the individual. There is no single statement of what a person may demand, no time limit attached to any commitment, and no named point of contact.
We propose a Citizen AI Charter, published as a short document in Greek and English within three months of adoption. It should state the right to be told AI is in use, to a meaningful explanation, to human review by a named body, to challenge a decision and obtain correction, to an alternative service route, and to know where to complain. Each right should carry a maximum response time and a responsible contact point. The Charter should distinguish rights that already exist in law from commitments made by the Strategy, and should describe the explanation right as Article 86 of the AI Act does.
Comment 2
Affected sections: 3.3.2, 3.4, 3.9.3, 3.9.6, Section 5 item 4, Annex B
The Strategy proposes three registration instruments. Section 3.9.6 mandates registration in the European database. Section 5 proposes a national application and certification registry, and separately a registry cataloguing AI solutions on the market. All three are compliance or market instruments. None is a national list of the systems that Cypriot public bodies use on the people they serve.
The European database does not meet this need. It covers high-risk systems only, it is populated by providers rather than by the deploying public bodies, and it is structured for conformity rather than public comprehension. A citizen asking whether AI shaped a decision about their benefits would not find the answer there.
We propose a single public register of AI systems used by ministries, public law bodies and local authorities. Scope it by risk, covering systems that are operational or approved and that materially affect rights, health, safety, eligibility or access to public services, together with pilots involving live personal data or direct public interaction. For each system publish the purpose, responsible body and contact point, supplier, data categories, risk classification and legal basis, human oversight arrangements, lifecycle stage, impact assessment summary, routes to challenge, and any serious incidents or withdrawals. Justified exceptions should apply for national security, cybersecurity and legitimate commercial confidentiality. Registration should be a condition of passing the control gates in Annex B.
Cyprus should adopt an existing international schema rather than design its own. The Netherlands, the United Kingdom, France, Norway and Scotland all operate national registers, and a group of European cities has developed a shared data schema.
Comment 3
Affected sections: 2.5.4, 3.1.1, 3.4.1, 3.4.3, Annex A, Annex C
The Strategy commits to human oversight of high-risk systems and refers to multilingual support and inclusive access tools. It does not commit that a citizen who cannot or does not wish to use an AI-mediated channel retains a route to the service.
We propose a commitment structured by the significance of the service. For essential public services, and for any service where an AI system makes or materially informs a decision affecting a person’s rights, eligibility, entitlements or effective access, the responsible body should guarantee timely access to human assistance, and where appropriate human review or an alternative route. The alternative should carry no additional charge and should not place the person at an unjustified disadvantage in timeliness or completeness. It may be delivered by digital, telephone or in-person channels, and need not require a wholly separate service infrastructure where AI performs only a back-office function.
Accessibility requirements under the European Accessibility Act should apply to AI-enabled interfaces from design stage rather than as remediation. AI-enabled citizen services should be tested with older users, users with disabilities and users with low digital confidence before deployment, with results published in summary.
Cyprus records 44.2 per cent generative AI use among people aged 16 to 74, but that figure conceals a wide spread by age and circumstance. A strategy that improves service for confident digital users while degrading it for everyone else will reduce trust even as it raises efficiency.
Comment 4
Affected sections: 2.5.6, 3.2, 3.5, 3.7, 3.8.6, Annex C
The Strategy refers to multilingual services in eighteen places. It does not name the Greek language anywhere in the document. It does not refer to Cypriot Greek, and it does not refer to Turkish, which is an official language of the Republic.
We propose that the language position be stated explicitly, supported by a national language resources programme with four components. First, assembly and open publication of Greek-language corpora and terminology resources for public administration, health, law and tourism, with clear licensing and in compliance with data protection, copyright and confidentiality rules. Second, creation of Greek-language evaluation datasets and benchmarks, including Cypriot Greek usage, so that procurement can distinguish a system that genuinely performs in Greek from one that is machine translated. Third, participation in European multilingual model initiatives rather than an attempt to build a national foundation model. Fourth, a stated commitment on the official languages of the Republic and on the practical language needs of residents and visitors.
This is where the citizen agenda and the sovereignty agenda meet. If public services run on models that perform poorly in Greek, the citizen experience degrades and the state depends on suppliers whose language performance it cannot verify. Evaluation infrastructure is a public good. Without it, the phrase “supports Greek” is a claim on a sales document that procurement has no means to test.
Comment 5
Affected sections: 2.5.4, 3.3.1, 3.4, 3.4.4, Annex C
The Strategy is written almost entirely for central government. Ministries carry the obligations, AI Officers sit inside ministries, and the Applied AI Strategy requirement is directed at ministries and public bodies. Local authorities appear only marginally.
We propose that local authorities be included explicitly in Section 3.4 and in the governance structure, through a proportionate route. A municipality cannot reasonably produce an Applied AI Strategy on the same terms as a ministry. We suggest three elements. First, a shared services model in which local authorities consume national capabilities such as the citizen assistant, document intelligence and translation rather than procuring their own. Second, a simplified adoption template and a single point of support within the National AI Authority. Third, representation of local government in the governance structure.
In most European countries local government is where public sector AI meets the citizen most often, in permits, waste, local planning, social support and local information. It is also where capacity is weakest. A strategy that assumes ministry-level capability throughout will produce a two-speed public sector, in which the services citizens use most often are the least well governed.
Comment 6
Affected sections: 3.3.1, 3.3.1.3, 3.3.1.5, 3.3.1.6, 3.11.3, 4.1.6
The Strategy places considerable weight on public trust, human-centred AI and ethics. The governance architecture provides no institutional role for civil society. Every proposed body is drawn from government, academia, research and industry.
We propose three measures. First, civil society representation on the National Ethics and Values Committee. Section 3.3.1.5 gives that Committee responsibility for ethical principles and public trust, which cannot be discharged credibly by a body composed entirely of state, academic and industry representatives. Second, representation on the National AI Taskforce. Section 3.3.1.5 provides that the Committee’s recommendations are submitted to the Taskforce, so representation at Committee level has limited effect unless the body receiving those recommendations also includes a civil society voice. Third, a standing Civil Society and Stakeholder Engagement Mechanism, comprising transparent open calls for representatives, periodic structured consultation, and a permanent channel for submissions during implementation.
Participation should attach to three fixed points: comment on the annual implementation report, consultation before deployment of high-impact citizen-facing systems, and an independent opinion before any substantial revision of the Strategy. Transparency and conflict of interest rules should apply, and participation should complement rather than displace accountable decision-making by the responsible public bodies.
This introduces no new objective. It gives effect to objectives the Strategy has already adopted. Multi-stakeholder models at European Union, Council of Europe and UNESCO level have involved civil society alongside academia, industry and public authorities.
Comment 7
Affected sections: 1.4.10, 2.3.3, 3.11.2, 3.12.1, Section 5, Annex A
The Strategy cites the AI Act as Regulation 2024/1689. It gives one compliance date, in the Section 5 table, asking for risk management, auditability and governance maturity ahead of 2 August 2026. That date has passed and the obligations behind it have changed. The Strategy makes no mention of Regulation (EU) 2026/1744, which amended the AI Act on 27 July 2026, six days before that deadline.
We propose three changes. Update the citation to read Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. Replace the 2 August 2026 milestone with the dates that now apply. Add a short compliance calendar to Annex A.
Some obligations are already in force. The Article 5 prohibitions have applied since 2 February 2025, with new provisions added by the amending Regulation from 2 December 2026. General purpose AI model obligations have applied since 2 August 2025, with earlier models to comply by 2 August 2027. Article 50 transparency obligations have applied since 2 August 2026, with systems already on the market having until 2 December 2026 to mark synthetic content in machine readable form.
The remaining dates fall ahead. At least one national AI regulatory sandbox must be operational by 2 August 2027. Stand-alone high-risk systems under Annex III come into scope on 2 December 2027, and high-risk AI inside regulated products on 2 August 2028. High-risk systems already used by public authorities have until 2 August 2030.
The Strategy proposes a unified government knowledge assistant, a Citizen 2032 portal and multilingual ministry assistants. All are citizen-facing conversational systems already within Article 50.
Comment 8
Affected sections: 3.3.1 and Figure 2, 3.3.1.1, 3.3.1.5, 3.9.6, Annex A
The Strategy contains two institutional maps that do not reference each other. Section 3.3.1 and Figure 2 set out the governance structure. Annex A separately states that the Communications Commissioner and the Commissioner for Personal Data Protection are the competent authorities for the AI Act. Neither Commissioner appears in Figure 2 or in the Section 3.3.1 list.
This leaves several questions open. Section 3.3.1.1 proposes a National AI Authority acting as policy coordination body, execution body and governance and control gatekeeper, without stating how that relates to authorities holding statutory enforcement powers. Figure 2 describes the National Ethics and Values Committee as overseeing compliance with the EU AI Act, which is a function of the designated authorities rather than of an advisory committee. Section 3.9.6 refers to an annual audit by a Cyprus AI Security and Certification Authority, a body that appears nowhere else and is not defined.
We propose that the two maps be merged, with Annex A carrying a single institutional map and Figure 2 redrawn to show the designated authorities and their interface with the Strategy bodies. The Strategy should state clearly what the National AI Authority is and is not. The draft is currently inconsistent, since Section 3.3.1.1 says the Authority does not assume operational control while Section 5 assigns it standards, enablement, compliance oversight and platform operations. Enablement and platform functions should be separated from any compliance assessment role. Regulated entities should have a single point of contact, formal escalation arrangements and predictable decision timelines.
The same principle should apply within ministries. The person or team delivering an AI use case should not be the person or team performing its risk, ethics and compliance review.
Comment 9
Affected sections: 3.8.5, Section 5 item 2, Annex A
The Strategy refers to sandboxes in many places, including industry sandboxes, sectoral sandboxes and a maritime sandbox. No date, responsible authority or funding is attached, and the Article 57 obligation is not mentioned.
Article 57 of the AI Act requires each Member State to ensure that at least one AI regulatory sandbox is established at national level. The original deadline of 2 August 2026 was moved by Regulation (EU) 2026/1744, and the obligation now stands at 2 August 2027. The obligation may be met jointly with another Member State, or by participating in an existing sandbox providing equivalent national coverage.
We propose that the Strategy name the responsible authority, state the operating model, commit to an operational date within the deadline, and state whether Cyprus intends to meet the obligation alone or jointly. It should confirm the priority access for small and medium enterprises and start-ups required under Articles 58 and 62. Participation should remain voluntary and support testing and compliance readiness. It should not become a precertification mechanism or a prerequisite for procurement, deployment or market access.
Cyprus has a live legal deadline eleven months away with no named authority, no operating model and no date in its national strategy. A sandbox that is genuinely operational ahead of August 2027, well documented and open to foreign small and medium enterprises, would be a concrete demonstration of the trusted jurisdiction proposition.
Comment 10
Affected sections: 3.9, 3.3.2, 3.4.2, Annex B, Annex F
The Strategy requires mandatory legal, ethical and data protection assessments for high-impact systems and approval gates before procurement, deployment and scaling. It specifies no methodology, template, publication requirement or consultation requirement.
We propose a single national methodology for an integrated impact assessment covering fundamental rights, ethics, data protection and, where material, environmental and workforce effects. It should be required for high-risk systems and for any system materially affecting rights or access to public services, whether or not classified as high risk under the AI Act. It should be completed before Control Gate 2 in Annex B, with a non-confidential summary published in the public register, and repeated after substantial modification, material drift, a serious incident or a significant change of context. Proportionate consultation with affected groups and frontline professionals should apply where impact is material.
Three operational points matter. There should be one methodology rather than several, so a public body completes a single assessment. The assessment must attach to a gate in the delivery lifecycle, or it becomes documentation produced after decisions are already made. The template must be usable without specialist support, or small bodies and local authorities will not complete it. The assessment should be prepared by a person independent of the delivery team, or where the size of a body makes that impractical, reviewed independently before the gate.
The methodology governs the public sector’s own use of AI. It should not impose obligations on private organisations beyond Union and sectoral law.
Comment 11
Affected sections: 3.3.2, 3.9.5, 3.11.3, 3.13, Annex B, Annex F
The commitment to redress exists in four places. Section 1.1 refers to clear redress mechanisms. Section 3.9.6 commits to mechanisms for redress. Annex A describes an aspiration to establish a robust and accelerated legal mechanism. The control framework refers to procedures for incident reporting, escalation and remediation. None states to whom an incident is reported, how a citizen reports harm, what is published, or within what period.
We propose that the incident pathway be defined in operational terms. Establish a single reporting channel for citizens, public servants and suppliers. Define what constitutes a serious incident, aligned with Article 73 of the AI Act, so that a single report discharges both national and Union obligations where the law permits. State the internal reporting timeline and the escalation route. Publish an annual account of serious incidents, systems suspended or withdrawn, corrective actions and time to remediation, in aggregated and anonymised form that protects personal data, trade secrets and security-sensitive information. Include reversal and override rates, and the number and resolution time of requests for human review, in the measurement framework.
The Strategy should state explicitly that transparent incident reporting is treated as evidence of good governance rather than as failure. If reporting an incident is treated as an admission of fault, incidents will be resolved quietly and the national record will show a safety performance that does not exist.
Comment 12
Affected sections: 3.4.1, 2.5.8, 3.1.2, 3.3.2, 3.6.3, Annex B, Annex F
Section 3.4.1 states that the government will work towards AI-first procurement models by 2032. The control framework refers to approval gates and to approved and certified delivery partners. There are no standard contractual requirements.
We propose two changes. First, replace the AI-first framing with a problem-first framing, committing that procurement will assess whether AI is the appropriate solution to a defined problem and that AI-enabled options are evaluated on outcomes rather than on technology category. Section 3.1.2 already states that AI initiatives will be selected on measurable outcomes and not on technological novelty. The AI-first formulation states the opposite, and it appears twice, in Section 3.4.1 and in the description of the Government Innovation Hub.
Second, mandate a standard set of contractual requirements for AI procurement. These should cover technical documentation sufficient for oversight, rights of independent audit, ownership and deletion of data, portability of exportable data and digital assets in interoperable formats, substitutability of models and components where technically and legally feasible, avoidance of lock-in, open standards, documented accuracy and fitness for purpose, continuous monitoring of failure and bias, liability and remediation, tested exit, complete audit logs, publication of lifecycle cost, and environmental impact where material. Audit rights should be scoped to the oversight objective and should protect trade secrets, with recognised certifications accepted where they provide sufficient evidence.
We would add one point on lot sizing. Large tenders normally require minimum turnover and evidence of comparable prior contracts. Applied to national AI programmes that test is circular, because a company can only qualify by having already delivered a programme of similar scale, and Cyprus has never run one. Every domestic supplier is excluded before its capabilities are examined. Dividing flagship programmes into lots that a small domestic supplier can bid for requires no additional funding, no new institution and no legislation, only a decision taken when the tender is drafted.
Comment 13
Affected sections: 3.4.2, 3.5, Annex A, Annex C
The Strategy states that private-sector AI adoption is voluntary. Other provisions qualify that significantly. Section 3.4.2 provides that every sizeable organisation must formalise an AI adoption plan. Annex C provides that in regulated sectors institutional AI strategies become part of supervisory reporting with the same legal weight as risk-management frameworks, and that private enterprises dealing with critical and high-risk systems must share their AI strategy and acceptable use policy in order to obtain or renew participation in state-subsidised programmes, access to national compute or datasets, and new or renewed operating licences in strategic sectors. The terms sizeable organisation, critical and high-risk systems, strategic sectors and basic compliance are not defined.
We propose four changes. Preserve the voluntary character of private-sector adoption, and recast the requirement that every sizeable organisation formalise a plan as guidance. Remove the connection between disclosure of an enterprise AI strategy and the grant or renewal of operating licences. Do not give institutional AI strategies the same legal weight as risk-management frameworks by way of a strategy document, since supervisory reporting obligations should be established under Union and sectoral law within the mandate of the competent regulator. Where eligibility conditions attach to state-supported programmes, national compute or public datasets, they should be transparent, risk based, proportionate and non-discriminatory, requiring only the information necessary and accepting targeted attestations rather than a full institutional AI strategy.
A corporate AI strategy contains forward-looking commercial plans, technical architecture, security controls and supplier relationships. Conditioning market access on its disclosure, through a strategy document rather than legislation and with undefined triggering terms, creates legal uncertainty for every company operating in or considering Cyprus.
Comment 14
Affected sections: 3.5, Annex C
Section 3.5 and Annex C propose an AI Judge Capability for very basic, factually uncontested cases valued under five thousand euro, subject to legal constraints and human oversight. They also propose AIREG, a blockchain-based registry providing immutable certification of AI assets.
On the judicial provision, we propose replacing the term AI Judge Capability with AI-assisted judicial administration and decision support, and stating expressly that AI may support administration, research and analysis but does not determine case outcomes, issue judgments or exercise judicial authority. The competent judge should retain independent judgment, decisional authority, responsibility for the reasoning and accountability for the outcome. Any deployment should protect the right to a fair trial, procedural fairness, contestability and effective human oversight. Judicial and case-outcome uses fall within the high-risk categories of the AI Act.
On AIREG, we propose that its scope, legal effect and disclosure requirements be defined. Registration should be voluntary and evidentiary, supporting proof that a record existed at a point in time and has not been altered. It should not create or determine ownership, alter copyright or intellectual property rules, or be presented as establishing Union-wide presumptions, and it should not require disclosure of model weights, training data, source code or trade secrets.
Terminology carries commitments. A national strategy that announces an AI Judge, whatever the safeguards in the surrounding text, invites every reader to conclude that Cyprus intends machines to decide cases, and that impression will outlive the caveats.
Comment 15
Affected sections: 1.1, 2.4, 2.5.6, 2.5.8, 3.7.3, Annex G
Sovereignty is central to the Strategy and is used in at least three different senses across the document. Sometimes it means physical control of compute, sometimes legal and regulatory autonomy, sometimes the ability to decide independently while relying on partners for delivery. Sovereignty that is not defined cannot be planned, budgeted, procured or measured.
We propose a single operational definition across five layers, each with its own test, owner and indicator. Infrastructure sovereignty concerns where computation runs, under whose jurisdiction, and whether critical services continue if a supplier relationship ends. Data sovereignty concerns who decides access to national datasets, on what legal basis, with what auditability. Model sovereignty concerns the ability to choose, inspect, adapt, evaluate and replace the models on which public services depend. Application and assurance sovereignty concerns the ability to verify independently that a system performs as claimed. Talent sovereignty concerns whether the knowledge to specify, commission, operate and supervise these systems sits inside Cypriot institutions.
The definition should go into the glossary in Annex G, be used consistently, and be supported by a small number of indicators. The Strategy should state where Cyprus intends to be on each layer by 2032.
Three points keep the framework practical. Each layer is measured through verifiable outcomes and controls, and each can be satisfied while working with international partners. Inspection means access to information and evidence proportionate to the use case, sufficient to evaluate performance, limitations, safety, security and compliance. Talent sovereignty means the capability to specify, commission, evaluate and govern, which is where the existing education and skills provisions already do most of the work.
Comment 16
Affected sections: 3.7.1 to 3.7.5, 3.10.2, Annex F
Section 3.7.3 states that infrastructure choices should be guided by interoperability, portability, vendor diversity, supply chain resilience, security and long-term sustainability. This is the right list, expressed as guidance rather than requirement, and none of it is measured.
We propose that the guidance be converted into testable criteria applied at procurement and reviewed annually. First, legal and regulatory exposure, meaning the extent to which applicable legal regimes may compel access to data or affect service continuity, assessed for the relevant workload alongside the technical and contractual safeguards available. Second, key control, meaning who holds encryption keys and administrative access. Third, exit, meaning a documented and tested plan to move a workload to another provider within a stated period. Fourth, dependency, meaning a published register of critical dependencies across compute, models and platforms. Fifth, continuity, meaning what happens if a supplier relationship ends at short notice.
Two indicators should be added. One measuring material dependency on any single provider across compute, model and platform layers, regardless of nationality or place of establishment, assessed through workload criticality, substitutability, interoperability, tested exit and continuity. One measuring the share of critical public workloads subject to legal regimes permitting compelled access from outside the Union without effective safeguards. The first measures resilience, the second measures the exposure that motivates the sovereignty objective, and neither substitutes for the other.
We recommend that Cyprus adopt the European Commission’s Cloud Sovereignty Framework rather than design national criteria. It assesses providers against eight sovereignty objectives, assigns assurance levels, and was applied by the Commission in April 2026 to a sovereign cloud award. Adopting it gives Cyprus a tested methodology at no development cost and aligns national procurement with Union practice.
The risk in a hybrid model is not the partnership itself but the absence of an exit path. Sovereignty as reversibility is testable in a way that sovereignty as ownership is not.
Comment 17
Affected sections: 3.2, 2.5.6, Annex C, Annex D
The Strategy treats data modernisation and the National Data Policy as prerequisites for AI adoption, which is correct. It proposes a federated architecture, a national data layer and a national API fabric, and a National Health Data Repository. Annex C states that healthcare data and interoperability will follow HL7 FHIR, SNOMED CT and ICD, and will reflect European Health Data Space principles.
We propose three additions. First, state the sequencing explicitly and accept that digital maturity differs across public bodies, so that AI adoption is staged according to the readiness of each organisation rather than applied uniformly. Second, establish a formal data access framework, including data access committees with published decision criteria and published decisions, so that access to high-value national datasets is governed by a visible process rather than by negotiation. Third, convert the reference to European Health Data Space principles into an operational commitment, identifying the national bodies responsible for primary and secondary use of health data, stating how Cyprus will connect to the cross-border infrastructures, and setting a date. The semantic and technical standards named in Annex C should be carried into the main body of the Strategy, since they apply well beyond healthcare.
Data sovereignty is not achieved by holding data nationally. It is achieved by controlling, documenting and being able to justify decisions about access. A federated architecture without published access rules relocates discretion rather than governing it.
Comment 18
Affected sections: 2.5.8, 3.7, 3.8, 3.8.6, Annex D
The Strategy addresses compute, data, skills and governance. On models it says relatively little. The Government Innovation Hub is to guide developments for sovereign specialised learning models, and a legal language model trained on Cyprus law is proposed. There is no national position on which models the state will use, on what basis it will choose them, how it will evaluate them, or how it will change them. In the delivery lifecycle, model approach appears once, in Annex B Stage 2, with no criteria attached.
We propose a short model layer subsection covering five points. First, a model selection policy enabling choice among commercial, open weight and nationally adapted models on the functional requirements and risk profile of each use case, with criteria covering performance and accuracy including Greek-language performance, security, privacy, safety, transparency, legal compliance and licensing, interoperability, operational support, total cost of ownership, and substitutability. Second, a scoped weighting for open weight models in defined use categories where inspection, independent evaluation or long-term availability is material to the public interest, applied through the criteria of a specific procurement rather than as a general preference or a mandatory condition. Third, national evaluation capability, meaning the ability to test a model against Cypriot requirements. Fourth, adaptation rather than creation, meaning that Cyprus fine-tunes existing models and participates in European initiatives rather than financing a national foundation model. Fifth, portability, so that the underlying model can be replaced without rebuilding the service.
Model choice is where dependency is created and hardest to reverse. In agentic systems the lock-in accumulates in orchestration, tool integration and evaluation rather than in the model itself, so the Strategy should commit to open, vendor-neutral interoperability standards adopted from recognised international bodies.
Portugal released a national model for European Portuguese in July 2026 for an initial public investment of approximately five and a half million euro, built by extending an existing open European model rather than training from scratch. That is the cost envelope and the method a country of Cyprus’s size should plan against.
Comment 19
Affected sections: 2.5.1, 3.8, 4.3, Section 5 item 4, Annex C
The Strategy proposes a National AI Compliance Framework, a certification registry, an annual audit function and centres of excellence, and positions Cyprus as a compliance and testing hub. It does not describe the capability required to perform assurance, or identify who will be qualified to do it.
We propose an assurance capability plan with three elements. First, technical evaluation capacity, meaning people and facilities able to test AI systems for accuracy, robustness, bias, security and compliance, hosted in the research ecosystem and available to the public sector and industry. Second, an explicit assessment of whether Cyprus should host one or more notified bodies under the AI Act, and if so what accreditation and staffing that requires and by when. Third, deliberate development of AI assurance, audit, evaluation and compliance services as an export industry building on the existing professional services base.
Where the capability performs conformity assessment under the AI Act, it should operate within the applicable accreditation and notified body framework. It should not create additional national certification, registration or audit requirements, and it should not extend to the supervision of general purpose AI models as such, which is the role of the European AI Office. Voluntary evaluation and compliance support should complement the Union framework and should not become a prerequisite for procurement, deployment or market access.
This is the commercial opportunity best matched to what Cyprus already has. Assurance is also the layer at which sovereignty becomes economically productive. A country that can independently verify AI systems does not need to own them in order to trust them.
Comment 20
Affected sections: 1.5, 3.10.3, Section 5, Annex F
The Strategy is not silent on money. Section 3.10.3 states that funding may combine public investment, European co-funding through EuroHPC and Digital Europe, and structured cost-sharing. Section 3.3.1 states that budget allocations will be aligned with strategic performance goals agreed between the Ministry of Finance and the Deputy Ministry. The Sovereign Investment Matching Fund carries a stated cap of one million euro per round per company.
What is absent is scale and attribution. There is no total investment envelope, no figure attached to any of the four proposed funds, no capital or operating cost for the national compute infrastructure, and no budget or named delivery owner against any individual action. The funding sources are named in the conditional.
We propose a costed delivery plan for the period to 2032, published as a companion document and updated annually. For each major action it should state the responsible organisation, the delivery lead, the timetable and interim milestones, the expected deliverables, the estimated budget and funding source, the staffing requirement and the principal dependencies. Cost should be assessed across the full lifecycle rather than at procurement, including operation, maintenance, security, audit, data management, model monitoring, licensing, support, upgrade and decommissioning. The total public investment envelope and its expected sources should be stated.
Estonia, a country of comparable population with a stronger digital baseline, backed its AI and Data Action Plan for 2024 to 2026 with a stated package of approximately eighty-five million euro. A strategy that names no figure invites the assumption that no figure has been agreed.
Comment 21
Affected sections: 3.3.1 and Figure 2 and all subsections, 4.2, Section 5 items 1 and 3
The Strategy proposes a National AI Authority including a Government AI Accelerator, an Interministerial AI Council, a National AI Taskforce, a National AI Infrastructure Committee, a National Ethics and Values Committee, a National AI Misinformation and Security Council, a National AI Skills Observatory, a Government Innovation Hub, an Industrial Centre of Excellence, a National AI Cybersecurity Centre of Excellence, AI Officers in every ministry and AI Champions in every ministry. Additional bodies appear elsewhere.
Figure 2 is a useful diagram and it is not an accountability instrument. It shows which bodies exist and how they are grouped. It does not show, for any given decision, which body decides, which approves, which is consulted and which remains answerable for the outcome.
We propose two changes. First, publish a governance and accountability matrix identifying, for every function, which body sets policy, which approves, which delivers, which supervises and which is accountable, together with escalation and dispute resolution procedures. Second, consolidate. The monitoring and advisory functions currently distributed across four separate bodies could be delivered by fewer standing committees reporting through the National AI Taskforce, and the three centres of excellence could share a single governance and administrative structure while maintaining distinct technical missions. Where an existing institution can perform a function, the Strategy should say so rather than create a new body.
The objection is arithmetic. The proposed architecture requires a substantial number of senior, scarce and specialised people to staff committees, and the Strategy itself identifies limited execution capacity as one of the two structural weaknesses it must overcome. The risk is not that these bodies will conflict. It is that several will exist only on paper.
Comment 22
Affected sections: 3.10.1, 3.7, 3.4.1, Annex D, Annex F
Section 3.10.1 commits to green computing principles, renewable energy integration where feasible, efficient cooling and shared services. This is one short subsection with no measurement, no reporting obligation, no procurement weighting and no target.
We propose four changes. First, state that data centres supporting national AI infrastructure will report energy and water key performance indicators in line with Article 12 of the recast Energy Efficiency Directive and Commission Delegated Regulation (EU) 2024/1364, which apply to facilities with installed information technology power demand of at least 500 kilowatts and cover energy consumption, capacity utilisation, waste heat, renewable energy and both total and drinking water consumption. Second, publish national aggregate figures annually, reusing information already reported under Union and national mechanisms rather than creating a duplicative national channel, with aggregation that protects trade secrets and security-sensitive information. Third, include energy and water performance as weighted criteria in the procurement of AI infrastructure and services. Fourth, add environmental indicators covering energy intensity, water consumption, share of renewable supply and waste heat recovery.
This is a matter of national self-interest rather than general environmental preference. Cyprus operates an isolated electricity system with no interconnection to a continental grid, which makes additional large and inflexible loads more consequential than in most Member States. Cyprus also faces severe water stress, and the Strategy itself identifies water management as a research priority. Data centre cooling is water intensive.
The European Commission is developing a Union rating scheme for data centres with labels expected from 2027. Facilities that already measure and report will be able to demonstrate performance from the outset.
Comment 23
Affected sections: 1.5, 2.5.2, 3.4, 3.5, 3.11, Section 5 item 4, Annex C, Annex F
The Strategy has targets but very few milestones. A target is an endpoint. A milestone is a dated checkpoint with an owner and published evidence.
Quantified endpoints appear throughout Section 1.5 and Annex C, including a recommended productivity improvement of 15 per cent, a recommended GDP expansion of 12 per cent, more than three thousand AI professionals, a 40 per cent reduction in citizen waiting times, and sector figures for shipping and financial services. Almost all are dated 2030 or 2032 with nothing in between. Dated commitments appear in only one place, in Section 5.
The measurement framework is not yet operational. Annex F is described as a sample and as indicative. It lists categories of indicator rather than indicators, with no baseline value, no numerical target, no data source, no measurement method, no reporting frequency and no organisation named as responsible. The implementation timeline in Section 1.5 uses relative bands of 0 to 8 months, 6 to 12 months and 12 to 24 months, with no anchor date, followed by a band labelled 2026 to 2032 that overlaps them.
We propose six changes, of which the first three are the priority. Publish a milestone schedule with absolute dates rebased to the date of adoption, each milestone naming the responsible body and the evidence to be published. Complete Annex F, attaching to every principal indicator a baseline, a numerical target, a target date, a data source, a measurement method, a reporting frequency and a named responsible organisation, with baseline measurement completed within twelve months of adoption. Provide for one mandatory mid-point review in 2029, conducted by an independent external evaluator, published in full and accompanied by a corrective action plan where performance is behind trajectory. Reconcile the adoption targets to a single headline definition. Publish the assumptions behind the productivity and GDP projections or restate them as scenarios. Report annually to the House of Representatives with public debate.
On the arithmetic, the figures do not reconcile. The Strategy records enterprise AI adoption at 9.27 per cent in 2025 following annual progression of 17.3 per cent, and sets a target of 75 per cent industry adoption by 2030. Held at the rate the document itself observes, 9.27 per cent compounds to approximately 21 per cent by 2030. Reaching 75 per cent within five years requires sustained annual growth of roughly 52 per cent, about three times the observed rate. Extending the horizon to 2032 still requires roughly 35 per cent annual growth.
Comment 24
Affected sections: 2.3.4, 2.5.1, 3.12, Annex A
The Strategy positions Cyprus as a bridge between the European Union and neighbouring regions, refers to readiness to participate in the Global Partnership on AI, and aligns with the OECD principles. It does not refer to the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, and it does not describe what the bridge role means in practice.
We propose two additions. First, address the Framework Convention explicitly, stating Cyprus’s position and how the Convention relates to obligations arising under Union law. This matters because the Convention is the principal instrument through which non-Union states in the region engage with rights-based AI governance, and it is therefore directly relevant to a bridge role. Second, convert the bridge positioning into concrete commitments, for example a regional forum on AI governance hosted in Cyprus, cooperation programmes with Eastern Mediterranean and Middle Eastern partners on assurance and standards, and participation in international capacity building.
This is the area where Cyprus has the clearest comparative advantage and the least developed plan. Regulatory credibility is transferable in a way that compute capacity is not. If Cyprus becomes the place where regional actors learn how European AI governance works in practice, the bridge role generates both influence and revenue.
Comment 25
Affected sections: 3.6 (International alignment), 2.5.8, 3.12, Annex C
Section 3.12 adopts a broad and outward-looking approach to international engagement. The treatment of education and human capital is narrower. Under International alignment, the Strategy provides that the UK National AI Skills Framework will inform occupational pathways and competency structures, complemented by collaboration with Finland, France and Estonia on teacher training, AI literacy and ethics in education. The Strategy separately states that it references international best practices from Finland, France, Estonia, the UK and the UAE across education, governance, infrastructure and public-private collaboration. The criteria for selecting these jurisdictions are not stated, and it is unclear whether the list is illustrative or exhaustive. Section 1.7 describes a wider literature review covering the national strategies of Cyprus, Greece, Malta, France, Estonia, the UAE, Finland and the UK, so the evidence base is broader than the education provisions suggest.
We propose two changes. State the criteria on which international reference points for AI literacy have been selected, and state expressly whether the list is illustrative. Reframe the provision as open and non-exhaustive, so that Cyprus can draw on relevant expertise and good practice from a wider range of European and international jurisdictions as the field develops, including emerging and established technology ecosystems beyond Europe such as India, where these offer complementary expertise or opportunities for mutual capacity building. Alignment with Union law, values and standards should remain the governing constraint.
AI literacy is unusually broad and fast-moving, spanning technical competency, ethical awareness, responsible use, critical thinking, digital inclusion, workforce preparedness and general societal understanding. No group of four or five jurisdictions is likely to hold the best available practice across all of these, and the distribution will change over the life of the Strategy.
Comment 26
Affected sections: 3.3.1 and Figure 2, 3.3.1.4, 3.4.1, 3.9.6, 3.11.2, Annex A, Annex C, Annex F
The following are drafting matters rather than questions of policy. We raise them because they are inexpensive to correct and because a document of this standing will be read closely by suppliers, by other Member States and by the institutions of the Union.
– The body established under Section 3.3.1.4 is titled the National AI Infrastructure Committee in its own heading, and the National AI Infrastructure Council in the Section 3.3.1 list, in Figure 2 and again in Annex A.
– Figure 2 presents the Government AI Accelerator and the Innovation Hub as a single body. The text treats the Government AI Accelerator as a component of the National AI Authority and the Government Innovation Hub as a separate innovation body.
– In Figure 2 the description attached to the AI-Industrial Centre of Excellence is the tracking of talent, skills gaps and workforce readiness, which is the function of the AI Skills Observatory and is stated for that body in the tier above.
– The names given to the centres of excellence in Figure 2 do not match those used in the Section 3.3.1 list.
– The Cyprus AI Security and Certification Authority is referred to in Section 3.9.6 and nowhere else, and is not defined.
– Industry adoption targets appear at different values and against different dates in Section 5 and in Annex C, and government adoption targets appear at different values in Section 3.4 and in Annex C.
– The implementation timeline in Section 1.5 combines relative time bands with a calendar band beginning in 2026, which overlaps them.
– We propose that a single name be adopted for each body and used consistently in the headings, in the Section 3.3.1 list, in Figure 2 and in the annexes, that Figure 2 be redrawn so that it matches the text it illustrates and each body carries its own description, and that the numerical targets be reconciled.
CITEA Comments and Recommendations
on the Cyprus National AI Strategy 2032
Formal policy submission to the Deputy Ministry of Research, Innovation and Digital Policy
Cyprus Information Technology Enterprises Association (CITEA)
Submitted by the President of CITEA
CITEA welcomes the work undertaken in preparing the Cyprus National AI Strategy 2032.
The Strategy is ambitious, comprehensive and sets an important direction for Cyprus. It recognises the effect Artificial Intelligence will have on competitiveness, productivity, public services, skills, innovation and economic development.
CITEA supports that direction. The priority now is implementation.
For the Strategy to succeed, each major initiative needs an identified owner, committed funding, a timetable, defined KPIs and a mechanism for intervention when delivery falls behind. Industry must also have a meaningful role in the decisions that affect adoption, funding and implementation.
CITEA submits the following recommendations.
1. National AI Performance Scorecard and KPIs
Reference: Section 3.11 – “Measuring Impact and National KPIs”
Suggestion
CITEA recommends strengthening the existing KPI framework through a comprehensive National AI Performance Scorecard, supported by a formal measurement and governance structure.
Each KPI should include:
• a clear definition;
• baseline value;
• annual and multi-year targets;
• accountable owner;
• responsible Ministry or organisation;
• data source;
• reporting frequency;
• calculation methodology;
• dependencies;
• escalation criteria.
The Scorecard needs to distinguish between implementation metrics and impact metrics.
Implementation metrics would include matters such as training programmes delivered, AI pilots completed, funding programmes launched, public services digitised, AI infrastructure deployed and the number of organisations participating.
Impact metrics need to show what those activities have produced in practice, including AI adoption rates, productivity improvements, economic contribution, investment attracted, export growth, SME adoption, products commercialised, improvement in public services, citizen trust and wider societal outcomes.
Justification
The Strategy already identifies AI adoption, public-sector modernisation, talent, trust, compliance and economic impact as areas in which progress has to be assessed.
What is missing is a common measurement structure that allows Government, industry and other stakeholders to work from the same baselines and targets. Without it, there is a risk that progress will be reported in terms of programmes launched and activities completed rather than the results achieved.
A National AI Performance Scorecard would provide a consistent basis for reporting, early identification of underperforming initiatives and timely intervention.
2. Formal Six-Month Implementation Review in 2027
CITEA proposes a formal review of implementation at the end of June 2027.
By that point, the Government needs to be in a position to report what has been implemented, how much funding has been committed and deployed, how many companies and SMEs have adopted AI, how many pilots have entered production, how many public-sector projects are operational, and what productivity and economic gains can already be identified.
Where agreed KPIs have not been achieved, corrective measures must follow in the second half of 2027. Depending on the cause, these may involve additional funding, budget reallocation, programme redesign, changes in delivery organisations, accelerated procurement mechanisms, removal of administrative barriers or reassignment of responsibility.
The purpose of this six-month review is practical. It gives Cyprus an early opportunity to identify what is working, what is not, and what needs to change before delays become embedded.
3. Clear Roles, Responsibilities and Decision-Making Framework
Reference: Section 3.3 – “Governance and Controls”
Suggestion
CITEA recommends a detailed Roles, Responsibilities and Decision-Making Framework covering the organisations involved in implementation.
This framework needs to set out the responsibilities, decision rights, consultation requirements and reporting obligations of the responsible Ministry or Deputy Ministry, the National AI Authority, the Interministerial AI Council, specialised advisory committees, delivery organisations, regulators, public-sector entities, research institutions, local authorities, private-sector representatives and industry associations.
For every major initiative, the Strategy must identify the organisation responsible for delivery, the Ministry with policy ownership, the owner of the relevant KPI, the body controlling the budget, the decision-making authority and the person or organisation answerable for delay.
This level of definition is necessary where initiatives cross several Ministries, agencies and sectors. It will reduce overlap, make escalation easier and allow delivery problems to be addressed quickly.
4. Dedicated AI Implementation Body with Budget and Authority
CITEA recommends the establishment of a national AI implementation body or executive committee with its own approved budget and delegated authority.
Its remit must extend beyond consultation and coordination. It needs the power to initiate projects, approve or recommend funding, accelerate priority initiatives, resolve cross-Ministry obstacles, monitor delivery and intervene where agreed targets are slipping.
It must also be able to trigger corrective action when progress falls below plan.
A body given responsibility for implementation needs the financial capacity and decision-making authority to carry that responsibility through.
5. Detailed Implementation Roadmap to 2032
Reference: Section 1.5 – “Implementation Timeline and Success Metrics”
Suggestion
CITEA recommends a detailed implementation roadmap covering the period to 2032, with milestones, timelines, deliverables, responsible organisations, dependencies, budgets and KPIs.
The roadmap needs to distinguish immediate priorities, 2027 milestones, medium-term targets and long-term outcomes. Annual budget requirements and the organisation responsible for each deliverable must form part of the same plan.
For every major initiative, the basic information must be available in one place: who owns it, what budget is available, when delivery is due, which KPI will be used and what result is expected.
This would give the Strategy a practical management structure and provide a common basis for monitoring progress across Government and industry.
6. Dedicated €1 Billion National AI Investment Programme 2027-2032
Reference: Section 3.10.3 – “Funding and Renewal Model”
CITEA strongly recommends that Cyprus commit to a National AI Investment Programme of at least €1 billion for the period 2027-2032.
The financial commitment needs to match the ambition set out in the Strategy. AI is becoming a major driver of national competitiveness, productivity, innovation, investment, economic growth, digital sovereignty and public-sector modernisation.
A programme of this scale cannot depend on fragmented calls and annual discretionary budgets. CITEA proposes a multi-year national investment envelope with funding planned from 2027 through 2032.
Indicative Investment Profile
Year Proposed Investment
2027 €100 million
2028 €140 million
2029 €170 million
2030 €190 million
2031 €200 million
2032 €200 million
Total €1 billion
The programme needs to begin strongly in 2027 and increase as infrastructure, market capacity and AI adoption expand.
The €1 billion can be built from a combination of:
• Government funding;
• European Union programmes;
• structural funds;
• AI Factory investments;
• digital infrastructure;
• private-sector co-investment;
• public-private partnerships;
• SME adoption programmes;
• innovation and commercialisation programmes;
• skills programmes;
• AI infrastructure, cloud, data and compute;
• public-sector AI transformation.
Financial Transparency
CITEA asks that the Strategy report separately how funding is allocated to Research, Innovation, AI Adoption, Infrastructure, Skills and Public-Sector Transformation.
Research expenditure must be reported separately from adoption expenditure so that Government, industry and the public can see how much funding is reaching companies and the wider economy.
The investment framework also needs to connect expenditure to outcomes. For each major funding line, the Strategy must state the intended result, the amount committed and the economic return or public value expected.
7. Research, Innovation and AI Adoption Must Be Clearly Separated
CITEA’s position is that Research, Innovation and AI Adoption are different activities and need different objectives, programmes, funding mechanisms, evaluation criteria and KPIs.
Research
Research concerns scientific discovery, advanced research, the creation of new knowledge, academic excellence, scientific publications and longer-term technological development. Appropriate Research KPIs include scientific output, publications, research excellence, new knowledge and patents arising from research where applicable.
Innovation
Innovation concerns the conversion of ideas and intellectual property into products, companies and commercial activity. It includes new products, IP, commercialisation, startups, scale-ups, new markets, investment and exports. Appropriate Innovation KPIs include products reaching the market, IP created, private investment attracted, export revenue, international customers and companies scaling internationally.
AI Adoption
AI Adoption concerns the use of existing technologies by organisations to improve productivity, competitiveness, cost structures, decision-making, revenue, customer service, operational efficiency and workforce capability. Appropriate Adoption KPIs include the number of companies implementing AI, productivity gains, cost reductions, revenue improvements, employees reskilled, processes automated and operational efficiencies achieved.
A company implementing an existing AI solution must not be forced to present that project as research in order to receive support.
Cyprus will not achieve broad business adoption if the mechanism for deploying proven technology is treated in the same way as a research grant.
8. Strong Industry Participation in SME AI Funding
The ICT industry needs a formal role in the design, implementation and evaluation of AI funding programmes for SMEs.
Those programmes have to reflect the costs and barriers businesses face in practice. These include implementation and integration costs, cloud infrastructure, cybersecurity, data readiness, staff training, consultancy and access to specialist expertise.
CITEA recommends establishing an AI Adoption for SMEs Committee, with CITEA in a leading or co-leading role alongside the relevant Government authorities and business organisations.
CITEA represents many of the companies that will develop, integrate and support the technologies used by SMEs. That experience can help ensure that funding schemes are workable, reach the market quickly and are assessed against business outcomes.
9. Horizontal “AI for SMEs” Programme
The Strategy needs an AI for SMEs in All Sectors programme with its own budget, adoption targets, implementation mechanism and KPIs.
The programme may include AI vouchers, implementation grants, cloud and compute credits, employee training, cybersecurity support, consultancy and integration support.
Most SMEs will not develop their own AI technologies. Their immediate opportunity is to adopt available tools and integrate them into existing operations. A national programme focused on
that objective can produce productivity gains across a much larger part of the economy than sector-specific research schemes alone.
10. Public Procurement Must Match the Speed of AI
Traditional public procurement procedures are generally too slow for technologies developing at the pace of AI.
A procurement process lasting 12 to 18 months can result in Government acquiring technology against requirements that were written long before implementation begins. During that period, products, models, costs and technical approaches can change substantially.
CITEA recommends specific mechanisms for AI and emerging technologies, including rapid proof-of-concept programmes, AI sandboxes, pre-commercial procurement, innovation partnerships, technology framework agreements, controlled pilot programmes and fast-track procurement procedures suited to emerging technologies.
The public sector needs a process that allows it to test a solution, evaluate the result, improve the design and scale what works while maintaining transparency, security and proper oversight.
Without a procurement route that reflects the pace of the technology, public-sector AI programmes will face avoidable delays.
11. Conflict-of-Interest and Supplier Neutrality Framework
Government needs private-sector expertise to develop and implement AI policy. That participation has to be accompanied by safeguards that prevent an advisory role from creating an unfair commercial advantage.
CITEA recommends a formal Conflict-of-Interest and Supplier Neutrality Framework.
Where a technology company, consultancy or supplier is engaged to advise a Ministry, public authority or national AI governance body on strategy, architecture, technical specifications, procurement design, funding criteria or supplier evaluation methodologies, that organisation, its parent company, subsidiaries and relevant affiliates must normally be barred from bidding for directly related implementation work arising from the engagement.
The restriction must apply for the duration of the advisory engagement and for a defined cooling-off period afterwards. CITEA proposes that a period of approximately 12 to 24 months be considered, depending on the nature of the engagement.
Any exception requires an independent assessment and documented approval confirming that no unfair competitive advantage has been created.
The same principle applies where companies participate in the design of funding programmes. A firm involved in setting programme criteria must not gain privileged access to the resulting funding or influence conditions in favour of its own technology.
The purpose is to preserve industry participation while protecting fair competition and confidence in public decision-making.
12. ICT and Software Must Be a Priority Sector
The omission of ICT and software as a standalone priority sector needs to be reconsidered.
The ICT sector is an economic sector in its own right, with strong GDP contribution, export potential, high-skilled employment, substantial AI absorptive capacity and the ability to develop products and services that can scale internationally.
Cyprus needs to pursue two parallel objectives. The first is AI adoption across the economy. The second is the development of an internationally competitive Cyprus AI industry capable of creating and exporting products, technologies and services.
For the ICT and AI industry, relevant indicators include AI software exports, international recurring revenue, new AI products launched, Cypriot IP created and retained, international customers acquired, private investment attracted and high-value technology jobs created.
Cyprus must aim to be a producer and exporter of AI technology as well as an adopter.
13. Retail and Wholesale Should Be Explicitly Included
Retail and wholesale are significant parts of the Cypriot economy and SME base and need explicit recognition in the Strategy.
Retail has particular importance for Cyprus because of its relationship with tourism, hospitality, payments, logistics, e-commerce, consumer experience and the wider visitor economy. Tourist expenditure extends well beyond accommodation, restaurants and transportation. Retail forms part of the visitor experience and of the economic value generated by tourism.
AI can deliver practical gains in demand forecasting, inventory optimisation, automatic replenishment, pricing, customer personalisation, multilingual interaction, workforce planning, supply-chain management, e-commerce and payments.
CITEA proposes that Retail be added as a priority sector or, alternatively, supported through a specifically funded Retail & Commerce AI Transformation Programme.
14. Broader Sector Coverage
The eight priority sectors identified by the Strategy are important, but they do not cover substantial parts of the economy and SME base.
Manufacturing, agri-food, energy and utilities, construction, retail and wholesale, transport and logistics, and ICT and software all require access to structured AI adoption programmes.
Where the existing eight-sector model is retained, the Strategy needs to specify what support companies outside those sectors can access, under which programme and with what budget.
General statements on inclusion are insufficient unless firms outside the priority sectors have an identifiable route to funding and implementation support.
15. Open Architecture, Interoperability and Vendor Independence
Public AI investments need to avoid unnecessary long-term dependency on individual suppliers.
CITEA recommends that public AI systems, where technically feasible, use open standards, interoperable architectures, documented APIs, portable data structures and defined exit mechanisms.
Government entities must retain control and ownership of their data and have practical means of moving data, applications, AI workloads and models between suppliers where required.
Procurement evaluation needs to consider vendor dependency, migration cost, interoperability, long-term operating cost and exit cost alongside the initial project price.
National AI infrastructure must be designed so that dependence on a single cloud provider, consulting organisation, model provider or technology vendor does not become embedded in public systems.
16. National Data and AI Infrastructure
AI adoption requires access to high-quality data, cloud infrastructure and computing capacity.
The Strategy needs continued investment in trusted national data platforms, secure Government APIs, interoperable datasets, national data spaces, AI Factory resources, compute infrastructure, cloud capability and cybersecurity infrastructure.
Access must extend to SMEs, startups, established technology companies and innovative businesses, alongside universities and large organisations.
Pricing, eligibility and allocation rules need to support commercial use as well as research activity. If national infrastructure is intended to support the economy, companies must be able to access it on terms that allow them to build and deploy products.
17. Skills, ICT Upskilling and Workforce Transformation
AI skills policy needs to reach well beyond universities and academic research. Cyprus requires rapid reskilling and upskilling across the existing workforce, including SME employees, CEOs and business leaders, managers, professionals, public-sector employees, technical specialists and educators.
CITEA also recommends a specific national track for upskilling and reskilling employees working in Cypriot technology companies. The country cannot deliver an ambitious AI programme unless its own ICT sector has the skills to design, integrate, secure, support and export AI solutions.
Software developers, data professionals, cloud engineers, cybersecurity specialists, business analysts, consultants, project managers and technical support teams will all require new capabilities as AI becomes embedded in mainstream software and business systems.
The ICT skills programme needs to cover applied AI development, AI agents, data engineering, machine learning, AI architecture, cybersecurity for AI, responsible AI, AI governance, model integration, cloud and compute infrastructure, API-based AI development and the commercial deployment of AI solutions.
Training needs to be tied closely to real projects and market requirements. The objective is to increase the number of professionals who can build and deploy AI systems successfully for customers in Cyprus and abroad, rather than measuring success by course attendance alone.
Special support is also required for ICT SMEs that may find it difficult to release employees for extended training or finance advanced technical certifications.
CITEA recommends support for professional AI certifications, executive education, employee reskilling, sector-specific programmes, public-sector training and the attraction of specialised international AI talent where required.
Relevant KPIs can include the number of ICT professionals completing advanced AI training, internationally recognised certifications achieved, AI specialists employed by Cypriot companies, companies developing AI products, AI projects successfully deployed and export revenue generated from AI-related products and services.
CITEA is prepared to work with Government and training institutions to identify the skills most urgently required by the industry and to help design programmes that remain aligned with rapidly changing technologies.
18. Reconsider the “AI Judge” Proposal
Reference: Section 3.5 – Legal Services
The proposed “AI Judge Capability” for low-value, factually uncontested cases creates legal, constitutional and reputational questions that go well beyond the scope of an economic and technology strategy.
CITEA takes no position on judicial policy, as this falls outside our sector. We raise the point because the terminology creates a practical risk for the Strategy as a whole. A reference to an “AI Judge” could easily become the focus of public and media discussion and distract from the wider programme.
The intended benefits can largely be achieved without assigning an adjudicative role to an AI system.
CITEA recommends removing the term “AI Judge” from the Strategy and reframing the initiative around AI-assisted judicial administration. Appropriate applications include case administration, scheduling, transcription, document processing, document classification, legal research and workflow automation.
Judicial decisions must remain within the judicial framework.
Any future consideration of automated or AI-supported adjudication requires a separate consultation involving the Supreme Court, the Ministry of Justice, the Cyprus Bar Association and relevant constitutional and legal experts.
The other LegalTech initiatives, including transcription, LegalTech sandbox programmes and Cyprus-specific legal language technologies, remain sound and merit continued support.
19. Measure Economic Impact, Not Only Activity
Training programmes, workshops, pilots and research projects all have value, but they cannot become the principal measure of success.
From 2027 onwards, Cyprus needs to track the number of companies actively using AI in production, SMEs that have adopted AI, productivity gains, cost reductions, revenue growth, AI products commercialised, exports generated, private investment attracted, high-value jobs created, public services improved, citizen satisfaction and contribution to GDP.
The purpose of the Strategy is economic and societal progress. The reporting framework must reflect that purpose.
20. Maximum 5% for External Advisory and Consultancy Expenditure
CITEA recognises that Government may require external expertise in specific areas during the implementation of the National AI Strategy. Specialist advice can be useful, particularly where Government does not have the necessary expertise internally.
At the same time, a national AI investment programme must not become disproportionately focused on consultancy, strategy work and advisory studies at the expense of actual implementation.
CITEA recommends that external advisory and consultancy expenditure be capped at a maximum of 5% of the total National AI Investment Programme and at a maximum of 5% of the budget of any individual major programme.
The 5% limit must apply to strategy consulting, programme design, management consulting, governance consulting, advisory studies and comparable professional advisory services. It must not apply to companies contracted to develop, integrate, deploy or operate AI systems where the expenditure relates directly to implementation.
Any proposed advisory expenditure above the 5% ceiling must require exceptional approval and a published justification explaining why the additional external advice is necessary and why the expertise cannot reasonably be obtained through Government, academia, industry bodies or existing national institutions.
The classification of advisory expenditure must also be defined carefully so that consulting work cannot simply be moved into another budget category.
CITEA recommends annual disclosure of the amounts spent on external advisory and consultancy services, the organisations engaged, the purpose of each engagement and the percentage of the relevant programme budget consumed.
This is particularly important in a programme of the scale proposed by CITEA. With a €1 billion National AI Investment Programme, even relatively small percentages represent significant amounts of public money. A 5% ceiling already permits expenditure of up to €50 million across the full programme.
The large majority of the available resources must reach implementation, technology adoption, infrastructure, skills, Cypriot businesses and projects capable of producing economic value.
21. AI Adoption KPIs Must Include Customer Experience
The National AI Performance Scorecard needs to measure the effect of AI on the customer experience created by Cypriot businesses, particularly SMEs.
Productivity and cost reduction are important measures, but AI adoption also needs to improve how companies serve customers, respond to them and personalise their services.
CITEA recommends the inclusion of customer-experience KPIs within SME AI adoption programmes. These may measure customer response times, service resolution times, customer satisfaction, personalisation, multilingual service capability, digital-service usage, reduction in customer complaints, conversion rates and other sector-specific indicators.
These KPIs need to be practical and suitable for SMEs. A small retailer, hotel, professional-services company or distributor cannot be expected to build complex measurement systems simply to participate in an AI programme.
CITEA is prepared to work with Government, business associations and participating companies to develop practical Customer Experience and AI Adoption KPIs for SMEs.
The aim is to demonstrate that AI investment is producing improvements that customers can experience directly, alongside gains in productivity and financial performance.
22. Establish a Major International AI Event in Cyprus
Cyprus needs a major annual international AI event capable of attracting technology companies, investors, policymakers, researchers, startups, customers and international media.
Countries that are serious about developing their technology ecosystems use major events to create international visibility, attract investment, generate business opportunities and connect local companies with global technology leaders.
CITEA recommends establishing a flagship Cyprus International AI and Technology Event, with the ambition over time to develop an event comparable in international reach to major technology and AI exhibitions held in other countries, including events such as GITEX.
The event needs to be commercially focused and internationally oriented. It can include exhibitions, product demonstrations, investment meetings, international speakers, B2B meetings, startup participation, Government programmes and opportunities for Cypriot technology companies to present their solutions to overseas customers and partners.
The objective is to bring international technology companies, buyers, investors and media to Cyprus, rather than creating another event aimed mainly at the domestic audience.
Government, CITEA, the private sector and the wider innovation ecosystem can work together to establish the event and build its international profile.
Relevant KPIs should include international exhibitors, overseas visitors, investors attending, B2B meetings, commercial agreements generated, investment leads, international media coverage and export opportunities created for Cypriot technology companies.
23. Preference for Cyprus-Developed AI Solutions in Government
Government can play an important role in building a domestic AI industry by becoming an early customer of technologies developed in Cyprus.
Where a Cypriot company has developed an AI solution that meets the required technical, security, operational and commercial standards, CITEA recommends that public-sector procurement and AI adoption programmes provide a meaningful preference for Cyprus-developed technology, within the applicable legal and public-procurement framework.
Public investment in AI should help create economic value inside Cyprus where suitable local capability already exists.
Evaluation criteria can recognise technology and intellectual property developed in Cyprus, local technical capability, local implementation and support, contribution to employment and skills, export potential, knowledge retained in Cyprus and the long-term economic value created by the procurement.
Government should also create mechanisms through which Cypriot companies can demonstrate proven AI solutions to Ministries and public organisations before large international procurement exercises are launched.
A local company that has already invested in developing a working AI solution needs a realistic opportunity to demonstrate that solution to Government.
Government adoption can give a Cypriot technology company an important reference customer. That reference can support international sales, exports, skilled employment, further investment and continued product development in Cyprus.
The National AI Strategy needs to treat public-sector adoption as an instrument for developing the domestic AI industry as well as improving Government services.
Overall CITEA Position
CITEA recognises and supports the significant work undertaken in developing the Cyprus National AI Strategy 2032. The direction is strong. The next phase requires firm ownership, committed budgets, deadlines, KPIs, transparent reporting and faster implementation.
CITEA strongly recommends a €1 billion National AI Investment Programme for 2027-2032, supported by an implementation structure with the authority and financial resources to deliver the programme.
A formal national review must take place in June 2027. Where KPIs are below target, corrective measures need to be introduced during the second half of 2027 rather than deferred to a later review.
Research, Innovation and AI Adoption need separate programmes, budgets and KPIs. ICT and software need recognition as a priority sector in their own right, while Retail requires explicit inclusion because of its economic weight and its connection with tourism and the visitor economy.
Industry must have a substantive role in funding decisions, particularly in relation to SME AI adoption. Public procurement needs mechanisms that can operate at the pace of AI. Conflict-of-interest safeguards, open architectures, interoperability and vendor independence are necessary to protect public investment and fair competition.
External advisory and consultancy expenditure must remain tightly controlled. CITEA proposes a firm maximum of 5%, ensuring that public resources are concentrated on delivery, adoption, infrastructure, skills and economic outcomes.
The national scorecard must also capture customer experience and SME outcomes, while the skills programme needs a strong ICT-sector component so that Cypriot companies can build, deploy and export AI solutions. Cyprus also needs an international AI event with global ambition, and Government procurement should give Cyprus-developed AI solutions a meaningful preference where they meet the required standards and the applicable legal framework.
CITEA is ready to take an active role in implementation alongside Government and the wider ecosystem. The Strategy has established the direction. The task now is to convert that direction into funded programmes, completed projects and economic value for Cyprus.
For CITEA
George Malekkos
President, CITEA
SUBMISSION TO THE PUBLIC CONSULTATION ON THE NATIONAL AI STRATEGY OF THE REPUBLIC OF CYPRUS 2032
BUILDING THE NATIONAL AI ASSURANCE LAYER: MAKING THE ‘TRUSTED JURISDICTION’ PROPOSITION OPERATIONAL
Submitted by: Lina Lemessiou, FCA; Founder & Managing Director; NEW Insight Limited (trading as NEWinsight™)
Submission basis: This response is submitted on behalf of NEW Insight Limited.
Perspective: Corporate reporting, governance, assurance, quality management and professional standards. The comments are made from the standpoint of how responsibilities and obligations are evidenced, reviewed and reported, and how confidence can be supported through appropriate governance, examination and oversight arrangements.
Consultation reference: Draft National AI Strategy of the Republic of Cyprus 2032, posted for public consultation on 20 July 2026.
INTRODUCTORY ASSESSMENT
The draft National AI Strategy 2032 provides an ambitious and thoughtful foundation for positioning Cyprus as a trusted, human-centred and EU-aligned jurisdiction for artificial intelligence. Its emphasis on governance, accountability, organisational readiness, risk-based controls and role-specific capability is particularly welcome.
The comments below focus on a specific implementation question: how the Strategy’s trust proposition can be supported by a coherent national assurance framework. The Strategy already refers to governance, auditability, certification and internal or external assurance where appropriate. What remains is to distinguish their respective purposes and translate them into defined responsibilities, criteria, evidence requirements, competence requirements and oversight arrangements.
Trust is not produced by governance structures or assertions alone. It is strengthened when responsibilities and criteria are clear, relevant evidence is retained, examinations are performed by competent and appropriately objective or independent parties, and those performing them are themselves subject to suitable quality management and oversight. Different mechanisms provide different forms of confidence and should be designed to complement, rather than substitute for, one another.
The following recommendations favour the use and adaptation of existing or already proposed institutions, standards and professional capabilities. They are not intended to prescribe technical testing methodologies, provide legal interpretation or treat professional assurance as a substitute for technical validation, conformity assessment or regulatory supervision.
COMMENT 1: DEFINE THE NATIONAL AI ASSURANCE ARCHITECTURE
> ARTICLE AND SECTION
Sections 2.3 and 2.4, particularly the first key idea in the Vision; Sections 3.3 and 3.3.2; Section 3.5; Section 4.3; Annex A; Annex C; Annex E.
> COMMENT AND RECOMMENDATION
Insert a new Section 3.3.3, ‘National AI Assurance Framework’, setting out a coherent framework for the different mechanisms through which confidence in AI systems, governance arrangements and reported claims may be obtained.
The framework should distinguish clearly between:
• management monitoring and operational control;
• risk and compliance functions;
• internal audit;
• technical testing and model validation;
• conformity assessment under the EU AI Act;
• certification of management systems, products, processes or persons;
• independent external assurance;
• regulatory supervision and inspection.
These activities are complementary but are not interchangeable. The framework should specify which mechanism is intended for which purpose and should prevent a certificate, technical assessment or compliance review from being represented as providing confidence over matters outside its defined scope.
For each mechanism, as applicable, the framework should identify:
• the subject matter being evaluated;
• the applicable criteria and how those criteria are established;
• the intended users;
• the scope and reporting boundary;
• the evidence and documentation requirements;
• the nature of the resulting report, certificate, conclusion or regulatory decision;
• the competence requirements for those performing the work;
• the required degree of objectivity or independence;
• how the provider is authorised, registered, licensed or accredited, as appropriate;
• the arrangements for provider oversight, quality management, complaints, remediation and, where relevant, sanctions.
For independent external assurance engagements, the framework should also identify whether reasonable or limited assurance is intended and the form of the resulting conclusion. These assurance levels should not be applied indiscriminately to certification, conformity assessment or technical testing, which operate through different frameworks.
Recognised international standards and frameworks addressing assurance, ethics and quality management should be used where appropriate rather than recreated nationally.
The development of the National AI Assurance Framework should involve relevant regulatory, professional, standardisation, accreditation, technical and public-interest bodies. Their respective roles should reflect their competence. Technical specialists should lead technical testing and validation; regulatory authorities should retain their statutory responsibilities; accreditation and standardisation bodies should address conformity-assessment infrastructure; and suitably qualified assurance practitioners should contribute expertise in criteria, evidence, independence, professional scepticism, documentation, quality management and reporting.
Cyprus already possesses relevant professional capacity. Regulated audit and assurance firms, internal audit professionals, accountants, governance and risk professionals, lawyers and other regulated professions bring complementary experience in evidence, ethics, professional judgement, reporting, internal control and accountability. This capacity should be recognised as part of the horizontal infrastructure supporting the priority sectors, while acknowledging that AI-specific technical and legal competence will frequently require multidisciplinary teams.
> JUSTIFICATION
The Strategy makes trust a central part of the economic and institutional positioning of Cyprus. Section 2.3 refers to compliance, assurance and trusted deployment environments as a national advantage, while the Vision at Section 2.4 identifies ‘national AI assurance’ as one of the critical layers Cyprus should control.
The Strategy also uses ‘assurance’, ‘audit’, ‘certification’ and related terms in materially different contexts. These include internal or external assurance under Section 3.3; assurance mechanisms supporting delivery under Section 3.5; ‘compliance auditing’ by the Government Innovation Hub; approved and certified delivery partners under Section 3.3.2; an annual audit under Section 3.9.6; and a funding programme ‘audited by’ a ministry under Section 5.
Each activity has different purposes, competence requirements, independence implications and forms of reporting. Unless those distinctions are made explicit, organisations and users may attribute more confidence to a certificate, validation exercise or compliance review than its scope supports.
A national assurance framework would make the Strategy’s trust proposition operational while avoiding unnecessary duplication. It would also create a common vocabulary through which technical, regulatory, professional and institutional actors could understand their respective responsibilities.
COMMENT 2: CLARIFY THE ASSURANCE BODIES, ANNUAL-AUDIT PROPOSAL AND SEPARATION OF ROLES
> ARTICLE AND SECTION
Sections 3.3.1, 3.3.1.1 and 3.3.2; Section 3.9.6; Annex A; Annex B; Annex E.
> COMMENT AND RECOMMENDATION
Section 3.9.6 refers to documented conformity assessments ‘complemented by an annual audit by the Cyprus AI Security & Certification Authority’. This body does not appear within the governance structure at Section 3.3.1 and is not otherwise defined.
The final Strategy should either:
1. define the Cyprus AI Security & Certification Authority within the governance architecture, including its legal basis, mandate, funding, competence, accountability and relationship with existing competent authorities, notifying and market-surveillance arrangements, notified bodies and sectoral regulators; or
2. remove the reference and rely on the conformity-assessment and regulatory framework established under the EU AI Act, supplemented where appropriate by voluntary accredited certification and appropriately defined external assurance.
The wording in Section 3.9.6 concerning registration in the EU database should also be aligned precisely with the roles, system categories and registration obligations established by the EU AI Act. It should not imply an undifferentiated registration or audit requirement applying to every organisation irrespective of its role, AI use, risk profile or legal obligations.
If any national audit mechanism is retained, the Strategy or subsequent implementation framework should define:
• its legal basis;
• the organisations, systems or claims within scope;
• its subject matter and applicable criteria;
• whether it is an entity-level, system-level or control-level examination;
• who may perform it;
• the required competence, objectivity and independence;
• its frequency and the circumstances in which frequency may change;
• materiality or risk thresholds;
• reporting, remediation and appeal arrangements;
• how duplication with EU AI Act conformity assessments, sectoral supervision and other existing reviews will be avoided;
• how proportionality will be maintained for SMEs and lower-risk uses.
The mechanism should be risk-based and proportionate. It should not automatically be annual, entity-wide or identical across all systems and organisations.
The Strategy should also establish functional separation between enablement, preparation, approval and independent examination.
Within the National AI Authority:
• policy coordination, adoption support and delivery enablement should be functionally separated from control-gate approval and compliance oversight;
• no individual or function should prepare the principal compliance evidence and then be solely responsible for approving the same evidence;
• high-risk, citizen-facing or otherwise high-impact systems should be subject to an appropriately objective pre-deployment review by a suitably competent person or function not responsible for preparing or delivering the system;
• reporting lines, decision rights and escalation routes should be documented.
A maker-checker or independent pre-deployment review principle may be informed by established quality-review disciplines, but it should be adapted to the AI governance context rather than treated as a direct application of audit engagement quality review.
Annex E should also clarify the statement that AI Officers act as ‘a point of coordination and assurance’. AI Officers are simultaneously described as implementation coordinators, change agents, capability builders and supporters of compliance documentation. If these responsibilities are retained, the role should be described as coordination, monitoring and challenge, rather than refer to assurance.
An AI Officer should not provide assurance over an initiative that the same officer has promoted, designed, coordinated or documented. Independent assurance, where required, should be assigned to a separate person or function.
> JUSTIFICATION
A national authority with an audit or certification mandate requires a clear legal and institutional basis. An undefined authority attached to a potentially extensive and complex annual-audit requirement creates uncertainty over jurisdiction, cost, competence, accountability and the relationship with EU and sectoral regulatory structures.
The Strategy’s wider governance model also gives the National AI Authority several roles. It establishes national frameworks, resources the Government AI Accelerator, coordinates AI Officers, supports delivery and acts as a governance and control gatekeeper. Annex E gives AI Officers responsibilities for use-case prioritisation, compliance documentation, risk oversight, capability-building and organisational change.
These responsibilities are individually legitimate, but their combination creates a risk of self-review unless preparation, enablement, approval and independent examination are clearly separated.
Functional separation does not necessarily require additional institutions. It can often be achieved through defined responsibilities, separate reporting lines, appropriately objective reviewers, documented escalation arrangements and diligent oversight. This would strengthen the credibility of the governance model while retaining the Strategy’s emphasis on efficient and coordinated delivery.
COMMENT 3: ESTABLISH THE ACCREDITATION AND CROSS-BORDER-RECOGNITION PATHWAY
> ARTICLE AND SECTION
Section 4.3; Section 5, particularly the immediate steps concerning adoption, compliance and certification; Section 3.11.2; Annex A; Annex C, including the Legal Services pillar.
> COMMENT AND RECOMMENDATION
The Strategy repeatedly positions Cyprus as a location for AI testing, certification, pre-certification and regulatory readiness. It proposes a European AI Certification Lab, a national registry of AI systems certified under EU rules, the National AI Compliance Framework and the implementation of ISO/IEC 42001 and ISO/IEC 27001 across industry and the public sector.
The ability to provide internationally recognised certification and related conformity-assessment services depends on a defined accreditation and recognition pathway.
Article 7 of Regulation (EC) No 765/2008 permits cross-border accreditation in specified circumstances, including where the national accreditation body does not perform the requested accreditation activity or has not successfully undergone peer evaluation for it.
The final Strategy should therefore establish a specific workstream, with an identified owner and timetable, to:
1. confirm with CYS-CYSAB and the European co-operation for Accreditation the current position and the accreditation services required for AI management-system certification, validation and verification and other anticipated AI conformity-assessment activities;
2. determine whether Cyprus intends to extend the scope and peer-evaluated capability of CYS-CYSAB, use permissible cross-border accreditation arrangements while domestic capability is developed, or adopt a combination of the two;
3. identify the competence, assessor and institutional-capability requirements associated with each intended accreditation scope;
4. clarify the relationship between pre-certification support, technical testing, voluntary certification, EU AI Act conformity assessment and regulatory supervision;
5. sequence the certification-hub ambition against the accreditation and recognition milestones on which it depends;
6. state how certification bodies, testing laboratories and other conformity-assessment providers will be approved, monitored and recognised within the national framework.
The European AI Certification Lab should not be described or understood as providing final accredited certification unless its legal role, applicable certification scheme, accreditation basis and institutional independence support that function. Pre-certification, readiness assessment, testing and final accredited certification should be distinguished explicitly.
> JUSTIFICATION
Accreditation provides an authoritative assessment of the competence of conformity-assessment bodies and supports the recognition of accredited certificates and reports across borders.
The current EA Multilateral Agreement scope of CYS-CYSAB does not cover all the activities implicated by the Strategy’s ambitions for AI management-system certification, validation and verification. This is a concrete implementation dependency that should be addressed in the Strategy’s sequencing and institutional-capability planning.
It does not follow that Cyprus-based bodies are incapable of obtaining internationally recognised accreditation. The European framework provides defined circumstances for cross-border accreditation. The strategic question is therefore how Cyprus will secure the necessary capability and recognition, through domestic scope extension, permitted cross-border arrangements or both.
Addressing this question now would protect the Strategy from conflating national testing or pre-certification capability with internationally recognised accredited certification. It would also identify an important area of sovereign institutional capability requiring planning, competent personnel, peer evaluation and sustained quality management.
COMMENT 4: ESTABLISH EVIDENCE STANDARDS AND MEANINGFUL HUMAN OVERSIGHT AT THE CONTROL GATES
> ARTICLE AND SECTION
Section 3.3.2; Section 3.4.3; Sections 3.9.2 and 3.9.3; Annex B; Annex E.
> COMMENT AND RECOMMENDATION
Annex B should be supplemented with a proportionate minimum evidence specification for each control gate.
For each gate, the specification should identify:
• the decision to be made and the applicable approval criteria;
• the minimum documentation required to support that decision;
• the significant assumptions, uncertainties and judgements considered;
• the evidence supporting the conclusion;
• the identity and role of the preparer;
• the identity, competence and role of the reviewer;
• the person or body accountable for the final decision;
• the dates of preparation, review and approval;
• the version of the system and supporting documentation considered;
• a defined, risk-appropriate period for completing the gate record;
• the custodian, location, access arrangements and retention period for the evidence;
• the process for logging subsequent amendments, additional evidence and changes in judgement;
• the evidence required to demonstrate that remediation conditions have been completed.
The documentation should be sufficient to enable a suitably competent reviewer with no previous involvement in the particular decision to understand:
• what was decided;
• why it was decided;
• which evidence was considered;
• which significant judgements were made;
• which limitations or uncertainties remained;
• who accepted the residual risk;
• what subsequent monitoring or remediation was required.
The control-gate framework should also define the minimum characteristics of meaningful human oversight. These should include:
• clearly assigned responsibility and decision authority;
• sufficient understanding of the use case, its limitations and its operating context;
• access to relevant and traceable evidence;
• authority to challenge, pause, override or escalate;
• ability to identify uncertainty, bias, inappropriate reliance and circumstances outside the system’s intended use;
• documentation of significant judgements and the rationale for the final decision;
• adequate time, resources and organisational support;
• safeguards against human oversight becoming a routine, procedural or ‘rubber-stamp’ approval.
Human oversight should therefore be assessed not only by whether a person is present, but by whether that person is competent, authorised and practically able to exercise informed challenge and judgement.
Evidence requirements should be proportionate to risk, impact and complexity. They should also be designed so that the same properly governed evidence can support, where relevant, internal governance, subsequent conformity assessment, sectoral supervision, incident investigation and independent assurance, rather than requiring organisations to recreate similar records repeatedly.
> JUSTIFICATION
Annex B establishes a valuable lifecycle and control-gate structure and provides for documentation at different stages. It does not, however, establish a common minimum evidence specification for each gate or define the characteristics of an adequate gate record.
An approval is not the same as defensible evidence supporting the approval. Without consistent documentation, it becomes difficult to determine whether the relevant criteria were applied, whether significant risks and uncertainties were considered, whether the reviewer exercised informed challenge or whether the gate operated only as a procedural step.
A credible Operational Assurance Review at Control Gate 4 requires a sufficiently complete and traceable record against which continuing performance and compliance can be evaluated.
The Strategy correctly states that AI should support rather than replace human judgement. The presence of a named human reviewer is nevertheless insufficient if that person lacks the competence, authority, information, time or organisational support required to challenge the system or its proponents.
A disciplined evidence framework would help translate the Strategy’s principles of auditability, traceability, accountability and human oversight into operating requirements. It would also help distinguish substantive implementation from activity that cannot demonstrate its decisions or outcomes.
COMMENT 5: CLARIFY GOVERNING-BODY AND SENIOR-MANAGEMENT ACCOUNTABILITY
> ARTICLE AND SECTION
Sections 3.3 and 3.5; Section 3.9.6; Annex C, particularly the provisions concerning the public sector, regulated private sector and private companies and organisations; Annex E.
> COMMENT AND RECOMMENDATION
The Strategy or subsequent implementation guidance should specify who holds organisational accountability for approving and overseeing Institutional or Applied AI Strategies.
The arrangements should recognise differences between ministries, public bodies, regulated entities, companies and other organisations. They should nevertheless establish the common principle that responsibility remains with the organisation’s existing governing or accountable authority and is not transferred to an AI Officer, technology function, vendor or external adviser.
For ministries and public bodies, the relevant Applied AI Strategy should be approved by the minister, governing board, accounting officer, chief executive or other legally accountable authority appropriate to the institution.
For companies and regulated entities, the board of directors or equivalent governing body should approve the Institutional AI Strategy where AI use is material, high-risk, critical to the business model or capable of significantly affecting customers, employees, investors, citizens or regulatory obligations.
The governing or accountable authority should:
• approve the organisation’s overall AI direction and risk appetite;
• confirm the allocation of responsibilities and decision rights;
• oversee the integration of AI governance with corporate or institutional strategy;
• receive appropriate information on material use cases, incidents, control failures, remediation, performance and emerging risks;
• review the strategy at a frequency proportionate to the organisation’s AI use, risk exposure and regulatory environment;
• retain responsibility for significant judgements and accepted residual risks.
Where audit committees, risk committees, internal audit, risk-management or compliance functions exist, their AI-related responsibilities should be mapped onto their existing mandates and applicable legal or regulatory responsibilities. The Strategy should not assume that every organisation has identical governance structures.
Institutional AI Strategies should be integrated, as relevant, with:
• corporate or institutional strategy;
• risk appetite and risk-management frameworks;
• internal-control arrangements;
• data governance and protection;
• cybersecurity;
• third-party, procurement and outsourcing governance;
• quality management;
• corporate and regulatory reporting;
• business continuity and operational resilience;
• workforce and organisational-change arrangements.
AI acceptable-use policies should be approved at an appropriately senior level. Governing-body approval may be appropriate where the policy addresses material, high-risk or organisation-wide use. Operational policies may be approved by management within authority delegated by the governing body.
Existing governance structures should be used and adapted before new organisational committees are created. New committees should be established only where a defined responsibility or competence gap cannot be addressed effectively through existing arrangements.
> JUSTIFICATION
Annex C provides that Institutional AI Strategies for regulated private-sector entities will form part of supervisory reporting ‘with the same legal weight as risk-management frameworks’. The Strategy does not specify which body within the regulated entity approves the Institutional AI Strategy or exercises continuing oversight over it.
Risk-management frameworks in regulated sectors are ordinarily subject to governing-body and senior-management responsibilities established through the applicable sectoral regime. Giving an AI strategy comparable significance while leaving its approval and oversight arrangements undefined creates a governance gap.
Governance structures differ across companies, public bodies and regulated sectors. The appropriate response is therefore not a universal requirement for a particular committee, but a clear accountability principle combined with proportionate application.
AI should not become a separate technology workstream operating outside established governance, reporting and control arrangements. Embedding it within existing structures would strengthen accountability, reduce duplication and help avoid the institutional complexity that could arise from creating new AI-specific bodies at every level.
COMMENT 6: ESTABLISH A CONTROLLED BASIS OF PREPARATION FOR NATIONAL AI INDICATORS
> ARTICLE AND SECTION
Section 1.5; Section 2.5.2; Sections 3.5 and 3.11; Annex C; Annex F; Section 5.
> COMMENT AND RECOMMENDATION
The Strategy’s national targets and indicators should be reconciled and supported by a published basis of preparation.
First, the final Strategy should reconcile the different adoption targets currently stated in the draft:
• Section 3.5 refers to increasing AI adoption to 50% across government and priority sectors by 2032;
• Annex C refers to 75% AI adoption by 2032, aligned with the Digital Decade target;
• Section 5 refers to 75% industry adoption of AI technologies by 2030;
• the stated baseline for enterprise adoption is approximately 9.3%.
The 15% productivity improvement and 12% GDP expansion presented as expected outcomes should also be accompanied by their source, model, assumptions, baseline trajectory, measurement period and principal limitations. The distinction between an aspirational target, an upper-bound scenario and an outcome against which delivery will be assessed should be clear.
Second, the Strategy should require a basis of preparation for every principal national indicator. This should identify:
• the precise definition of the indicator;
• the unit of measurement;
• what constitutes ‘AI adoption’, including whether it is measured at entity, use-case, employee, user or system level;
• the reporting population and boundary;
• the baseline year and baseline value;
• the target year and target value;
• the data source and data owner;
• the calculation methodology;
• the responsible organisation;
• the reporting frequency;
• relevant assumptions, estimates and limitations;
• controls over data collection, consolidation and reporting;
• arrangements for internal review, validation or external examination;
• the treatment of errors, methodology changes and restatements;
• how performance will be compared consistently over time.
Third, the adaptive character of Annex F should be supported by formal change control. Indicators may need to evolve as technology, regulation and national priorities change, but any material amendment should be:
• approved by an identified authority;
• dated and documented;
• accompanied by a clear explanation;
• assessed for its effect on previously reported performance;
• reflected through restatement or appropriate comparative information where practicable;
• disclosed in the relevant public report.
The ability to update indicators without revising the core Strategy should support learning and relevance, but should not permit targets or measurement methods to change without transparent governance.
Fourth, progress should be reported publicly through an annual ‘State of National AI’ report or equivalent mechanism. The report should present:
• performance against principal targets;
• the relevant basis of preparation;
• significant changes in indicators or methodology;
• limitations and data-quality matters;
• explanations of material variances;
• remediation or reprioritisation decisions;
• the relationship between expenditure, activity, outputs and outcomes.
A defined subset of indicators linked to significant public expenditure, national productivity claims and the ‘trusted jurisdiction’ proposition should be considered for independent external assurance or another appropriate form of external verification once sufficiently suitable and stable criteria have been established. The scope, criteria, provider, nature and level of any assurance should be stated clearly.
Independent assurance should not be imposed automatically on every indicator. It should be targeted according to materiality, public interest, risk, maturity of the measurement system and the value that external examination would provide.
> JUSTIFICATION
Reporting is not merely an output. It is a governance mechanism through which responsibilities are made visible, progress is evaluated, resources are redirected and public claims can be challenged.
An indicator without a defined boundary, methodology, data owner and baseline cannot support reliable comparison or accountability. Similarly, an adoption rate can convey materially different information depending on whether it measures organisations using at least one AI tool, production use cases, employee usage or the proportion of processes supported by AI.
The current differences between the stated adoption targets make it difficult to identify the principal national target and the population to which it applies. The productivity and GDP figures also require a transparent analytical basis if they are to function as performance measures rather than illustrative scenarios.
Annex F correctly recognises that measurement must evolve. Adaptability and accountability can coexist if changes are governed, documented and disclosed while comparative information is preserved as far as practicable.
A controlled basis of preparation, transparent public reporting and targeted external examination would strengthen the Strategy’s response to the risk of ‘AI theatre’. They would enable Cyprus to demonstrate not only that activity occurred, but that claimed outcomes were defined in advance, measured consistently and subjected to appropriate challenge and oversight.
CONCLUSION
The Strategy is right to place trust at the centre of Cyprus’s positioning and to recognise that trust must be built through governance, accountability, human oversight, organisational capability and evidence.
The next step is to translate those principles into a coherent set of assurance roles, criteria, evidence requirements, competence requirements and oversight arrangements.
The recommendations above draw principally on institutions, standards and professional capabilities that Cyprus already possesses or proposes to develop.
They would:
• distinguish professional assurance from certification, conformity assessment, technical validation and regulatory supervision;
• clarify the responsibilities and independence or objectivity of the bodies involved;
• establish the accreditation pathway supporting the certification-hub ambition;
• create a traceable evidence base for lifecycle decisions;
• make human oversight substantive rather than procedural;
• embed accountability within existing governing structures;
• make national targets and reported progress more credible and capable of appropriate examination.
Adopting these recommendations would make the national trust proposition more operational, proportionate and internationally intelligible, without implying that every AI system or organisation requires the same form or level of assurance.
1. Defining a clear role for public universities while respecting institutional and academic autonomy
Reference: Annex C – Priority Sectors for Leadership, Section – Education and Human Capital Development, pages 77–81.
The National Strategy appropriately recognises that lifelong AI learning extends to higher education and that academia should contribute to the national talent pipeline. However, the specific role of public universities in the implementation of the education pillar is not clearly defined.
Public universities should be explicitly recognised as key partners in advanced AI education, skills development, research and knowledge transfer.
They should also be actively involved in the design and implementation of national measures affecting higher education, so that these measures benefit from academic expertise, established institutional responsibilities and existing quality-assurance processes.
The Strategy should clarify the mechanisms through which public universities will participate in implementation, including consultation, appropriate representation in relevant governance structures, and access to the funding, data and national AI infrastructure required to support education, research and innovation.
2. Defining education-specific measures of successful AI adoption
Reference: Annex C – Priority Sectors for Leadership, Section – Education and Human Capital Development, pages 77–81.
The Strategy sets a national target for increasing AI adoption across education and labour. However, increased use of AI tools should not, by itself, be treated as evidence of successful educational adoption.
Progress should be assessed through clearly defined education-specific outcomes, including improvements in AI literacy and learning, the ability of learners and educators to use AI critically and responsibly, accessibility and inclusion, and evidence of meaningful educational benefit.
Major national initiatives should be evaluated against these outcomes before wider implementation, so that their effectiveness can be demonstrated and any necessary adjustments can be made.
3. Distinguishing the implementation approach for higher education
Reference: Annex C – Priority Sectors for Leadership, Section – Education and Human Capital Development, pages 77–81.
The Strategy brings together school education, higher education, lifelong learning and workforce development under the education and human-capital pillar. However, its principal measures focus on learners aged 6–18 and on the upskilling of the existing workforce, while the role of higher education in preparing future graduates for an AI-enabled economy is less clearly developed.
The Strategy should explicitly recognise the role of higher education in ensuring that graduates enter the workforce with appropriate AI knowledge and skills.
Depending on their field of study, graduates should be equipped with relevant AI literacy, critical judgement, ethical awareness and the ability to use AI responsibly and effectively in professional contexts.
National initiatives should support universities in developing these capabilities through their established academic and quality-assurance processes. Continuing workforce upskilling should complement, rather than substitute for, the preparation provided through undergraduate and postgraduate education.
4. Ensuring equitable access to suitable generative AI tools in public universities
Reference: Annex C – Priority Sectors for Leadership, Section – Education and Human Capital Development, pages 77–81; Section 3.7 – Infrastructure, Compute and Digital Sovereignty, pages 38–40.
The National Strategy promotes AI literacy, advanced skills development and the responsible adoption of AI across higher education and professional life. Achieving these objectives requires students, academic staff and researchers to have appropriate opportunities to gain practical experience with relevant AI tools, including generative AI and large language models where appropriate.
The cost of institution-wide commercial licences may limit access and result in unequal provision between institutions and departments, as well as unequal access among individual users, particularly students.
A coordinated national approach should therefore be considered through which public universities could obtain licensed access to suitable generative AI tools under collectively negotiated terms.
Such an approach could reduce costs through economies of scale, avoid fragmented procurement and provide more consistent contractual safeguards concerning data protection, security, confidentiality and the use of institutional information.
It should remain technology-neutral, allow access to more than one appropriate tool where necessary, and enable each university to determine how licensed services are used within its teaching, research and administrative activities.
This would help ensure that access to advanced AI capabilities does not depend on the personal financial means of individual students or staff and would support the development of practical AI skills across the public higher-education system.
5. Using AI to strengthen personalised support for students with disabilities and specific learning difficulties
Reference: Annex C – Priority Sectors for Leadership, Section – Education and Human Capital Development, pages 77–81.
The National Strategy identifies personalised learning, accessibility and inclusion as important elements of AI adoption in education. It should also explicitly recognise the potential of AI to provide specialised and personalised support for students with disabilities and specific learning difficulties across primary, secondary and higher education.
Appropriate AI-enabled tools could support the adaptation of learning materials, accessible formats, assistive communication, personalised feedback and learning support tailored to individual needs.
These tools should complement, rather than replace, educators, specialists and existing student-support services, which, due to resource constraints, may rely primarily on group-based provision or may only be able to address basic learning needs.
Used appropriately, AI-enabled tools could extend the reach and responsiveness of existing provision by offering additional, more individualised assistance tailored to each student’s needs.
Appropriate safeguards should also be in place concerning accessibility, data protection, privacy, reliability and professional oversight, particularly where such technologies are used by children or other vulnerable learners.
6. Ensuring the infrastructure and support required for effective AI education in schools
Reference: Annex C – Priority Sectors for Leadership, Section – Education and Human Capital Development, pages 77–81.
The National Strategy proposes the introduction of AI literacy across primary and secondary education through national frameworks and AI-enabled learning tools. However, it does not set out how schools, educators and pupils will obtain the hardware, software and technical support required for effective and equitable implementation.
Given that the Strategy’s principal school-level measures focus on learners aged 6–18, effective implementation will require pupils to have regular access to modern computing equipment within the public-school environment.
The Strategy should recognise this as an important enabling condition, and implementation should include a coordinated plan to strengthen access to suitable devices, licensed software, secure AI tools, digital resources, reliable connectivity and ongoing technical support.
Such provision would enable AI literacy to be developed through practical engagement with AI concepts and, where age-appropriate, with suitable AI tools under educator supervision, alongside theoretical learning.
Without such provision, access to AI-enabled education may vary between schools and may depend on the resources available to individual families, creating unequal opportunities for pupils.
Particular attention should therefore be given to schools and communities with limited resources, so that the implementation of national AI education initiatives does not widen existing inequalities.
Infrastructure provision should also be accompanied by appropriate support and training for educators, enabling available technologies to be used effectively, safely and consistently in teaching and learning.
TechIsland Feedback on the Cyprus National AI Strategy
TechIsland welcomes the development of the Cyprus National AI Strategy and the opportunity to contribute to the public consultation process. The Strategy provides a strong and necessary framework for Cyprus, particularly through its focus on value-driven use cases, measurable outcomes, organisational readiness, common infrastructure, trusted and EU-aligned AI, and the intention to avoid fragmented pilots and “AI theatre”.
The following comments and recommendations reflect feedback gathered from contributors across companies and institutions spanning AI and software, IT services, digital health and diagnostics, enterprise communications, higher education, technology and transformation consulting, AI-enabled recruitment, and diversified sectors including property, hospitality, healthcare and education. The respondent group hold senior roles, including executive or C-suite roles, senior AI and technology leadership roles.
Executive Summary
TechIsland’s feedback is centred on three priorities that can strengthen the Strategy’s ability to translate ambition into measurable impact:
Make transformation ownership explicit by assigning clear authority to change processes, KPIs, responsibilities and organisational structures, and to stop or scale initiatives based on actual value and adoption.
Build a Cyprus AI industry by recognising, supporting and deploying solutions already being developed by Cyprus-based technology companies, AI providers, start-ups, entrepreneurs and research centres.
Compete on trust, compliance and speed by strengthening Cyprus’ position as a trusted, EU-aligned jurisdiction and exploring an EU AI Act sandbox that can provide a fast and safe pathway from product testing to certification.
1. Transformation Ownership and Decision-Making Authority
There is insufficient clarity on who has responsibility and authority when AI-enabled transformation creates conflicts between organisational interests, responsibilities and KPIs.
For example, AI and process redesign may improve the overall performance of a public service while reducing the workload, budget, influence or responsibility of a particular department. A local organisational KPI may therefore conflict with the overall outcome the state is trying to achieve.
The Strategy should make transformation ownership explicit.
It should clarify:
which KPI takes priority when system-level and local KPIs conflict;
who has the authority to change a local KPI when it incentivises preservation of an inefficient process;
who has the authority to redesign or remove an existing process step;
who can redistribute responsibilities between organisations;
escalation and final decision rights where organisations disagree;
who can stop technically successful projects that fail to generate adoption or real value;
who can scale successful solutions even when they negatively affect an existing local KPI or organisational interest.
The issue is therefore not only who owns an AI system, but who owns the transformation and has the authority to change processes, responsibilities, KPIs and organisational structures when required.
2. Cyprus as an AI Technology and Innovation Hub
The Strategy currently places stronger emphasis on Cyprus as an adopter, catalyst or user of AI across citizens, businesses and the public sector than as an AI technology innovator and industry hub.
Greater emphasis should be placed on developing and supporting a Cyprus AI industry.
The Strategy should capitalise on existing:
Cyprus-based technology companies;
AI solution providers;
digital industry leaders;
start-ups;
entrepreneurs;
research centres.
Cyprus does not need to build its AI ecosystem entirely from the beginning. A number of companies and organisations are already developing AI technologies and solutions, including solutions that are successfully used internationally.
It is recommended that Government identifies and becomes more aware of Cyprus-developed AI solutions, explores opportunities to use them within ministries and public services, and supports their promotion locally and internationally.
TechIsland can support this effort by helping to map Cyprus-based companies and organisations already developing AI technologies and solutions, and by facilitating engagement between Government and relevant industry providers.
The objective should be to foster a Cyprus AI industry rather than primarily act as a catalyst for international AI leaders.
3. Cyprus’ Strategic Positioning: Trust, Regulation and Compliance
The Strategy’s positioning of Cyprus as a trusted, EU-aligned jurisdiction is a strong direction.
There is an opportunity to go further by making regulatory agility a core element of Cyprus’ competitive positioning.
Cyprus does not have the scale to compete globally on GPU or computing capacity.
It is therefore recommended that Cyprus explores positioning itself as an EU AI Act sandbox, offering international companies a fast and safe pathway from product testing to certification.
Under this approach, Cyprus’ competitive advantage would be compliance, trust and speed rather than hardware scale.
4. Prioritisation and Scope
The Strategy is highly ambitious in terms of the number of sectors, priorities, programmes and structures it attempts to address simultaneously. There is a risk that the breadth of the roadmap may make successful implementation difficult, particularly given the pace at which AI is developing.
It is recommended that:
priorities are reduced and focused on a smaller number of areas, potentially four or five;
implementation proceeds in clear phases, with a distinction between immediate priorities and initiatives that should follow later;
at least one flagship, citizen-facing or compliance-facing AI system is selected, fully resourced and brought into live production within twelve months in order to demonstrate visible and measurable value in practice.
5. Delivery and Implementation
The Strategy is currently a high-level, non-binding framework. A clearer delivery mechanism is therefore needed to translate its ambition into practical implementation.
It is recommended that the Strategy is complemented by a binding Delivery and Investment Plan, updated annually.
This plan should specify:
what will be implemented first and what will follow in later phases;
the expected cost of each major initiative;
the sources of funding;
responsibility and accountability for delivery;
key milestones;
workforce impacts;
measurable outcomes;
arrangements for independent evaluation.
The proposed actions should also be more specific, practical and accompanied by clear budgets.
6. Financing and Funding
There is an absence of a clearly defined financing envelope.
The Strategy sets out ambition, governance structures and KPIs, but does not provide a costed capital plan, named funding sources or clear phasing of expenditure.
It is recommended that a multi-year, phased financing envelope is published alongside the Strategy, identifying national funding and relevant EU co-financing sources, including Digital Europe, Horizon Europe and EuroHPC.
Funding should also be directed towards existing Cyprus-based AI companies, entrepreneurs, start-ups and technology organisations already developing and deploying AI solutions. This would help retain capability in Cyprus, keep more data and technical know-how within the jurisdiction, enable shorter iteration cycles with local providers, and recirculate a greater share of AI-related investment within the domestic economy.
National AI funding, compute infrastructure, data facilities, sandboxes, skills programmes and commercialisation support should be accessible to all accredited Cyprus higher education and research institutions on transparent, competitive and outcome-based terms, irrespective of whether they are public or private. Access to national AI capabilities should be based on quality, relevance and expected impact rather than institutional status.
7. Research and Industry
The Strategy places significant emphasis on universities, research centres and the development of Centres of Excellence. This is important, but the framework should more explicitly connect research capability with commercial, operational and public-sector deployment.
The objective should be to create stronger pathways through which research, talent, infrastructure and industry capability translate into tested, scalable solutions and measurable outcomes.
Universities, research centres and industry bring complementary capabilities. Universities contribute research, talent development, specialised infrastructure, validation environments and knowledge creation, while industry contributes productisation, integration, operational deployment and scaling. The Strategy should strengthen mechanisms that bring these capabilities together around real-world deployment and measurable outcomes.
Universities should also be recognised as important real-world deployment and validation environments for AI, including in education, healthcare, administration and professional services. This would allow solutions to be tested with real users and operational processes before wider deployment, while generating evidence on adoption, effectiveness and scalability.
8. Public-Private Partnerships and Procurement
There is insufficient emphasis on Public-Private Partnerships.
Implementation of the Strategy cannot rely on the government alone.
Public-Private Partnerships should be explicitly incorporated into the implementation model, particularly in areas where industry expertise, market agility and operational experience are required.
Furthermore, Public-Private Partnerships should not be limited to consultation or advisory input. They should be designed as practical delivery mechanisms through which government can work with technology companies, AI providers, start-ups, integrators and established enterprises to identify existing solutions, adapt them for public-sector needs, and deploy them at speed. This is particularly important because many of the AI capabilities that can improve public services are already being developed and tested in industry rather than in purely academic settings.
For this delivery model to work in practice, public procurement rules and tender design should also enable qualified local and emerging providers to compete on fair terms.
Tender thresholds, framework agreements, reference-customer requirements, liability terms and payment schedules should be reviewed so that they do not unintentionally favour only large incumbent integrators or create excessive vendor dependence. Procurement should support competition, interoperability and the ability to pilot and scale solutions from a wider pool of providers.
9. Governance Structure
The proposed governance structure appears overly complex.
The Strategy includes the National AI Authority, the Interministerial AI Council, specialised or oversight committees, Centres of Excellence, as well as AI Officers and AI Champions within ministries.
For a country of Cyprus’ scale and with an already limited AI talent pool, there is a risk that the governance structure itself will consume scarce resources needed for implementation.
The governance structure should include a clearer and stronger industry-facing component. While the proposed model includes several public-sector, academic and coordination bodies, it is not sufficiently clear who is responsible for representing the needs of industry or ensuring that implementation decisions reflect real-world adoption challenges. The AI Task Force and related steering structures should therefore include stronger representation from technology companies, AI providers, start-ups, SMEs and large enterprises, so that national priorities are informed by both research expertise and practical deployment experience.
In summary, it is recommended that:
the governance structure is simplified and consolidated;
the AI steering structure is small and composed primarily of experts and stakeholders directly involved in AI;
consideration is given to a single empowered delivery unit with its own budget and clear accountability;
the distinction and responsibilities between roles such as AI Officer, AI Champion and/or AI Ambassador are clearly defined.
10. Measuring Actual Transformation and Value
The success of AI projects should not be measured solely by whether a system, portal or pilot has been successfully launched.
A technically successful implementation may still create little value if citizens continue using existing channels and employees continue relying on old systems, spreadsheets and manual processes.
Measures of success should therefore include:
whether users moved from old channels to new ones;
whether the service became faster;
whether manual work decreased;
whether unnecessary process steps decreased;
whether the cost of delivering the service decreased;
whether the end-user experience improved.
The success of the National AI Strategy should therefore be measured by whether AI changes underlying processes and improves system-level outcomes.
11. Organisational Change and AI Adoption Across the Economy
The Strategy discusses workforce augmentation, agentic AI and AI Officers, but provides limited detail on how organisations should redesign workflows, team structures and decision-making processes around AI agents.
The role envisaged for AI Officers in government, bridging existing business needs and new technology, is also relevant to the wider economy.
The Industrial Centre of Excellence and Change Management components should therefore have a more central role in a national strategy intended to cover the whole economy.
Cyprus’ economy relies heavily on SMEs. Reskilling and empowering professionals already working within existing businesses to embrace innovation and develop value-oriented AI use cases from within their organisations should be treated as a high priority.
Adding new AI talent is not sufficient unless the transition between new AI capabilities and existing people, processes and technical infrastructure is also addressed.
This requires sustainable transformational change management.
12. SME Access to AI Support
The Strategy sets out support mechanisms for SMEs, including the AI Sovereign Investment Matching Fund and the AdoptNAICF programme.
There is insufficient clarity on how companies will practically access these mechanisms.
It is recommended that a “single digital front door” is established, with clear service-level commitments for decision-making.
The process for accessing support should be simple and frictionless, particularly where AI adoption can demonstrably improve productivity or reduce costs.
13. Practical Upskilling and AI Literacy
The FutureAI CY programme and its proposed stackable micro-credentials are important for long-term education and skills development.
However, there is also a need for practical and immediately applicable AI skills.
It is recommended that the programme is supplemented by short, practical bootcamps focused on how existing employees can use currently available AI tools in their daily work to reduce costs and accelerate processes.
14. AI Access for Students and Citizens
There is a need to create more opportunities for students and citizens to use AI directly.
Practical access can help improve adoption, understanding and familiarity with AI.
Examples from Malta and the UAE demonstrate approaches that could be considered.
It is recommended that Cyprus considers:
providing students with access to AI tools;
considering free access to AI tools for students and potentially the wider public;
organising hackathons, awareness activities and practical programmes covering areas such as AI for cybersecurity, design and advertising;
creating programmes and events aimed separately at students and employees.
Public discussion around AI is often dominated by concerns that it is a bubble, a scam, will take jobs or replace humans.
Giving people practical opportunities to use AI can help them understand how it can be useful in everyday life and reduce the perception that the technology is inaccessible or overwhelming.
15. Talent and International Partnerships
In addition to developing the domestic AI talent pool, Cyprus should continue to attract experienced international AI professionals and specialised teams.
Cyprus universities should also be used as a pathway for attracting and retaining international AI talent, including through streamlined arrangements for specialist researchers and clear post-study pathways for graduates in high-demand AI and technology fields.
The possibility of establishing government-backed Global Capability Centres (GCCs) should also be explored as a mechanism for bringing high-value AI expertise and capabilities to Cyprus.
16. Sovereign AI, Compute, and Data
The principle of “partner for scale, sovereign where it counts” is appropriate, but the Strategy would benefit from stating explicitly where each half of that principle applies.
It is recommended that the distinction is drawn by technology layer. Cyprus should buy at the infrastructure layer, where compute, foundation models and silicon are already commoditised and where national investment competes against capital Cyprus does not have, and build at the application, assurance and data layers, where domestic capability is achievable and where the Cyprus AI industry described in Section 2 already operates.
Ambitions around sovereign models, sovereign compute and RISC-V risk spreading limited capital and talent across layers where the return does not justify the expenditure. Computing capacity should instead be accessed through EuroHPC and hyperscaler partnerships, with sovereign investment concentrated on assurance, deployment and trust.
Data is the layer where sovereignty genuinely applies, and it receives insufficient attention in the Strategy relative to compute and infrastructure. Secure and interoperable data is named as a national objective, but is treated largely as infrastructure to be built rather than as the precondition on which every proposed use case depends.
Public sector data in Cyprus is distributed across ministries in systems that were not designed to interoperate, with uneven quality, incomplete documentation and no consistent access regime. Every flagship initiative contemplated in Section 4 depends on that data being available and usable. National AI programmes fail more often on data availability and quality than on model access, computing capacity or governance design.
It is recommended that:
a public sector data inventory is compiled, identifying which datasets exist, who owns them, their quality and their current accessibility;
interoperability requirements apply by default to new public sector systems;
a defined access regime is established for accredited public and private users, with published timelines for access decisions;
named accountability is assigned for the quality and maintenance of each significant dataset;
data readiness is treated as a selection criterion for the twelve-month flagship proposed in Section 4, so that the initiative chosen is one where the underlying data already exists.
accredited universities and research institutions have clear, governed and timely pathways to access appropriate national datasets for legitimate research, validation and innovation purposes;
Sovereignty over data, and the capability to use it, will matter more to Cyprus over the period to 2032 than sovereignty over silicon.
17. Energy Consumption
Energy consumption represents a major issue and opportunity that is not sufficiently addressed in the Strategy.
Greater attention should be given to the relationship between AI adoption, computing infrastructure and energy consumption.
18. Stakeholder-specific Implementation
The Strategy would benefit from a clearer segmentation of its proposed actions by stakeholder group. At present, several measures appear to apply across the economy, but it is not always clear which initiatives are intended primarily for start-ups, scale-ups, established technology companies, large enterprises, SMEs, the public sector, research institutions, students or citizens. A practical implementation matrix should be added, showing for each stakeholder group what support, obligations, funding routes, infrastructure access, skills programmes and regulatory measures are relevant to them. This would make the Strategy easier to implement, easier to communicate, and easier for each group to understand how it can participate.
Conclusion
The Cyprus National AI Strategy 2032 provides an important and necessary foundation for the country.
Its success will depend primarily on execution: maintaining focus, translating the Strategy into concrete actions, ensuring sufficient funding, involving existing industry capabilities, establishing clear accountability, and demonstrating practical and measurable results throughout the implementation period.
ΔΗΜΟΣΙΑ ΔΙΑΒΟΥΛΕΥΣΗ — ΕΘΝΙΚΗ ΣΤΡΑΤΗΓΙΚΗ ΓΙΑ ΤΗΝ ΤΕΧΝΗΤΗ ΝΟΗΜΟΣΥΝΗ (ΤΝ) 2032
Public Consultation Submission — Republic of Cyprus National AI Strategy 2032
To: Υφυπουργείο Έρευνας, Καινοτομίας και Ψηφιακής Πολιτικής, μέσω της πλατφόρμας «η-Διαβούλευση»
Subject: Σχόλια επί του προσχεδίου της Εθνικής Στρατηγικής για την ΤΝ — Πρόταση ενίσχυσης της θεσμικής αρχιτεκτονικής υλοποίησης (National AI Authority)
Date: 31 Αυγούστου 2026
1. Executive Position
We welcome the draft National AI Strategy 2032 and, in particular, its recognition in Section 3.3 that a National AI Authority, an Interministerial AI Council and a supporting network of specialised committees are required to coordinate AI governance and adoption across the Republic. This submission does not propose an alternative institutional model. It proposes that the Strategy’s existing National AI Authority concept be strengthened, before final adoption, along the lines set out below, so that the Authority is unambiguously independent, cross-sectoral in mandate, and equipped with genuine implementation powers granted by the Council of Ministers — rather than a purely advisory or coordinating unit.
The central argument is straightforward: artificial intelligence is not a conventional single-sector policy domain. It is a general-purpose, cross-cutting capability that simultaneously reshapes public administration, financial services, healthcare, justice, education, tourism, shipping, and the wider investment and business environment — precisely the eight Priority Sectors the Strategy itself identifies (Section 3.5). A policy area with this horizontal reach across government layers and the economy cannot be implemented effectively through the ordinary machinery of a single ministry acting alone. It requires a dedicated, independent institution with a whole-of-government and whole-of-economy mandate, operating in close coordination with the Deputy Ministry of Research, Innovation and Digital Policy, the Commissioner of Electronic Communications, the Commissioner for Personal Data Protection, sector regulators, the European Artificial Intelligence Board, and other EU and international bodies active in this field.
2. Comments by Section
Article / Section No. Comment / Suggestion Rationale
Section3.3.1.1 (“National AI Authority”) See 2.5.7 (Target 7) The Strategy correctly proposes designating a National AI Authority “with a clear political mandate”, appointed by the President and ratified by the Council of Ministers. We recommend the final text state explicitly that the Authority be established as an independent legal entity with defined operational and budgetary autonomy — not merely a coordination function nested inside an existing ministry. The founding instrument should specify: (a) legal personality; (b) an explicit Council of Ministers implementation mandate covering AI adoption and governance across both the public sector and the private sector; (c) multi-annual budget and staffing guarantees; and (d) a transparent, merit-based appointment process for its Chief Executive/Commissioner. AI is not a single-sector policy area; it is a horizontal capability cutting across public administration, financial services, healthcare, education, justice, tourism and shipping, as the Strategy’s own eight Priority Sectors (Section 3.5) demonstrate. A body without legal personality and secured funding risks becoming, in practice, a subordinate coordination unit unable to give binding direction to sector regulators or to attract technical staff at competitive terms. Comparative practice — Spain’s AESIA, Malta’s MDIA, and Ireland’s planned AI Office of Ireland — shows that credible national AI institutions combine legal independence with a dual mandate spanning trust/compliance and adoption/innovation. Anchoring this in the Strategy itself, rather than leaving it to secondary legislation, reduces the risk that implementation stalls at the design stage and signals credibility to ministries, businesses and investors alike.
Section3.3.1.1, part “The Authority does not assume operational control … nor does it replace ministerial authority” We recommend sharpening this language so the Authority’s role is not read as purely advisory. Ministries should retain day-to-day accountability for their own AI deployments (consistent with Section 3.4.3), but the Authority should hold an explicit Council of Ministers implementation mandate to: (i) issue binding minimum standards for high-risk public-sector AI systems; (ii) require ministries to align their Applied AI Strategies (Section 3.4) with common national templates within a defined timeframe; and (iii) escalate sustained non-compliance to the Interministerial AI Council and, where unresolved, directly to the Council of Ministers. A body limited to “guidance” and “coordination” without any escalation path risks exactly the “AI theatre” the Strategy itself warns against in Section 1.4 — many pilots, little systemic impact. Because AI adoption touches multiple layers of governance at once (data policy, procurement, cybersecurity, sector regulation), an authority with only soft-coordination powers will struggle to align ministries operating on different timelines and risk appetites. A defined, Council-of-Ministers-backed implementation mandate — while preserving ministerial operational accountability — gives the Authority the institutional weight needed to drive genuinely national, rather than fragmented, adoption.
Section3.3.1.1 σε συνδυασμό με Appendix Α (EU AI Act designations) We recommend an explicit clause clarifying the division of labour between the new National AI Authority and the bodies already designated under the EU AI Act — the Deputy Ministry of Research, Innovation and Digital Policy (overall AI Act coordination and Cyprus’s seat on the European AI Board) and the Commissioner of Electronic Communications (Notifying Authority, Market Surveillance Authority, Single Point of Contact). A formal cooperation protocol should be published alongside the Authority’s founding legal instrument, confirming that the Authority provides technical capacity, Article 57 regulatory-sandbox coordination, and cross-sector adoption support, while statutory AI Act enforcement powers remain with the already-designated competent authorities. Without a clear non-duplication clause, Cyprus risks creating two centres of gravity for AI policy — the Authority and the AI Act competent authorities — recreating the very fragmentation risk the Strategy’s governance chapter (Section 3.3) is designed to solve. Ireland’s planned AI Office and Malta’s MDIA both show that a single national implementation body can coordinate distributed statutory functions without duplicating them, provided the legal instrument defines this relationship explicitly rather than leaving it to informal practice that may not survive changes in political leadership.
Section3.3.1.1 (institutional independence) & 3.4.3 (Human Oversight and Accountability) We recommend an explicit conflict-of-interest safeguard: because the state will simultaneously be a major deployer of AI (through the “Government and Public Sector” priority use cases in Section 3.5) and, through the Authority, the source of guidance and standards for that same deployment, the Authority’s assurance and testing functions should be organisationally separated internally from its adoption-acceleration functions, with published conflict-of-interest rules for board members and senior staff. Institutional neutrality is essential for public trust, particularly for AI used in sensitive domains such as health, justice, welfare and policing, which the Strategy itself prioritises. If the same unit that helps a ministry deploy an AI system is also responsible for assuring its safety, the credibility of that assurance is undermined. Separating these functions internally — while keeping them under one Authority for efficiency — preserves coherence while safeguarding the impartiality Cyprus needs to be recognised as a “trusted jurisdiction” under Objective 1 (Section 2.5.1).
Section3.5 (Priority Sectors) and also Chapter 3 (cross-cutting nature of AI) We recommend the governance chapter state explicitly that AI’s cross-sectoral character is itself the institutional justification for a single, sufficiently senior Authority, rather than sector-by-sector coordination alone. The Authority’s founding mandate should include a statutory duty to publish an annual, cross-sector “State of AI Adoption and Governance” report to the Council of Ministers and the House of Representatives, consolidating inputs from all eight Priority Sectors, so that cross-cutting risks and opportunities in data infrastructure, skills and trust are visible nationally rather than siloed within each sector’s own review cycle. The Strategy’s own priority-sector analysis — financial services, healthcare, tourism, legal services, education, shipping, entrepreneurship and government — shows that the same underlying enablers (data governance in Section 3.2, compute infrastructure in Section 3.7, skills in Section 3.6, and trust in Section 3.9) recur across every sector. Without one body with visibility across all of them, ministries and regulators risk duplicating investment (already flagged as a risk for compute in Section 3.7) or developing inconsistent standards for the same underlying AI capability. A cross-sector reporting duty operationalises the whole-of-system approach the Strategy already commits to in Section 3.
Section1.5 (Implementation Timeline: “0–8 months: Governance activation, authority establishment”) Given the Strategy’s own 0–8 month target for “authority establishment,” we recommend the Council of Ministers fast-track the drafting and adoption of the founding legal instrument for the National AI Authority in parallel with, rather than after, finalisation of the Strategy text, so that the institutional vehicle exists before the first wave of ministry Applied AI Strategies and flagship “moonshot” programmes (Section 3.5) is due to launch. Comparable jurisdictions show that the institutional design phase is frequently the longest-running item on the critical path (e.g., Ireland’s AI Office was announced well before its planned August 2026 operational date). If Cyprus sequences legal establishment after strategy adoption rather than alongside it, the Authority may not be operational when ministries are expected to begin implementation, undermining the Strategy’s own timeline and creating exactly the execution gap identified in Section 1.4 (“limited applied AI experience within ministries … risk of AI theatre”).
3. Reasoning of the appraisal and the suggestion: Why AI requires an Independent Implementation Authority?
Beyond the specific drafting comments above, we set out the broader institutional rationale for the Council of Ministers’ consideration:
3.1 AI is a horizontal, not a vertical, policy domain
Unlike sector-specific technologies, AI simultaneously affects data governance, cybersecurity, procurement, competition, labour markets, fundamental rights, financial supervision, healthcare regulation, judicial administration and education policy — often within a single use case. The Strategy’s own structure, built around eight Priority Sectors sharing common enablers (data, compute, skills, trust — Sections 3.2, 3.6, 3.7, 3.9), is itself evidence that no single sectoral ministry can own AI implementation end-to-end. A cross-cutting problem requires a cross-cutting institution with the standing to convene, and where necessary direct, action across ministries that would not otherwise coordinate.
3.2 Independence protects both innovation and public trust
The state will simultaneously be one of the largest deployers of AI in Cyprus (through the Government and Public Sector priority use cases) and the entity responsible for setting the rules that govern that deployment. Only a body with genuine operational and budgetary independence — rather than a unit embedded within a single ministry’s hierarchy — can provide guidance and assurance that is, and is seen to be, impartial. This is particularly important for AI used in health, justice, welfare, migration and policing, where citizens must be able to trust that oversight is not simply the ministry marking its own homework.
3.3 A Council of Ministers mandate gives the Authority the authority to act
A body created by administrative circular or informal designation can be diluted or bypassed the moment a competing ministerial priority emerges. A mandate formally granted and periodically reaffirmed by the Council of Ministers — covering both public-sector and private-sector implementation — gives the institution the political weight to require ministries to align their Applied AI Strategies (Section 3.4), to coordinate the national AI regulatory sandbox under Article 57 of the EU AI Act, and to represent Cyprus credibly in EU and international AI governance forums, including the European Artificial Intelligence Board, the Global Partnership on AI, and relevant OECD, WHO and ITU processes referenced in Section 3.8 of the Strategy.
3.4 Cross-sector economic and investment stakes require a single point of institutional accountability
The Strategy sets ambitious national targets — up to 15% productivity improvement, 12% GDP expansion, and over 3,000 new AI professionals by 2032 (Section 2.5.2, Section 2.5.5). These targets span government, financial services, healthcare, tourism, legal services, education, shipping and the startup ecosystem simultaneously. Investors, SMEs and international partners need one credible institutional counterpart for AI policy in Cyprus — not eight separate sectoral conversations. A single, independent, adequately resourced Authority, operating under a clear Council of Ministers mandate and in structured cooperation with the Deputy Ministry, the Commissioner of Electronic Communications, EU institutions and international bodies such as the OECD and GPAI, is the institutional design most likely to deliver on the Strategy’s own ambition.
4. Conclusion
We support the Strategy’s direction and its recognition, in Section 3.3, that a National AI Authority is required. We urge that, in the final version submitted to the Council of Ministers, the Authority’s independence, legal personality, cross-sectoral and dual (public/private) mandate, non-duplication protocol with existing EU AI Act competent authorities, and internal separation between assurance and adoption functions be stated explicitly rather than left to future secondary legislation. This would ensure Cyprus moves, in practice and not only on paper, from a strategy document to an operational, trusted and internationally credible AI implementation capability by the Strategy’s own 2032 horizon.
Dr. G. Kentas,
Associate Professor of Politics and Governance,
Director of the Master Program of Public Administration
at the University of Nicosia
The Water Development Department welcomes the proposed Cyprus National Artificial Intelligence Strategy and supports its objective of establishing a coordinated, secure, human-centred, and outcomes-driven framework for the adoption of artificial intelligence across government and the wider economy.
We particularly welcome the Strategy’s emphasis on trustworthy AI, human oversight, data governance, interoperability, shared national infrastructure, cybersecurity, public-sector capability development, and measurable public value. We also support the recognition of Energy, Environment and Resource Management, including water management, as a national priority for AI research and innovation. The Strategy specifically identifies water-scarcity monitoring, precision irrigation, and water-use optimisation as relevant areas for development.
Given Cyprus’s exposure to water scarcity, drought, climate variability, energy-intensive water production, and increasing pressure on water infrastructure, we recommend that Water Resources Management be identified more explicitly as a strategic national AI application area. The Water Development Department should be included as a key stakeholder in the relevant governance, research, data, infrastructure, and implementation workstreams.
1. Priority AI Applications for Water Management
AI can provide significant public value by improving forecasting, monitoring, operational planning, infrastructure management, and evidence-based decision-making. The following use cases should be considered for inclusion in the Department’s initial Applied AI portfolio:
1. Water-demand forecasting: Combining historical consumption, weather, seasonal activity, population, and other relevant data to support operational and infrastructure planning.
2. Reservoir inflow and drought forecasting: Using hydrological, meteorological, catchment, and historical data to improve storage projections and provide early warning of water-scarcity conditions.
3. Leakage and network-anomaly detection: Analysing flow, pressure, smart-meter, and telemetry data to identify abnormal network behaviour and support the prioritisation of inspections.
4. Predictive maintenance: Using sensor data, operating hours, fault histories, and maintenance records to estimate failure risk for pumps, treatment facilities, pipelines, telemetry systems, and other critical assets.
5. Energy optimisation: Supporting the efficient scheduling of water production, treatment, pumping, and distribution while considering demand, storage, electricity costs, infrastructure constraints, and service-continuity requirements.
6. Water-quality monitoring: Detecting unusual patterns in sensor or laboratory data, subject to verification by qualified personnel and established regulatory procedures.
7. Geospatial and remote-sensing analytics: Supporting catchment monitoring, infrastructure inspection, environmental assessment, and analysis of changes affecting water resources.
8. Secure departmental knowledge services: Improving access to legislation, technical manuals, policies, contracts, correspondence, and institutional knowledge through shared government document-intelligence and knowledge-search capabilities.
AI should initially operate primarily in a monitoring, forecasting, or advisory capacity. Decisions involving water allocation, public health, critical infrastructure, or continuity of essential services must remain subject to authorised human oversight.
2. Data, Infrastructure and Interoperability
The effective application of AI in water management depends on reliable and interoperable data from telemetry systems, GIS platforms, reservoirs, hydrological monitoring, water-quality systems, laboratories, smart meters, maintenance systems, asset registers, remote-sensing platforms, and administrative applications.
We support the Strategy’s proposed federated national data architecture, secure API-based exchange, common standards, and treatment of data as a strategic national asset.
The proposed National AI Infrastructure should provide secure experimentation, testing, validation, and production environments, including protected services for sensitive public-sector data. Shared services should include model and dataset registries, secure integration gateways, monitoring and logging, document intelligence, multilingual assistance, and government knowledge-search capabilities.
Architecture and procurement frameworks should also require data portability, open and documented interfaces, transparent licensing, clear intellectual-property arrangements, exit provisions, and protection against unauthorised reuse of government data for external model training.
3. Cybersecurity and Critical Infrastructure
AI used in connection with operational technology, telemetry, industrial control systems, or critical water infrastructure must be distinguished from general administrative AI and subjected to enhanced safeguards.
Minimum requirements should include:
• separation and segmentation of IT and operational-technology (ΟΤ) environments;
• least-privilege access and controlled integration interfaces;
• independent security and technical validation;
• tested manual overrides and fail-safe operating procedures;
• business-continuity and disaster-recovery arrangements;
• model, software, and supply-chain assurance;
• comprehensive logging and continuous monitoring;
• secure update and change-management procedures;
• incident reporting and response; and
• periodic security assessment and penetration testing.
AI should not be permitted to exercise direct autonomous control over water production, treatment, pumping, or distribution systems unless the use case has passed formal risk, safety, security, and operational-readiness assessments and has been expressly approved by the competent authorities.
A common public-sector AI cybersecurity baseline should address AI-specific threats, including data poisoning, prompt injection, model manipulation, insecure agents and connectors, compromised updates, information leakage, excessive permissions, and dependency on external providers.
4. Principal Recommendations
The Water Development Department recommends that the final Strategy and implementation roadmap:
1. explicitly recognise water-resource management as a strategic national AI application area;
2. include the Water Development Department in relevant national AI workstreams;
3. establish common data-governance, interoperability, API, and data-quality standards;
4. provide secure shared AI infrastructure and reusable government services;
5. issue enhanced safeguards for AI connected to critical infrastructure and operational technology;
6. publish a common public-sector AI cybersecurity baseline;
7. provide specialised training and implementation support to public-sector personnel; and
8. fund data preparation, integration, security, testing, monitoring, and organisational change, not only the acquisition of AI software.
5. Conclusion
The Water Development Department supports the overall direction of the Cyprus National Artificial Intelligence Strategy. AI can strengthen the sustainable and resilient management of Cyprus’s water resources through better forecasting, early warning, leakage detection, predictive maintenance, water-quality monitoring, energy optimisation, and decision support.
Successful implementation will depend on trusted data, secure and interoperable infrastructure, clear accountability, appropriate human oversight, specialist skills, sustainable funding, and enhanced protection for critical infrastructure. The Water Development Department is well positioned to contribute its operational expertise, technical knowledge, sectoral data, and practical use cases to the implementation of the National AI Strategy.
SUBMISSION TO THE PUBLIC CONSULTATION ON THE NATIONAL ARTIFICIAL INTELLIGENCE STRATEGY 2032 OF THE REPUBLIC OF CYPRUS
Submitted by: Cyprus Space Exploration Organisation (CSEO)
Date: 31 August 2026
Subject: Strategic Alignment, Structural Feedback, and Institutional Implementation Pathways
1. INTRODUCTION AND GENERAL STATEMENT OF SUPPORT
The Cyprus Space Exploration Organisation (CSEO) commends the Deputy Ministry of Research, Innovation and Digital Policy, the Chief Scientist for Research, Innovation and Technology, and the National AI Taskforce on the formulation and publication of the Cyprus National AI Strategy 2032: A Strategic Blueprint.
The Strategy articulates a coherent, forward-looking roadmap for the Republic of Cyprus. CSEO strongly endorses its foundational pillars: its human-centred design, its disciplined focus on strategic differentiation rather than unconstrained scale, its commitment to digital sovereignty through trusted international partnerships, and its focus on translating frontier research into measurable societal and economic impact.
From an aerospace, mission-critical, and international governance perspective, Artificial Intelligence represents a transformative, dual-use general-purpose technology with profound societal, economic, and geopolitical implications. Historically analogous to the governance imperatives surrounding nuclear capabilities, advanced AI presents a defining duality: immense potential for human augmentation and economic productivity on the one hand, and systemic, existential risks to security, privacy, and social stability if left unregulated on the other.
As an International Space Innovation Centre and a globally recognized Centre of Excellence selected by the Committee on Space Research (COSPAR) to act as a multi-continental bridge for space innovation, CSEO operates as a trusted, neutral interlocutor across the international scientific landscape. Through institutional leadership within COSPAR and its Panel on Innovative Solutions (PoIS), the NASA Artemis Accords, the Global Expert Group on Sustainable Lunar Activities (GEGSLA), and the Mars Upper Atmosphere Network (MUAN), CSEO actively positions Cyprus at the core of multilateral technological cooperation. Domestically, through the Cyprus Space Research and Innovation Centre (C-SpaRC), the organisation develops mission-critical, AI-driven applications, including space weather predictive modelling, downstream satellite data analytics, and autonomous systems.
CSEO submits the following feedback to reinforce the Strategy’s implementation, strengthen its governance architecture, and present concrete operational pathways through which our ecosystem will actively support the realization of the national vision under the Quadruple Helix framework (Government, Academia, Industry, and Society).
2. STRATEGIC OBSERVATIONS AND STRUCTURAL CONTRIBUTIONS
POINT 1: STRATEGIC TECH DIPLOMACY AND HIGH-LEVEL EU AI LEADERSHIP
Strategy Reference: Section 1.1 (The Vision), Section 2.5.8 (Objective 8: Develop Sovereign Capability through Partnerships), Section 3.12 (International Cooperation and EU Alignment).
Observation and Recommendation:
The Strategy correctly identifies Cyprus’s potential to serve as an EU-to-regional bridge. To elevate this geographic advantage into an active geopolitical capability, Cyprus should establish a proactive Tech Diplomacy doctrine. Furthermore, the Republic of Cyprus should advocate at the European level for the creation of a High-Tier EU AI Standardization and Regulatory Committee, positioning Cyprus and its technocratic leadership (such as the Chief Scientist) in a prominent role in shaping EU-wide regulatory and technical standards. Additionally, the Republic should establish strategic bilateral government-to-government dialogues with leading EU Member States that host major global AI enterprises (such as Ireland) to exchange regulatory sandbox models, compliance architectures, and high-tech investment attraction strategies.
Operational Alignment and Ecosystem Contribution:
Leveraging its standing as a COSPAR-designated global Centre of Excellence bridging the US, Europe, and Asia, CSEO will facilitate high-level multilateral technical exchanges, supporting the Republic’s international standing as a trusted technological broker.
POINT 2: MISSION-CRITICAL STANDARD-SETTING: SPACE WEATHER (SWx) AI FOR AVIATION AND ASTRONAUTICS
Strategy Reference: Section 3.7 (Infrastructure, Compute and Digital Sovereignty), Section 3.8.1 and Annex D (Focus Area 4: Security, Defence and Space), Annex C (Shipping, Maritime and Critical Infrastructures).
Observation and Recommendation:
Advanced predictive AI is indispensable for safeguarding critical national and global infrastructure against severe solar events and geomagnetic disruptions, which directly threaten high-altitude civil aviation, satellite constellations, maritime communications, GNSS/GPS navigation, and terrestrial power distribution. AI-driven Space Weather (SWx) predictive modelling is a national strategic niche where Cyprus can establish European and global technical standards.
Operational Alignment and Ecosystem Contribution:
Through C-SpaRC and in cooperation with global space industry leaders, including members of the COSPAR Committee on Industry Relations (CIR), CSEO is actively advancing high-accuracy AI predictive models for Space Weather. CSEO will work to integrate these capabilities into European resilience frameworks, positioning Cyprus as an international reference node for aviation and astronautics protection.
POINT 3: ETHICAL GOVERNANCE AND DUAL-USE RISK MANAGEMENT (“THE NUCLEAR ANALOGY”)
Strategy Reference: Section 1.1 (Fundamental Principles), Section 2.5.7 (Objective 7: Embed strong governance, ethics and accountability), Section 3.9 (Ethics, Trust and Responsible AI).
Observation and Recommendation:
The Strategy’s rigorous alignment with the EU AI Act and human-centric governance should be highlighted as a vital protective framework for citizens, public institutions, and national resilience, rather than an administrative burden. Because advanced AI models possess dual-use characteristics with systemic risks analogous to nuclear technology, strict regulatory guardrails, continuous assurance, and human-in-the-loop oversight are fundamental prerequisites for sustainable societal adoption.
Operational Alignment and Ecosystem Contribution:
Drawing on its international experience as an honest broker within multilateral governance frameworks (such as the Artemis Accords and GEGSLA), CSEO will support the National Ethics and Values Committee and the National AI Misinformation and Security Council, providing specialized expertise on dual-use risk assessment and international compliance alignment.
POINT 4: PROTECTING CITIZEN RIGHTS: PRIVACY, BIOMETRICS AND DIGITAL IDENTITY IN PERPETUITY
Strategy Reference: Section 3.1.2 (Trust and Transparency), Section 3.9.6 (AI Social Contract Principles), Annex C (Legal Services).
Observation and Recommendation:
In response to public and industry concerns surrounding synthetic media, voice synthesis, and digital cloning, the Strategy should state that national policy guarantees the protection of personal data, biometric likeness, voice, and artistic creation in perpetuity. The legal and regulatory framework must prevent unauthorized commercial exploitation, synthetic imitation, or perpetual digital replication (such as digital avatars) of individuals, actors, and creators without verifiable, revocable, and legally audited consent.
Operational Alignment and Ecosystem Contribution:
CSEO will collaborate with competent authorities to support the technical validation of cryptographic provenance, content integrity, and digital rights protection architectures across research and innovation testbeds.
POINT 5: WORKFORCE TRANSFORMATION, HIGH-SKILL JOB CREATION AND THE QUADRUPLE HELIX
Strategy Reference: Section 2.5.2 (National Productivity and Employment Effects), Section 2.5.5 (Objective 5: Develop, attract and retain AI-related skills and talent), Section 3.6 (Talent, Skills and Workforce Transformation), Annex C (Education and Human Capital Development).
Observation and Recommendation:
Demonstrating that the National Strategy acts as an engine for high-value job creation is essential for maintaining broad public and institutional confidence. The target of developing 3,000+ certified AI professionals by 2032 should be operationalized through an active Quadruple Helix model, linking academia and specialized research facilities directly to high-skill industrial employment and domestic talent retention (brain gain).
Operational Alignment and Ecosystem Contribution:
CSEO and C-SpaRC will support the FutureAI CY programme by hosting postgraduate fellowships, master’s and doctoral research tracks, and specialized training modules in machine learning for physical sciences, satellite data engineering, and autonomous systems.
POINT 6: DOWNSTREAM SPACE DATA INTEGRATION AND ENERGY-EFFICIENT COMPUTING
Strategy Reference: Section 3.2 (Data as a Strategic National Asset), Section 3.7 (Infrastructure, Compute and Digital Sovereignty), Section 3.10 (Sustainability and Green AI).
Observation and Recommendation:
The National Data Architecture should explicitly incorporate downstream Earth Observation (such as Copernicus and Sentinel) and maritime tracking data spaces, enabling AI-driven early detection of wildfires, flood monitoring, precision agriculture, and maritime surveillance. To ensure digital infrastructure development remains environmentally sustainable, the Strategy should balance sovereign infrastructure with access to European Supercomputing (EuroHPC and Pharos-CY) for large-scale training, while prioritizing energy-efficient Onboard Edge AI that processes data directly on satellite payloads and low-power edge nodes.
Operational Alignment and Ecosystem Contribution:
CSEO will contribute its expertise in low-power Edge AI payload design (developed for CubeSat platforms such as C-SpaRC-1) and downstream satellite data processing to support public-sector environmental and maritime use cases without overburdening the national energy grid.
3. CONCLUSION
The Cyprus National AI Strategy 2032 establishes a balanced and authoritative roadmap that positions Cyprus as a trusted, highly competitive European jurisdiction.
CSEO reaffirms its commitment to supporting the Deputy Ministry of Research, Innovation and Digital Policy, the Chief Scientist, and the National AI Taskforce in translating these strategic priorities into durable national capabilities and international leadership.
1. Overall quality and standard for future strategies:
This is a comprehensive, well-structured and implementation-oriented strategy. Particularly positive is its focus on measurable national outcomes — including productivity, economic impact and AI workforce development —supported by defined governance, accountability and delivery mechanisms. This approach should serve as a benchmark for the development of future national strategy documents by the Government of Cyprus.
2. Immediate commencement of data preparation and cleansing:
Data readiness is a fundamental prerequisite for successful AI implementation. Ministries and public-sector organisations should therefore begin data cleansing, classification and quality improvement activities immediately. Clear ownership and accountability for data quality should be assigned within each organisation.
3. Dedicated organisation for AI strategy execution:
The proposed National AI Authority should be established as a dedicated, appropriately empowered and adequately resourced execution body, with clear responsibility and accountability for driving implementation of the Strategy across Government.
4. Healthcare as an early priority for implementation:
Healthcare should be elevated to one of the first sectors for implementation. GESY already provides a significant advantage by generating and maintaining structured digital health data, including patient records, diagnoses, prescriptions, referrals, laboratory activity and other healthcare transactions. This existing body of organised health data can provide a strong starting point for AI applications such as clinical decision support, predictive and preventive care. Subject to confirmation of data quality and governance readiness, healthcare could provide an early opportunity to demonstrate measurable national impact from AI.
IBM welcomes the opportunity to participate in the ongoing public consultation on the National AI Strategy 2032 of the Republic of Cyprus and appreciates the efforts of the Chief Scientist, the National AI Taskforce and the Deputy Ministry of Research, Innovation and Digital Policy in developing a comprehensive national vision for artificial intelligence. We also recognise and strongly support the significant effort undertaken by the Strategy Committee. The Strategy sets out an ambitious objective for Cyprus to become a trusted AI hub in the Eastern Mediterranean, a reliable European jurisdiction for AI-enabled services, and a bridge between the European Union and neighbouring regions by 2032.
IBM strongly supports the Strategy’s overarching goal of fostering trustworthy and responsible AI adoption and welcomes the Government’s commitment to engaging stakeholders through this public consultation process. In this spirit, we offer our recommendations with the objective of strengthening the Strategy’s contribution to innovation, competitiveness, cybersecurity, and the development of an open and globally connected AI ecosystem. In our comments, we highlight that the strategy should remain technology-neutral, risk-based, and aligned with the EU Single Market. Achieving the Strategy’s objectives will also require sustained investment in future-ready skills and close alignment between the Strategy’s AI ambitions and the evolution of hybrid cloud and quantum technologies, which together will underpin the next generation of secure and high-performance computing.
1. Coordinate AI, quantum computing and cybersecurity strategies
The AI Strategy should be implemented with holistic approach, in coordination with policies and investments in quantum computing, high-performance computing and cybersecurity. These technologies are increasingly complementary: AI can accelerate the design, calibration and operation of quantum systems, while quantum computing may open new avenues for machine learning, optimisation and scientific discovery. Policymakers should therefore foster integrated ecosystems in which AI, quantum processors and classical high-performance computing resources can be combined through open, interoperable and hybrid computing architectures. This should include coordinated investment in infrastructure, research, skills and early-stage industrial experimentation, as well as collaboration with international technology providers and research partners.
This coordination must also address the cybersecurity implications of quantum computing. Future cryptographically relevant quantum computers could undermine widely used public-key cryptography, while “harvest now, decrypt later” attacks already create risks for sensitive data with a long confidentiality life. Our recommendation is therefore to start integrating post-quantum cryptography into AI, cybersecurity and critical-infrastructure planning now, rather than treating quantum safety as a future issue. AI solutions can help critical organisations accelerate specific stages of the migration process, including the preparation of cryptographic asset inventories and quantum-risk assessments. Ultimately, these efforts should align with the EU’s coordinated PQC roadmap and internationally recognised standards, while accounting for supply-chain dependencies and the long lifecycle of operational technology and critical infrastructure.
2. Preserve technical approach and avoid origin-based sovereignty criteria
IBM supports the objective of strengthening digital sovereignty and trust in AI. However, sovereignty should be assessed based on the degree of technical, operational, and legal control exercised by customers over their data, systems, and business continuity, rather than provider’s nationality or headquarters location.
In particular, we welcome the Strategy’s focus on building partnerships in Section 3.7 – however, the approach should be clearer to avoid interpretations that discriminate companies based on their country of origin. Requirements should be based on verifiable security, resilience, transparency, and governance outcomes, ensuring open competition and access to best-in-class technologies.
3. Avoid national gold-plating beyond the EU AI Act
The strategy should build on existing EU legislation, including the AI Act, GDPR, and sectoral frameworks, without introducing additional national requirements that could create regulatory fragmentation. Consistency with EU rules will reduce compliance burdens, improve legal certainty, and support the development and deployment of AI solutions across the Single Market.
4. Accelerate AI adoption in priority sectors
IBM welcomes the Strategy’s focus on sectors in which Cyprus has established economic strengths and where AI can deliver significant productivity, competitiveness and public-value gains, as outlined in Section 3.5. We recommend that the Strategy translates into concrete sectoral roadmaps, supported by access to trusted data, secure hybrid-cloud infrastructure, skilling initiatives, testbeds and regulatory sandboxes. Particular attention should be given to the following sectors:
– Tourism and hospitality: AI can support demand forecasting, personalised visitor services, multilingual assistance, destination management, resource optimisation and more sustainable tourism.
– Healthcare and life sciences: AI can augment clinical decision-making, improve patient pathways and preventive care, support resource planning and accelerate research, subject to strong protections for sensitive health data, governance and human oversight.
– Financial services and fintech: AI can strengthen fraud detection, risk management, compliance, customer due diligence and operational efficiency.
– Energy: while this sector is not highlighted in the Strategy, we emphasise that AI can optimise grids and renewable-energy integration, forecast demand, improve asset maintenance and energy efficiency, and increase the resilience of critical infrastructure.
A coordinated approach across these sectors would create reusable capabilities and economies of scale, accelerate diffusion among smaller enterprises, and enable successful solutions developed in Cyprus to expand across the EU Single Market and internationally.
5. Foster innovation through proportionate governance
Trustworthy AI provides the foundation for sustainable innovation. At the same time, Governance mechanisms should be proportionate, risk-based, and targeted at high-risk use cases.
The strategy should encourage experimentation, AI sandboxes, public-private collaboration, and rapid adoption of beneficial AI applications. Excessive approval layers, mandatory certifications, or broad compliance obligations risk slowing deployment, increasing costs, and reducing the attractiveness of Cyprus as a destination for AI investment and innovation.
The Strategy should also recognise the shift from governance based primarily on policies, assessments, and periodic human review towards the technical enforcement of risk and compliance requirements at runtime. While not every control can be automated, this evolution is particularly important for agentic AI systems, where risks may emerge dynamically across multi-step workflows and cannot be addressed adequately through human processes alone. Section 3.3.2 should therefore explicitly promote the implementation of proportionate runtime controls to complement organisational governance and enable scalable, trustworthy deployment.
6. AI skills
IBM welcomes the Strategy’s strong focus on AI skills, workforce development, and lifelong learning. We particularly support the recognition that AI should be used to augment human capabilities and productivity, enabling people to work more effectively alongside AI systems rather than simply automating tasks.
To ensure that skills programmes remain aligned with rapidly evolving technologies and labour market needs, Cyprus should promote close collaboration between government, academia, and industry in the design and delivery of AI education, training, and reskilling initiatives. Such partnerships will be critical to developing a future-ready workforce and supporting the successful adoption of AI across the economy.
Conclusion
We recommend that the Strategy positions Cyprus as an open, innovation-friendly AI hub by combining strong security and governance with technology neutrality, support for AI development, interoperability with international standards, and full alignment with the EU Single Market.
The Digital Transformation & Fintech Committee of the American Chamber of Commerce in Cyprus (AmCham Cyprus) welcomes the publication of the Cyprus National AI Strategy 2032 and commends the Chief Scientist, the National AI Taskforce, the Deputy Ministry of Research, Innovation and Digital Policy, and all contributing stakeholders for developing a comprehensive and ambitious framework for the future of Artificial Intelligence in Cyprus. The Strategy reflects a clear vision to position Cyprus as a trusted AI hub in the Eastern Mediterranean, a reliable European jurisdiction for AI-enabled services, and a bridge between Europe and neighboring markets. Its focus on innovation, productivity, public sector transformation, skills development, data governance, cybersecurity, ethics, and international cooperation provides a strong foundation for the country’s digital future.
The Committee is fully supportive of the Strategy’s overarching objectives and recognizes the significant effort invested in creating a forward-looking roadmap that aligns with European values, regulatory frameworks, and the opportunities presented by emerging AI technologies. We particularly welcome the emphasis on trustworthy, human-centered AI, the commitment to strengthening Cyprus’s competitiveness, and the aspiration to create an ecosystem that fosters innovation, investment, entrepreneurship and talent development.
At the same time, the successful implementation of the Strategy will depend not only on vision but also on execution. The Committee therefore offers the following recommendations in a constructive spirit, with the objective of strengthening the Strategy’s practicality, investment attractiveness, governance effectiveness, cybersecurity resilience, and ability to deliver measurable economic and societal outcomes. These recommendations reflect common themes and areas of consensus that emerged during the Committee’s discussion and from stakeholder feedback received from businesses, technology providers, professional services organizations and industry experts.
We submit these observations with the shared objective of helping Cyprus establish itself as a leading trusted AI Nation, capable of combining strong governance and regulatory certainty with openness, innovation, international collaboration, and sustainable economic growth:
1. Create a National AI Delivery Office
The successful implementation of the Strategy will require dedicated execution capacity, not only governance and advisory structures. The Committee recommends establishing a compact, empowered and appropriately resourced National AI Delivery Office responsible for coordinating the national implementation portfolio.
The Delivery Office should bring together program management, enterprise architecture, data governance, cybersecurity, procurement, legal and regulatory expertise, change management and benefits realization. It should support ministries and public bodies, coordinate dependencies, maintain visibility across publicly funded AI initiatives, and prevent fragmented or duplicative investments.
Its role should be clearly distinguished from that of the authorities responsible for regulatory supervision, market surveillance, data protection, and sector-specific enforcement. Ministries and public bodies should retain accountability for their respective services and outcomes, while the Delivery Office provides central coordination, common implementation standards, and practical delivery support.
2. Add a Funded Delivery Roadmap
The Committee recommends complementing the Strategy with a funded, three-year rolling delivery roadmap that translates its ambitions into an executable national program. For every major initiative, the roadmap should define:
-The accountable owner and participating organizations.
-The approved budget and funding source.
-The delivery timeline and key milestones.
-The procurement and implementation route.
-Dependencies on data, infrastructure, skills or legislation.
-Expected economic, operational or societal benefits.
-Measurable performance indicators.
-Risk, review and exit criteria.
-Arrangements for periodic public reporting.
The roadmap should reconcile the different adoption targets and implementation dates contained in the Strategy, establish realistic sequencing, and distinguish between immediate priorities, medium-term initiatives and longer-term ambitions. No significant initiative should enter the national AI portfolio without a defined owner, budget, delivery date, and measurable outcome.
3. Strengthen the Data Implementation Layer
The Committee considers data readiness to be the most important prerequisite for scaling AI responsibly. The Strategy should therefore strengthen its practical data implementation layer and ensure that data governance progresses before, or in parallel with major technology procurement. The Committee recommends:
-Assigning an accountable data owner and data steward for every priority public-sector dataset.
-Establishing minimum standards for data quality, classification, metadata, lineage, retention and lawful use.
-Creating a national catalogue of high-value datasets that identifies ownership, availability, access conditions and permitted uses.
-Prioritising secure APIs, common data standards and interoperability over point-to-point integrations.
-Requiring a formal data-readiness assessment before approving or funding a significant AI project.
-Developing governed sectoral data spaces and secure testing environments that permit controlled use without unnecessary copying or centralisation.
-Defining clear rules for confidentiality, intellectual property, anonymisation, pseudonymisation, audit rights and derived data or model outputs.
-Clarifying lawful cross-border data access and transfer arrangements under applicable European legislation.
This implementation layer should be closely aligned with the National Data Policy and the National Data Governance Framework to avoid parallel or inconsistent structures.
4. Prioritise a Limited First Wave
The Strategy contains a broad portfolio of sectors, institutions, platforms, funds, centers, sandboxes, and transformational projects. While these ambitions are strategically valuable, attempting to launch too many initiatives simultaneously risks spreading limited funding, leadership attention and specialist expertise too thinly.
The Committee recommends selecting a limited first wave of national AI missions based on economic and public value, data readiness, implementation, feasibility, scalability, cybersecurity risk and the potential to create reusable capabilities.
The initial portfolio could concentrate on:
1. AI-enabled government and citizen services, particularly high-volume services with repetitive processing, significant document requirements or long response times.
2. AI for regulated financial, fintech and professional services, including AML/KYC, compliance, regulatory reporting, audit support and administrative efficiency.
3. AI for healthcare administration and care navigation, implemented with strong data protection, clinical accountability and human oversight.
Other strategic sectors should continue through research, preparation, and controlled experimentation, but the first major funding and implementation cycle should be concentrated on a manageable number of missions. Each first-wave mission should begin with a validated problem, confirmed data readiness, an accountable owner, a funded business case, and measurable success criteria.
5. Make Cybersecurity and Resilience a Foundational Requirement
Cybersecurity should be embedded horizontally across the entire AI lifecycle, from data preparation and system design through procurement, deployment, monitoring, material modification, and decommissioning.
Every publicly funded, critical or high-impact AI system should pass a proportionate AI Security and Resilience Assessment before entering production. The assessment should address:
-Data protection and information classification.
-Identity, privileged access and machine identities.
-APIs, AI agents and system integrations.
-Models, training data and AI supply chains.
-Third-party and supplier risk.
-Data poisoning, adversarial manipulation and prompt-based attacks.
-Secure logging, monitoring and auditability.
-Model performance, drift and misuse detection.
-Human intervention, override and rollback.
-Incident reporting and coordinated response.
-Business continuity, portability and secure exit arrangements.
High-impact and critical systems should be subject to independent assurance where appropriate. AI-related incidents should also be integrated into existing national cybersecurity, data-protection, and sector-specific incident-management structures.
6. Support SME Adoption
SMEs are central to the Cypriot economy but often lack the specialist expertise, financial capacity and infrastructure required to adopt AI responsibly. The Strategy should therefore include a practical, accessible and proportionate SME AI Adoption Program. The program should provide:
-AI readiness and data-readiness assessments.
-Implementation and advisory vouchers.
-Standard AI policies and governance templates.
-Risk-classification and impact-assessment tools.
-Vendor-assessment questionnaires and procurement guidance.
-Cybersecurity and compliance support.
-Affordable access to compute, testbeds and sector sandboxes.
-Access to recognised advisers and implementation partners.
-Guidance on intellectual property, data use and contractual protections.
-Market-access and export support for validated AI solutions.
Requirements should be proportionate to organizational size, use-case risk and potential impact. Low-risk productivity tools should not be subject to the same burden as high-risk or rights-impacting systems.
Public support should be released progressively and linked to measurable results, such as productivity improvement, reduced administrative costs, improved service quality, new revenue, export potential or successful progression from pilot to responsible production use.
7. Develop Role-Based Skills and Professional Capability
AI skills policy should extend beyond technical specialists. The Committee recommends role-based education and professional-development pathways for:
-Executives and board members.
-Public servants and policymakers.
-Accountants, auditors and finance professionals.
-Legal and compliance professionals.
-Procurement and commercial teams.
-Data owners and data stewards.
-Cybersecurity and risk professionals.
-Educators and trainers.
-Regulators and assurance professionals.
-SME leaders and frontline personnel.
Training should combine AI literacy with governance, cybersecurity, data protection, responsible use, procurement, change leadership and practical sector applications. Programs should be aligned with labor-market needs, recognized for continuing professional development frameworks, and applied workplace projects.
Cyprus should also build local AI governance, cybersecurity, implementation, testing and assurance capabilities that can support domestic adoption and develop into exportable professional services.
8. Measure Outcomes, Not Activities
The Strategy’s measurement framework should prioritize economic, operational, citizen and societal outcomes. Each national KPI should have a clearly defined baseline, calculation methodology, accountable owner, data source, reporting frequency, and target trajectory.
Priority measures should include:
-Productivity improvements.
-Reductions in service-processing times.
-Reductions in administrative cost and backlog.
-Improvements in citizen and customer experience.
-SME adoption and progression to production.
-Investment attraction and business expansion.
-Creation of high-skilled employment.
-Workforce reskilling and transition outcomes.
-Growth in AI-enabled products and exportable services.
-System reliability, cybersecurity and compliance.
-Public trust and responsible-use indicators.
The number of pilots, committees, systems purchased, individuals trained or events organized may provide useful supporting information but should not be treated as the principal evidence of success. Underperforming initiatives should be redesigned or discontinued, while successful and reusable capabilities should be scaled across ministries and sectors.
9. Preserve Openness, Investment and Trusted International Partnerships
Cyprus’s ambition to develop strategic AI capability should be pursued through openness, interoperability and trusted international cooperation. The Committee recommends defining AI sovereignty and strategic autonomy in terms of effective governance, security, resilience, legal control, portability and strategic choice, rather than domestic ownership, supplier nationality or blanket data localization.
Cyprus should retain meaningful control over critical data, services and operational decisions while leveraging trusted European, United States and other international partners to obtain the technology, compute capacity, expertise, investment and access to global markets required to achieve scale. International partnerships should be assessed using objective criteria, including security, transparency, legal enforceability, supply-chain assurance, operational continuity, and alignment with European law and values. The Committee recommends:
-Ensuring that public procurement, infrastructure access, funding programmes and testing environments apply transparent, proportionate and technology-neutral criteria.
-Avoiding origin-based preferences or localisation requirements unless objectively justified by applicable law, national security, data sensitivity or demonstrated operational risk.
-Supporting lawful cross-border data access and transfers under applicable European data-protection legislation.
-Protecting pre-existing intellectual property, confidential business information, trade secrets and cybersecurity-sensitive technical evidence.
-Defining clear rights for public-sector data, supplier data, project-created intellectual property, derived outputs and model improvements.
-Requiring interoperability, data portability, supplier-transition arrangements and tested exit plans to reduce concentration and vendor lock-in.
-Recognising equivalent international standards, technical evidence and assurance practices where permitted by European law.
-Creating clear and coordinated pathways for trusted international investors, technology providers, research institutions and implementation partners to establish, test, develop and scale AI-enabled services from Cyprus.
-Strengthening structured cooperation between Cyprus, the European Union, the United States and other trusted jurisdictions in areas such as research, skills, cybersecurity, standards, testing, investment and responsible AI deployment.
Strategic autonomy should provide Cyprus with control, resilience and choice without limiting access to global innovation. A clear and investment-compatible approach will strengthen Cyprus’s position as a trusted European jurisdiction, attract international capital and expertise, support domestic companies and researchers, and enable AI solutions developed or validated in Cyprus to scale into European and neighboring markets. This directly addresses the attached AmCham position paper’s concerns around sovereignty, localization, procurement, cross-border data flows and intellectual property protection.
The Committee values the opportunity to contribute to this important national dialogue and stands ready to support the next phase through continued cooperation among government, industry, academia, professional bodies and civil society.
Public Consultation Submission — Cyprus National AI Strategy 2032
Consultation: Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας
Submitted by: Christos Michas
Date: 31 August 2026
Note
It is encouraging to see Cyprus develop a National AI Strategy and make it available for public consultation. The Deputy Ministry of Research, Innovation and Digital Policy, the Chief Scientist for Research, Innovation and Technology, the National AI Taskforce and all those involved in preparing the Strategy should be congratulated.
Our comments below come from twenty years of building automation for enterprises and, more recently, watching what actually happens when AI agents get put in front of real processes — not demos. Daniel Dines, UiPath’s founder, wrote a whole book about this recently (The Work That Remains – https://www.uipath.com/resources/automation-whitepapers/the-work-that-remains), and the short version of the argument is the one we keep coming back to here: an agent proposes, a person decides, and deterministic automation executes — and the thing that has to be governed is the map (the description of how the work actually happens: who decides what, where the exceptions are, what gets audited) and the rails (the machinery that carries out the approved, stable parts of that map, exactly the same way every time). The agent sits on top of both. It isn’t either one.
The Strategy talks a lot about AI agents and use cases but never quite separates the agent from the process it’s dropped into. That’s the gap our four comments are about. We’ve kept them short.
We’d also flag that this isn’t just our house view. Independent commentary elsewhere in the industry has been making the same point from a different angle recently: model capability keeps expanding fast enough that anything an organisation hard-wires into an agent today is likely to be rebuilt or replaced within a year or two, while a well-written description of the process — the goal, the constraints, who signs off, what counts as done — stays valid across that churn. Whoever ends up building or supplying the agents to Cyprus’s public sector, that description is the thing worth Cyprus owning.
Comment 1 — Govern the process, not the agent
Άρθρο: Annex G Glossary (pp. 95–96); Section 3.3.2 Control Framework (pp. 27–28); Annex B Control Gate 1 (pp. 57–58)
Σχόλιο: Add “AI agent” and “process/workflow” as separate terms in the Glossary, and say explicitly in Section 3.3.2 and Annex B that risk classification, approval gates and human oversight attach to the process the agent is used in, not to the agent itself.
Αιτιολόγηση: An agent’s ability to produce a good answer doesn’t automatically give anyone permission to act on it — that permission comes from who owns the decision, what gate the work has to pass through, and what gets recorded afterward. Those things live in the process, not in the model. One agent can sit inside a low-risk internal task this week and a citizen-facing benefits decision next week, completely unchanged. Certifying “the agent” once tells nobody whether this particular use of it, right now, in this particular process, is safe. This is also how the AI Act itself works: Annex III classifies risk by use case, not by the technology underneath it.
Comment 2 — Map the process before automating it, and write down why each step is RPA, an agent, or a person
Άρθρο: Section 3.4.1 (p. 28) and 3.4.2 (p. 28); Annex B Stage 1 / Control Gate 1 (pp. 57–58)
Σχόλιο: Before a use case clears Control Gate 1, require a short written map of the process — what it touches, who decides what, where the exceptions live — with each step assigned to RPA, an AI agent, or a human. Drop the “AI-first procurement” commitment in 3.4.1 in favour of this.
Αιτιολόγηση: Not everything needs an agent. Rule-based, high-volume steps are usually cheaper and more predictable on deterministic automation; steps that need judgement should stay with a person. Annex B already lists RPA as a “quick win” option at Stage 1 (p. 58), so the thinking is already there — it just doesn’t make it into the procurement principle. “AI-first” as a default pushes the opposite way: reaching for an LLM where a rule-based bot would be faster, cheaper, and have a lot less that can go wrong. Most process charts also only describe the happy path; the exceptions are where the real risk sits, and they’re worth mapping honestly rather than assumed away.
Comment 3 — Testing and monitoring can’t stop at launch, and capability should be earned in stages
Άρθρο: Annex B, Stage 4 “Deployment and Operation” and Control Gate 4 “Operational Assurance Review” (p. 59)
Σχόλιο: Turn “ongoing monitoring” and “periodic reviews” at Stage 4 / Control Gate 4 into something concrete: a defined test cadence per process, a fixed test set re-run whenever the underlying model changes, and a rule that an agent doesn’t get more autonomy on a process until it has earned it through evidence — and loses it automatically if performance drops.
Αιτιολόγηση: An agent checking its own work has the same blind spots as the agent that did the work, so production systems need an independent check — a test, a rule, a person, something outside the agent itself. Models also don’t hold still: the one behind an agent gets updated by its provider, a prompt changes, upstream data shifts, often without anyone downstream noticing. “Periodic review” without a number attached to it tends to quietly stop happening once the launch is old news — we’ve watched that happen plenty of times, and not only in government. A cheap, repeatable test set that runs on a schedule, plus a simple rule that trust is earned gradually and can be taken back, catches drift before a citizen does.
Comment 4 — Measure ROI on the process, and treat the map — not the agent — as the durable asset
Άρθρο: Section 3.11.1 and 3.11.2 (pp. 44–45); Annex F (pp. 93–94); Section 3.1.2 “Reuse and interoperability” (p. 19)
Σχόλιο: Measure ROI (cycle time, cost per case, rework, citizen satisfaction) at the process level, not the agent level, and treat the documented process map as the thing worth keeping — a simple registry of what each redesigned process does, how each step is executed, and what its risk classification is — so ministries stop rebuilding the same process twice.
Αιτιολόγηση: Section 3.11.1 already says the right thing — focus on what AI enables, not how many systems get deployed (p. 44) — but the actual indicators in 3.11.2 and Annex F still count use cases and systems deployed. An agent can score perfectly on accuracy and leave the process just as slow if nothing else around it changed. Agents will be swapped out, upgraded, replaced by better ones; that’s normal and healthy. What shouldn’t get thrown away every time is the documented knowledge of how the process actually works — who decides what, where the exceptions are, what happened last time something went wrong. That’s the part worth Cyprus owning centrally, and it’s what future agents plug into, not the other way round.
1. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο:** Ενότητες 2.3, 2.4 και 2.5.1, τοποθέτηση της Κύπρου ως «Trusted AI Jurisdiction / Hub»
Σχόλιο / Εισήγηση:Προτείνεται να αποσαφηνιστεί και να συγκεκριμενοποιηθεί το ανταγωνιστικό πλεονέκτημα της Κύπρου ως «trusted AI jurisdiction». Η συμμόρφωση με το ευρωπαϊκό κανονιστικό πλαίσιο αποτελεί αναγκαία προϋπόθεση για όλα τα κράτη μέλη και, από μόνη της, δεν συνιστά διαφοροποίηση. Η Στρατηγική θα πρέπει να προσδιορίζει με σαφήνεια γιατί μία επιχείρηση, επενδυτής ή οργανισμός θα επέλεγε την Κύπρο έναντι άλλης ευρωπαϊκής δικαιοδοσίας. Ενδεικτικά, η διαφοροποίηση θα μπορούσε να στηριχθεί στην ταχύτερη κανονιστική καθοδήγηση, στην εύκολη πρόσβαση σε regulatory sandboxes και testbeds, στην εξειδίκευση σε συγκεκριμένους ρυθμιζόμενους κλάδους, στην πρόσβαση σε αξιόπιστα δεδομένα και στην ταχεία μετάβαση από το pilot σε παραγωγική εφαρμογή.
Αιτιολόγηση σχολίου / Εισήγησης: Μία εθνική στρατηγική χρειάζεται σαφή στρατηγική επιλογή και όχι μόνο έναν γενικό στόχο τοποθέτησης. Το ζητούμενο δεν είναι απλώς να δημιουργηθεί ένα αξιόπιστο περιβάλλον για την ΤΝ, αλλά να προσδιοριστεί σε ποιους συγκεκριμένους τομείς η Κύπρος μπορεί να είναι καλύτερη, ταχύτερη ή πιο αποτελεσματική από άλλες χώρες. Η συγκεκριμενοποίηση αυτής της πρότασης αξίας θα επιτρέψει επίσης τη δημιουργία μετρήσιμων δεικτών, όπως χρόνος πρόσβασης σε sandbox, χρόνος παροχής κανονιστικής καθοδήγησης, αριθμός εφαρμογών που περνούν από δοκιμή σε παραγωγή, επενδύσεις που προσελκύονται και εξαγωγές υπηρεσιών ΤΝ.
2. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Ενότητα 3.4.1, Παράρτημα Β και Ενότητα 5, «AI-first procurement» και υποχρέωση εντοπισμού πέντε περιπτώσεων χρήσης ΤΝ ανά Υπουργείο
Σχόλιο / Εισήγηση: Προτείνεται η έννοια «AI-first» να αντικατασταθεί από μία προσέγγιση «problem-first» και outcome-based, όπου η ΤΝ εξετάζεται συστηματικά ως πιθανή λύση, χωρίς όμως να θεωρείται εκ των προτέρων η κατάλληλη τεχνολογία. Αντίστοιχα, η απαίτηση κάθε Υπουργείο να εντοπίσει συγκεκριμένο αριθμό περιπτώσεων χρήσης ΤΝ θα ήταν προτιμότερο να αντικατασταθεί από υποχρέωση εντοπισμού και ιεράρχησης προβλημάτων ή ευκαιριών μετασχηματισμού, βάσει αναμενόμενης αξίας, διαθεσιμότητας και ποιότητας δεδομένων, εφικτότητας, κόστους και κινδύνου.
Αιτιολόγηση σχολίου / Εισήγησης: Η απαίτηση συγκεκριμένου αριθμού εφαρμογών ΤΝ ενέχει τον κίνδυνο να δημιουργήσει κίνητρο για χρήση της τεχνολογίας ακόμη και εκεί όπου δεν αποτελεί την καλύτερη λύση. Αυτό έρχεται σε αντίθεση με την ίδια τη φιλοσοφία της Στρατηγικής, η οποία ορθά αναφέρεται στην ανάγκη αποφυγής του «AI theatre» και στην αξιολόγηση της πραγματικής αξίας κάθε εφαρμογής. Ο στόχος του Δημοσίου θα πρέπει να είναι η βελτίωση υπηρεσιών, παραγωγικότητας και αποτελεσμάτων. Σε ορισμένες περιπτώσεις αυτό θα επιτυγχάνεται με ΤΝ, σε άλλες με αυτοματοποίηση, καλύτερη διασύνδεση συστημάτων, επανασχεδιασμό διαδικασιών ή απλούστερες τεχνολογικές λύσεις.
3. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Ενότητες 3.5, 4.4 και 5, υποστήριξη επιχειρηματικής υιοθέτησης της ΤΝ και μηχανισμοί κινήτρων
Σχόλιο / Εισήγηση: Προτείνεται η Στρατηγική να ενισχύσει σημαντικά τη διάσταση δημιουργίας επιχειρηματικής ζήτησης για ΤΝ, με τη δημιουργία ενός συστηματικού μηχανισμού που θα βοηθά επιχειρήσεις να μετατρέπουν πραγματικές επιχειρηματικές ανάγκες σε ώριμα και υλοποιήσιμα έργα. Ο μηχανισμός θα μπορούσε να περιλαμβάνει επιδοτούμενες αξιολογήσεις AI και data readiness, χαρτογράφηση διαδικασιών και σημείων συμφόρησης, identification και prioritisation συγκεκριμένων use cases, εκτίμηση οικονομικού οφέλους και κόστους, καθώς και συγχρηματοδότηση της υλοποίησης για τις περιπτώσεις όπου τεκμηριώνεται θετικό business case. Προτείνεται επίσης η δημιουργία sector-specific challenge calls, όπου επιχειρήσεις θα υποβάλλουν πραγματικά επιχειρηματικά προβλήματα και θα υποστηρίζονται στη μετάβασή τους από το πρόβλημα στην εφαρμογή.
Αιτιολόγηση σχολίου / Εισήγησης: Η αύξηση της προσφοράς τεχνολογίας, υποδομών, δεξιοτήτων ή χρηματοδοτικών εργαλείων δεν δημιουργεί αυτομάτως αντίστοιχη ζήτηση. Ιδιαίτερα στις ΜΜΕ, το βασικό εμπόδιο συχνά προηγείται της επιλογής τεχνολογίας: η επιχείρηση δεν γνωρίζει ποια προβλήματα αξίζει να αντιμετωπίσει με ΤΝ, ποια δεδομένα απαιτούνται, τι αλλαγές χρειάζονται στις διαδικασίες της ή ποιο θα είναι το οικονομικό αποτέλεσμα. Για να επιτευχθούν οι φιλόδοξοι στόχοι υιοθέτησης της Στρατηγικής χρειάζεται επομένως ένας ενεργός μηχανισμός δημιουργίας και ωρίμανσης της ζήτησης και όχι μόνο ένα οικοσύστημα προσφοράς λύσεων. Η δημόσια στήριξη θα πρέπει να λειτουργεί καταλυτικά ώστε περισσότερες επιχειρήσεις να φθάνουν σε τεκμηριωμένες επενδυτικές αποφάσεις και τελικά σε παραγωγικές εφαρμογές ΤΝ.
4. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Ενότητες 3.5, 3.6, 4.4 και 5, υιοθέτηση ΤΝ από επιχειρήσεις και ΜΜΕ
Σχόλιο / Εισήγηση: Προτείνεται η δημιουργία ενός συγκεκριμένου προγράμματος «AI Adoption and Productivity» για κυπριακές επιχειρήσεις και ιδιαίτερα για ΜΜΕ, το οποίο να μην περιορίζεται στη χρηματοδότηση τεχνολογικών λύσεων ή στην κατάρτιση. Το πρόγραμμα θα μπορούσε να περιλαμβάνει δομημένες αξιολογήσεις AI και data readiness, χαρτογράφηση και επανασχεδιασμό διαδικασιών, εντοπισμό και οικονομική αξιολόγηση περιπτώσεων χρήσης, πρόσβαση σε εξειδικευμένη υποστήριξη υλοποίησης, συγχρηματοδότηση εφαρμογών που έχουν τεκμηριωμένη επιχειρηματική αξία και υποχρεωτική μέτρηση των αποτελεσμάτων μετά την εφαρμογή.
Αιτιολόγηση σχολίου / Εισήγησης: Για μεγάλο μέρος των κυπριακών επιχειρήσεων, το βασικό εμπόδιο στην αξιοποίηση της ΤΝ δεν είναι η πρόσβαση σε μοντέλα ή υπολογιστική ισχύ. Είναι η ποιότητα και κατακερματισμένη μορφή των δεδομένων, οι μη τυποποιημένες διαδικασίες, τα απομονωμένα πληροφοριακά συστήματα, η περιορισμένη δυνατότητα εντοπισμού κατάλληλων περιπτώσεων χρήσης και η έλλειψη ικανότητας διαχείρισης της οργανωτικής αλλαγής. Εάν η πολιτική περιοριστεί στην προσφορά τεχνολογίας, training ή χρηματοδότησης pilots, υπάρχει κίνδυνος να αυξηθεί ο αριθμός των πειραματικών εφαρμογών χωρίς αντίστοιχη αύξηση παραγωγικότητας. Η επιτυχία της Στρατηγικής θα πρέπει να μετράται κυρίως από την οικονομική αξία που δημιουργείται από την πραγματική παραγωγική χρήση της ΤΝ.
5. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Ενότητες 3.2, 3.5 και 4.4, Data Infrastructure, Supporting SMEs και AI Adoption Enablers
Σχόλιο / Εισήγηση: Προτείνεται η έννοια του AI readiness να διευρυνθεί ώστε να περιλαμβάνει ρητά την ετοιμότητα δεδομένων, διαδικασιών και συστημάτων μιας επιχείρησης και οι σχετικές παρεμβάσεις να αποτελούν επιλέξιμες δαπάνες στα προγράμματα στήριξης. Η χρηματοδότηση της υιοθέτησης ΤΝ δεν θα πρέπει να αφορά αποκλειστικά την αγορά ή ανάπτυξη της τελικής εφαρμογής, αλλά και τις απαραίτητες προπαρασκευαστικές παρεμβάσεις, όπως data integration, data quality, interoperability, workflow redesign και διασύνδεση υφιστάμενων συστημάτων.
Αιτιολόγηση σχολίου / Εισήγησης: Πολλές αποτυχημένες ή περιορισμένης αξίας εφαρμογές ΤΝ δεν αποτυγχάνουν λόγω της ίδιας της τεχνολογίας, αλλά επειδή επιχειρούν να λειτουργήσουν πάνω σε κατακερματισμένα δεδομένα, μη τυποποιημένες διαδικασίες και ασύνδετα πληροφοριακά συστήματα. Εάν τα χρηματοδοτικά εργαλεία καλύπτουν μόνο το τελευταίο επίπεδο, δηλαδή την εφαρμογή ΤΝ, υπάρχει κίνδυνος να χρηματοδοτούνται τεχνολογικές λύσεις χωρίς τις απαραίτητες προϋποθέσεις για πραγματική αξιοποίηση. Η αντιμετώπιση του data και process readiness ως μέρος της επένδυσης στην ΤΝ θα αυξήσει σημαντικά την πιθανότητα οι επιδοτούμενες εφαρμογές να φθάσουν σε παραγωγική χρήση και να δημιουργήσουν μετρήσιμη αξία.
6. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Ενότητες 3.5, 3.8, 4.4 και Παράρτημα ΣΤ, επιχειρηματική υιοθέτηση, testbeds και δείκτες αποτελεσμάτων
Σχόλιο / Εισήγηση: Προτείνεται να θεσπιστεί ένας σαφής μηχανισμός «pilot-to-scale», ώστε οι επιχειρήσεις που ολοκληρώνουν επιτυχώς ένα pilot ή proof of concept να μπορούν να προχωρούν γρήγορα στην παραγωγική εφαρμογή, εφόσον επιτυγχάνονται προκαθορισμένοι δείκτες. Η δεύτερη φάση στήριξης θα μπορούσε να αφορά integration, deployment, change management, monitoring και scaling και να ενεργοποιείται βάσει τεκμηριωμένων αποτελεσμάτων του pilot. Παράλληλα, στους εθνικούς δείκτες θα πρέπει να καταγράφεται όχι μόνο ο αριθμός των pilots, αλλά το ποσοστό που περνά σε production και η οικονομική αξία που δημιουργείται.
Αιτιολόγηση σχολίου / Εισήγησης: Ένα από τα μεγαλύτερα προβλήματα διεθνώς στην αξιοποίηση της ΤΝ είναι το χάσμα μεταξύ πειραματισμού και παραγωγικής εφαρμογής. Ένας μεγάλος αριθμός pilots μπορεί να δημιουργεί την εικόνα έντονης δραστηριότητας χωρίς αντίστοιχη οικονομική επίδραση. Η Στρατηγική ορθά αναγνωρίζει τον κίνδυνο του «AI theatre». Συνεπώς, τα χρηματοδοτικά και υποστηρικτικά εργαλεία θα πρέπει να σχεδιαστούν ώστε να επιβραβεύουν τη μετάβαση από experimentation σε measurable business value. Βασικοί δείκτες επιτυχίας θα πρέπει να είναι το pilot-to-production conversion rate, η βελτίωση παραγωγικότητας, η εξοικονόμηση κόστους, η δημιουργία νέων εσόδων και ο χρόνος που απαιτείται για την κλιμάκωση μιας επιτυχημένης εφαρμογής.
The Digital Transformation & Fintech Committee of the American Chamber of Commerce in Cyprus (AmCham Cyprus) welcomes the publication of the Cyprus National AI Strategy 2032 and commends the Chief Scientist, the National AI Taskforce, the Deputy Ministry of Research, Innovation and Digital Policy, and all contributing stakeholders for developing a comprehensive and ambitious framework for the future of Artificial Intelligence in Cyprus. The Strategy reflects a clear vision to position Cyprus as a trusted AI hub in the Eastern Mediterranean, a reliable European jurisdiction for AI-enabled services, and a bridge between Europe and neighboring markets. Its focus on innovation, productivity, public sector transformation, skills development, data governance, cybersecurity, ethics, and international cooperation provides a strong foundation for the country’s digital future.
The Committee is fully supportive of the Strategy’s overarching objectives and recognizes the significant effort invested in creating a forward-looking roadmap that aligns with European values, regulatory frameworks, and the opportunities presented by emerging AI technologies. We particularly welcome the emphasis on trustworthy, human-centered AI, the commitment to strengthening Cyprus’s competitiveness, and the aspiration to create an ecosystem that fosters innovation, investment, entrepreneurship and talent development.
At the same time, the successful implementation of the Strategy will depend not only on vision but also on execution. The Committee therefore offers the following recommendations in a constructive spirit, with the objective of strengthening the Strategy’s practicality, investment attractiveness, governance effectiveness, cybersecurity resilience, and ability to deliver measurable economic and societal outcomes. These recommendations reflect common themes and areas of consensus that emerged during the Committee’s discussion and from stakeholder feedback received from businesses, technology providers, professional services organizations and industry experts.
We submit these observations with the shared objective of helping Cyprus establish itself as a leading trusted AI Nation, capable of combining strong governance and regulatory certainty with openness, innovation, international collaboration, and sustainable economic growth:
1. Create a National AI Delivery Office
The successful implementation of the Strategy will require dedicated execution capacity, not only governance and advisory structures. The Committee recommends establishing a compact, empowered and appropriately resourced National AI Delivery Office responsible for coordinating the national implementation portfolio.
The Delivery Office should bring together program management, enterprise architecture, data governance, cybersecurity, procurement, legal and regulatory expertise, change management and benefits realization. It should support ministries and public bodies, coordinate dependencies, maintain visibility across publicly funded AI initiatives, and prevent fragmented or duplicative investments.
Its role should be clearly distinguished from that of the authorities responsible for regulatory supervision, market surveillance, data protection, and sector-specific enforcement. Ministries and public bodies should retain accountability for their respective services and outcomes, while the Delivery Office provides central coordination, common implementation standards, and practical delivery support.
2. Add a Funded Delivery Roadmap
The Committee recommends complementing the Strategy with a funded, three-year rolling delivery roadmap that translates its ambitions into an executable national program. For every major initiative, the roadmap should define:
The accountable owner and participating organizations.
The approved budget and funding source.
The delivery timeline and key milestones.
The procurement and implementation route.
Dependencies on data, infrastructure, skills or legislation.
Expected economic, operational or societal benefits.
Measurable performance indicators.
Risk, review and exit criteria.
Arrangements for periodic public reporting.
The roadmap should reconcile the different adoption targets and implementation dates contained in the Strategy, establish realistic sequencing, and distinguish between immediate priorities, medium-term initiatives and longer-term ambitions. No significant initiative should enter the national AI portfolio without a defined owner, budget, delivery date, and measurable outcome.
3. Strengthen the Data Implementation Layer
The Committee considers data readiness to be the most important prerequisite for scaling AI responsibly. The Strategy should therefore strengthen its practical data implementation layer and ensure that data governance progresses before, or in parallel with major technology procurement. The Committee recommends:
Assigning an accountable data owner and data steward for every priority public-sector dataset.
Establishing minimum standards for data quality, classification, metadata, lineage, retention and lawful use.
Creating a national catalogue of high-value datasets that identifies ownership, availability, access conditions and permitted uses.
Prioritising secure APIs, common data standards and interoperability over point-to-point integrations.
Requiring a formal data-readiness assessment before approving or funding a significant AI project.
Developing governed sectoral data spaces and secure testing environments that permit controlled use without unnecessary copying or centralisation.
Defining clear rules for confidentiality, intellectual property, anonymisation, pseudonymisation, audit rights and derived data or model outputs.
Clarifying lawful cross-border data access and transfer arrangements under applicable European legislation.
This implementation layer should be closely aligned with the National Data Policy and the National Data Governance Framework to avoid parallel or inconsistent structures.
4. Prioritise a Limited First Wave
The Strategy contains a broad portfolio of sectors, institutions, platforms, funds, centers, sandboxes, and transformational projects. While these ambitions are strategically valuable, attempting to launch too many initiatives simultaneously risks spreading limited funding, leadership attention and specialist expertise too thinly.
The Committee recommends selecting a limited first wave of national AI missions based on economic and public value, data readiness, implementation, feasibility, scalability, cybersecurity risk and the potential to create reusable capabilities.
The initial portfolio could concentrate on:
AI-enabled government and citizen services, particularly high-volume services with repetitive processing, significant document requirements or long response times.
AI for regulated financial, fintech and professional services, including AML/KYC, compliance, regulatory reporting, audit support and administrative efficiency.
AI for healthcare administration and care navigation, implemented with strong data protection, clinical accountability and human oversight.
Other strategic sectors should continue through research, preparation, and controlled experimentation, but the first major funding and implementation cycle should be concentrated on a manageable number of missions. Each first-wave mission should begin with a validated problem, confirmed data readiness, an accountable owner, a funded business case, and measurable success criteria.
5. Make Cybersecurity and Resilience a Foundational Requirement
Cybersecurity should be embedded horizontally across the entire AI lifecycle, from data preparation and system design through procurement, deployment, monitoring, material modification, and decommissioning.
Every publicly funded, critical or high-impact AI system should pass a proportionate AI Security and Resilience Assessment before entering production. The assessment should address:
Data protection and information classification.
Identity, privileged access and machine identities.
APIs, AI agents and system integrations.
Models, training data and AI supply chains.
Third-party and supplier risk.
Data poisoning, adversarial manipulation and prompt-based attacks.
Secure logging, monitoring and auditability.
Model performance, drift and misuse detection.
Human intervention, override and rollback.
Incident reporting and coordinated response.
Business continuity, portability and secure exit arrangements.
High-impact and critical systems should be subject to independent assurance where appropriate. AI-related incidents should also be integrated into existing national cybersecurity, data-protection, and sector-specific incident-management structures.
6. Support SME Adoption
SMEs are central to the Cypriot economy but often lack the specialist expertise, financial capacity and infrastructure required to adopt AI responsibly. The Strategy should therefore include a practical, accessible and proportionate SME AI Adoption Program. The program should provide:
AI readiness and data-readiness assessments.
Implementation and advisory vouchers.
Standard AI policies and governance templates.
Risk-classification and impact-assessment tools.
Vendor-assessment questionnaires and procurement guidance.
Cybersecurity and compliance support.
Affordable access to compute, testbeds and sector sandboxes.
Access to recognised advisers and implementation partners.
Guidance on intellectual property, data use and contractual protections.
Market-access and export support for validated AI solutions.
Requirements should be proportionate to organizational size, use-case risk and potential impact. Low-risk productivity tools should not be subject to the same burden as high-risk or rights-impacting systems.
Public support should be released progressively and linked to measurable results, such as productivity improvement, reduced administrative costs, improved service quality, new revenue, export potential or successful progression from pilot to responsible production use.
7. Develop Role-Based Skills and Professional Capability
AI skills policy should extend beyond technical specialists. The Committee recommends role-based education and professional-development pathways for:
Executives and board members.
Public servants and policymakers.
Accountants, auditors and finance professionals.
Legal and compliance professionals.
Procurement and commercial teams.
Data owners and data stewards.
Cybersecurity and risk professionals.
Educators and trainers.
Regulators and assurance professionals.
SME leaders and frontline personnel.
Training should combine AI literacy with governance, cybersecurity, data protection, responsible use, procurement, change leadership and practical sector applications. Programs should be aligned with labor-market needs, recognized for continuing professional development frameworks, and applied workplace projects.
Cyprus should also build local AI governance, cybersecurity, implementation, testing and assurance capabilities that can support domestic adoption and develop into exportable professional services.
8. Measure Outcomes, Not Activities
The Strategy’s measurement framework should prioritize economic, operational, citizen and societal outcomes. Each national KPI should have a clearly defined baseline, calculation methodology, accountable owner, data source, reporting frequency, and target trajectory.
Priority measures should include:
Productivity improvements.
Reductions in service-processing times.
Reductions in administrative cost and backlog.
Improvements in citizen and customer experience.
SME adoption and progression to production.
Investment attraction and business expansion.
Creation of high-skilled employment.
Workforce reskilling and transition outcomes.
Growth in AI-enabled products and exportable services.
System reliability, cybersecurity and compliance.
Public trust and responsible-use indicators.
The number of pilots, committees, systems purchased, individuals trained or events organized may provide useful supporting information but should not be treated as the principal evidence of success. Underperforming initiatives should be redesigned or discontinued, while successful and reusable capabilities should be scaled across ministries and sectors.
9. Preserve Openness, Investment and Trusted International Partnerships
Cyprus’s ambition to develop strategic AI capability should be pursued through openness, interoperability and trusted international cooperation. The Committee recommends defining AI sovereignty and strategic autonomy in terms of effective governance, security, resilience, legal control, portability and strategic choice, rather than domestic ownership, supplier nationality or blanket data localization.
Cyprus should retain meaningful control over critical data, services and operational decisions while leveraging trusted European, United States and other international partners to obtain the technology, compute capacity, expertise, investment and access to global markets required to achieve scale. International partnerships should be assessed using objective criteria, including security, transparency, legal enforceability, supply-chain assurance, operational continuity, and alignment with European law and values. The Committee recommends:
Ensuring that public procurement, infrastructure access, funding programmes and testing environments apply transparent, proportionate and technology-neutral criteria.
Avoiding origin-based preferences or localisation requirements unless objectively justified by applicable law, national security, data sensitivity or demonstrated operational risk.
Supporting lawful cross-border data access and transfers under applicable European data-protection legislation.
Protecting pre-existing intellectual property, confidential business information, trade secrets and cybersecurity-sensitive technical evidence.
Defining clear rights for public-sector data, supplier data, project-created intellectual property, derived outputs and model improvements.
Requiring interoperability, data portability, supplier-transition arrangements and tested exit plans to reduce concentration and vendor lock-in.
Recognising equivalent international standards, technical evidence and assurance practices where permitted by European law.
Creating clear and coordinated pathways for trusted international investors, technology providers, research institutions and implementation partners to establish, test, develop and scale AI-enabled services from Cyprus.
Strengthening structured cooperation between Cyprus, the European Union, the United States and other trusted jurisdictions in areas such as research, skills, cybersecurity, standards, testing, investment and responsible AI deployment.
Strategic autonomy should provide Cyprus with control, resilience and choice without limiting access to global innovation. A clear and investment-compatible approach will strengthen Cyprus’s position as a trusted European jurisdiction, attract international capital and expertise, support domestic companies and researchers, and enable AI solutions developed or validated in Cyprus to scale into European and neighboring markets. This directly addresses the attached AmCham position paper’s concerns around sovereignty, localization, procurement, cross-border data flows and intellectual property protection.
The Committee values the opportunity to contribute to this important national dialogue and stands ready to support the next phase through continued cooperation among government, industry, academia, professional bodies and civil society.
PUBLIC CONSULTATION SUBMISSION
Priority Comments on the Cyprus National AI Strategy 2032
A Centre-of-Excellence and maritime perspective
Submitted by: CMMI Cyprus Marine and Maritime Institute
Submitted to: Deputy Ministry of Research, Innovation and Digital Policy
Consultation: National AI Strategy – public consultation
Date: 31 August 2026
Scope: The submission supports the Strategy’s overall vision and concentrates on the few amendments most likely to convert Cyprus’s maritime and Centre-of-Excellence strengths into safe, investable and publicly valuable AI capability.
__________________________________________________________________________
COMMENT 1: Make marine autonomy a first-wave European flagship
Article and paragraph to which the comment refers: Section 3.8.5, “National Testbeds” (paragraphs beginning “The Cyprus AI Strategy calls…” and “These testbeds will…”); Chapter 5, item 4, “Accelerating Adoption and Industry Readiness” (bullet “Development of an Autonomous Systems Park”); Annex C, “Shipping and Maritime” → “Flagship programme(s)” (paragraph beginning “A national Maritime AI programme…”); Annex D, “Focus Area 2: Autonomous Systems”.
Comment / Suggestion: Marine autonomy should be included in the initial national testbed programme. The Strategy should establish a named flagship: a European Centre for Testing, Validation and Assurance of Marine Autonomous Systems in Cyprus. CMMI proposes to develop and operate this facility under a national mandate and joint governance with the competent authorities, the Shipping Deputy Ministry, industry, universities and research organisations.
The Centre should provide an open pathway from simulation and digital twins through software- and hardware-in-the-loop testing to supervised harbour, coastal and open-water trials. Its scope should cover surface and underwater vessels, supporting aerial systems, multi-vehicle coordination, remote operations, communications and navigation degradation, cyber-resilience, human supervisory control and environmental performance. It should produce repeatable test protocols, validated datasets, safety-case support and evidence suitable for regulatory, classification and conformity-assessment review. Development, independent validation and formal certification functions must remain clearly separated.
CMMI should be tasked to coordinate the preparatory feasibility study, business plan and European partnership model, with investment conditional on open access, competent-authority participation, independent governance and measurable public and economic outcomes.
Justification: The Strategy already contains the necessary components—an Autonomous Systems Park, national testbeds, an EU shipping and maritime testbed, a regulatory sandbox and autonomous-systems research—but leaves them dispersed and postpones maritime participation. Cyprus can build rapidly on complementary CMMI assets and investments: MARIC expertise in heterogeneous marine robotics, CyMON mission-control and marine-data capabilities, MDigi-I testbeds and laboratories, the MARTA concept, expanded laboratory capacity and the demonstrated EONIOS autonomy concept. Federating these assets would reduce duplication and create a durable European-facing capability for safer shipping, port operations, search and rescue, pollution monitoring, environmental protection, emergency response and critical-infrastructure inspection.
Supporting evidence: CMMI MARIC (https://www.cmmi.blue/marine-autonomous-robotic-intelligent-systems-centre/) | CyMON (https://www.cmmi.blue/the-cyprus-marine-observation-network/) | MDigi-I (https://www.cmmi.blue/mdigi-i/) | EONIOS (https://www.cmmi.blue/eonios-unoc3/)
__________________________________________________________________________
COMMENT 2: Use a federated Centre-of-Excellence delivery model
Article and paragraph to which the comment refers: Section 1.2, paragraph beginning “To support the objectives, it is imperative to build world-class Centres of Excellence”; Section 3.3.1, “Governance Structure”, including “National AI Industrial Centre of Excellence”; Section 4.2.1, “AI Infrastructure Enablers”; Chapter 5, item 3, “Setting Up the Innovation Infrastructure”.
Comment / Suggestion: The Strategy should define a federated, mission-oriented national network of Centres of Excellence before creating additional institutions. The National AI Authority should set portfolio priorities and common governance; the proposed Industrial AI Centre of Excellence should provide horizontal AI engineering, compliance blueprints and reusable architectures; and designated existing thematic Centres should lead sector missions, data spaces and testbeds under transparent performance agreements.
The model should specify mandates, decision rights, infrastructure access, procurement roles, funding, intellectual-property and data rules, conflict-of-interest controls and outcome accountability. Mission leadership should be assigned through capability-based partnerships involving domain Centres, competent authorities, industry and universities. For maritime missions, CMMI proposes to serve as the thematic delivery node, subject to national governance, open participation and performance review.
The final Strategy should also use one consistent name and mandate for the “Industrial Centre of Excellence”, “National AI Industrial Centre of Excellence” and “AI Industrial Centre of Excellence”, and clarify its interface with sector-specific Centres.
Justification: The draft correctly recognises world-class Centres of Excellence as a national capability, but does not formally position existing thematic Centres as delivery assets and assigns overlapping functions to several proposed bodies. This creates a material risk of duplicating laboratories, scarce specialist teams and public investment.
A federated model combines national consistency with the domain knowledge required for safe deployment in regulated sectors. It would mobilise mature infrastructure and industry networks faster, preserve accountability and avoid implying an exclusive entitlement to future funding. It also reflects the Strategy’s own principles of shared services, interoperability and reduced fragmentation.
Supporting evidence: CMMI institutional profile (https://www.cmmi.blue/who-we-are/) | European CoE cooperation (https://www.cmmi.blue/signature-of-a-memorandum-of-understanding-mou-between-centres-of-excellence-cmmi-coe-marble-inesctec-ocean/)
__________________________________________________________________________
COMMENT 3: Fund infrastructure through mature, stage-gated business plans
Article and paragraph to which the comment refers: Section 3.3, “Governance and Controls” → “Roles, Accountability and Decision-making” (paragraph on budget allocations); Section 3.7.2, “Compute Capacity and Access”; Section 3.10.3, “Funding and Renewal Model”; Section 3.11.4, “Learning and Continuous Development”; Chapter 5, items 2–4 on funding, innovation infrastructure and industry readiness.
Comment / Suggestion: Add an Investment and Sustainability Framework governing allocations across the Strategy’s six research focus areas, sector missions, data spaces and enabling infrastructure. Begin with a national map of assets, capabilities, utilisation and gaps; prioritise the upgrade or federation of existing assets where this offers better value than parallel facilities.
Every material infrastructure or Centre-of-Excellence proposal should require an independently reviewed, phased business and implementation plan covering demonstrated demand; beneficiaries and public value; relationship to existing assets; capital and multi-year operating costs; total cost of ownership and renewal; staffing; governance and open-access model; pricing and cost recovery; liability and insurance; cybersecurity and environmental impact; procurement, State-aid and regulatory compliance; European and private co-financing; milestones, KPIs and go/no-go, consolidation or decommissioning criteria.
Create a preparatory funding window for feasibility studies and mature business plans, together with a dedicated investment line for shared sectoral testing, validation and assurance infrastructure. Funding must cover safe operation, maintenance, data stewardship and affordable SME and public-authority access—not equipment acquisition alone.
Justification: The Strategy identifies several funds and facilities but does not define a common method for comparing investments or financing their full lifecycle. Testbeds are service infrastructures: without predictable operating resources, specialist staff and renewal, capital expenditure can produce underused or stranded assets.
A stage-gated portfolio approach would improve value for money, make resource allocation transparent and allow underperforming initiatives to be adapted or stopped. It would also enable CMMI to mature one integrated maritime investment case around CyMON, the MARTA concept, MDigi-I, EONIOS and expanded laboratories for the forthcoming DMRIDP Investment Pillar, while exposing the proposal to the same objective tests as every other national investment.
Supporting evidence: MDigi-I infrastructure (https://www.mdigii.eu/the-project) | CMMI research-infrastructure access (https://www.cmmi.blue/cmmi-research-infrastructure-access/)
__________________________________________________________________________
COMMENT 4: Operationalise the Trusted Maritime Data Space
Article and paragraph to which the comment refers: Sections 3.2.1, “Strategic Role of Data”, 3.2.3, “Interoperability and Secure Data Sharing”, and 3.2.5, “Capability and Infrastructure” (including “National Intelligent Digital API Fabric”); Annex C, “Shipping and Maritime” → “Implementation, evidence and compliance” (paragraph beginning “To enable these capabilities…”) and “Flagship programme(s)”.
Comment / Suggestion: Convert the commitment to a Trusted Maritime Data Space into an implementation specification for a federated, standards-based and European-interoperable maritime data ecosystem. The Strategy should define the accountable authority and operator or trustee; stakeholder governance; participation incentives and decision rights; data licences and permitted uses; commercial confidentiality and intellectual-property safeguards; provenance, quality and common metadata; secure APIs; role-based access, retention, audit and withdrawal rules; and cybersecurity controls.
The design should support secure processing environments, federated analytics and learning, synthetic data and other privacy-preserving approaches where anonymisation or central pooling is unsuitable. It should connect with the National Intelligent Digital API Fabric and relevant European data initiatives. Priority datasets should support vessels, ports, maintenance, inspection, trials, metocean conditions, emissions, incidents, safety, pollution response and marine environmental monitoring. Non-sensitive results of publicly funded trials should be reusable for research and public-interest purposes.
Justification: Maritime operational data are distributed among ships, companies, ports, public authorities and research infrastructures; they are often commercially sensitive, safety-critical and difficult to anonymise without losing utility. The current formulation—company contributions of anonymised datasets for national model training—is therefore too narrow and may not earn industry trust.
A governed federated model would allow algorithms to learn from protected data without requiring organisations to surrender commercial know-how. It would also provide SMEs, authorities and researchers with trusted reference data for digital twins, maintenance, routing, regulatory support and autonomous-system validation. CyMON’s data architecture and EMODnet relationship, together with MDigi-I, provide practical seed capabilities.
Supporting evidence: CyMON and EMODnet (https://www.cmmi.blue/cmmi-becomes-an-associated-member-of-the-european-marine-observation-and-data-network/) | MDigi-I Hub (https://www.mdigii.eu/)
__________________________________________________________________________
COMMENT 5: Add marine public-interest and environmental missions
Article and paragraph to which the comment refers: Section 3.5, priority sector 7, “Shipping and Maritime”; Annex C, “Shipping and Maritime”; Annex D, “Focus Area 1: Energy, Environment and Resource Management”, “Focus Area 2: Autonomous Systems”, and “Focus Area 4: Security, Defence and Space”.
Comment / Suggestion: Expand the Shipping and Maritime pillar beyond fleet and ship-management productivity to include marine and blue-economy missions of direct public value. Add explicit priorities for maritime situational awareness and search and rescue; oil-spill, chemical-pollution, illegal-discharge and marine-litter detection, forecasting and response; navigational and port safety; inspection of coastal and subsea critical infrastructure; marine ecosystem, biodiversity and climate monitoring; sustainable aquaculture; and support for emergency-response authorities.
Add to Annex D, Focus Area 1: “AI-enabled marine and coastal environmental monitoring, including detection, forecasting, source attribution and response support for pollution and ecosystem stress, integrating Earth observation, airborne platforms, fixed and mobile sensors, autonomous surface and underwater systems, and digital twins.”
Where missions are dual-use, require proportionality, human command authority, access and data-classification controls, auditability, cyber-adversarial testing, applicable export controls, fundamental-rights safeguards and protection of the marine environment.
Justification: The current maritime pillar concentrates mainly on fuel efficiency, predictive maintenance, compliance and logistics. For an island state, maritime AI also affects human life, environmental protection, food systems, coastal communities and national resilience. The environmental research priorities list wildfire, air, water scarcity, grids and buildings but omit the marine environment.
This addition would link Research Focus Areas 1, 2 and 4, create shared civil-security uses for expensive sensing and validation infrastructure, and ensure visible public benefit. It can build on the Shipping Deputy Ministry’s pollution-monitoring direction and CMMI capabilities including CyMON, MDigi-I, iMERMAID and the EONIOS demonstrated concept.
Supporting evidence: CMMI iMERMAID pollution monitoring (https://www.cmmi.blue/imermaid/) | CMMI marine observation (https://www.cmmi.blue/the-cyprus-marine-observation-network/)
__________________________________________________________________________
COMMENT 6: Create a domain-specific marine autonomy assurance framework
Article and paragraph to which the comment refers: Section 3.3.2, “Control Framework”; Annex B, “AI Use Case Lifecycle and Control Gates”; Section 4.3, “AI Governance Enablers” → “National AI Compliance Framework”; Annex C, “Shipping and Maritime” → “International alignment” and “Flagship programme(s)”; Annex D, Focus Areas 2 and 4; Section 3.11.2, paragraph referring to ISO 42001 and ISO 27001.
Comment / Suggestion: Develop a Marine Autonomous Systems Assurance Framework under the National AI Compliance Framework and testbed programme. It should define operational design domains, scenario libraries, performance measures and acceptance criteria; safety-case templates; human supervisory control, intervention and abort mechanisms; collision-avoidance behaviour; operation under communications, navigation and sensor degradation; perception uncertainty; cyberattack resilience; multi-agent and swarm behaviour; logging, traceability and incident reporting; and environmental effects.
The framework should layer the EU AI Act where applicable with maritime safety, security, environmental and operational law and standards. It should be co-designed with competent maritime, port, AI, cybersecurity, data-protection, defence and emergency authorities, together with classification and standards bodies, insurers, operators, research organisations and Centres of Excellence. Reusable evidence packages should support procurement, trial authorisation, regulatory review, classification, insurance and cross-border trials.
Clarify that ISO 42001 and ISO 27001 can support governance and security evidence but do not, by themselves, establish compliance with the EU AI Act or maritime-sector legislation.
Justification: Marine autonomous systems are cyber-physical systems operating in variable, safety-critical environments and across overlapping legal regimes. General AI control gates or a regulatory sandbox cannot alone demonstrate safe navigation, resilient remote operations, adequate human control or acceptable environmental performance.
The timing is strategic: the IMO adopted the non-mandatory MASS Code in May 2026, effective from 1 July 2026, and plans an experience-building phase on the route to a mandatory code expected to enter into force in 2032. A Cyprus assurance and test programme could generate credible evidence during that transition, reducing uncertainty for regulators, developers, operators and insurers while distinguishing Cyprus as a trusted European validation location.
Supporting evidence: IMO MASS Code, 22 May 2026 (https://www.imo.org/en/mediacentre/pressbriefings/pages/imo-adopts-mass-code.aspx) | EU AI Act (https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng)
__________________________________________________________________________
COMMENT 7: Set credible maritime KPIs and correct material inconsistencies
Article and paragraph to which the comment refers: Section 3.11, “Measuring Impact and National KPIs”; Annex C, “Shipping and Maritime” → “Strategic objectives and 2032 target”, “Shipping and Maritime Pillar – What this pillar is expected to deliver”, and Figure 11; Annex F, “National KPIs and Measurement Framework”.
Comment / Suggestion: Replace or qualify promotional superlatives and aggregate savings estimates with baseline-defined, independently verifiable outcomes. By 2027, establish for each maritime KPI a baseline, scope, data source, method, accountable owner, target, reporting frequency and independent evaluation route. Report results by use case and user group rather than implying uniform sector-wide effects.
The maritime scorecard should cover verified fuel, emissions, downtime and maintenance outcomes; safety incidents and near-misses; systems and scenarios independently tested; authorised trial hours; time and cost to produce validation evidence; progression from testing to supervised trial, deployment or export; SME, research and public-authority access; use of datasets and shared services; specialised personnel trained; EU and private co-investment; and public-interest outcomes such as pollution alerts, search-and-rescue support and environmental coverage.
Before final adoption, align the maritime text and figures: reconcile the 2032 target with Figure 11’s 2035 date; repair the interrupted “Strategic objectives” paragraph and remove the unrelated sentence on personalisation and citizen experience; standardise Centre-of-Excellence and Infrastructure Council/Committee names; and replace tertiary sources with primary official data where available.
Justification: The Strategy’s outcomes-focused approach is sound, but its maritime annex presents 10–20% fuel savings and 30–40% maintenance-cost reductions without defining baselines, attribution or verification. It also describes a 2032 ambition while Figure 11 states 2035. These weaknesses can misdirect investment and undermine confidence in otherwise valuable priorities.
A transparent scorecard would connect public funding to accessibility, safety, environmental and economic outcomes, not merely pilot counts. Correcting the visible textual and institutional inconsistencies would improve legal and operational clarity and strengthen the Strategy’s credibility with industry, European partners and citizens.
Παρατηρήσεις του ΚΕΒΕ επί της Προτεινόμενης Εθνικής Στρατηγικής για την Τεχνητή Νοημοσύνη
Το ΚΕΒΕ θεωρεί ότι το προτεινόμενο Σχέδιο Δράσης για την Τεχνητή Νοημοσύνη είναι ιδιαίτερα φιλόδοξο και αντανακλά τη δέσμευση για την προώθηση του ψηφιακού μετασχηματισμού της κυπριακής οικονομίας. Ωστόσο, θεωρούμε ότι ορισμένα σημαντικά ζητήματα χρήζουν περαιτέρω ανάλυσης και διευκρίνισης, προκειμένου να διασφαλιστεί η αποτελεσματική και χωρίς αποκλεισμούς υλοποίηση της στρατηγικής.
Καταρχάς, θα ήταν χρήσιμο να εξεταστεί η εντονότερη ανάδειξη και ενσωμάτωση των τομέων του εμπορίου και της ενέργειας, οι οποίοι αναμένεται να επηρεαστούν άμεσα και ουσιαστικά από την εφαρμογή τεχνολογιών τεχνητής νοημοσύνης. Δεδομένης της σημασίας των συγκεκριμένων τομέων για την κυπριακή οικονομία, κρίνεται αναγκαία η σαφέστερη ενσωμάτωσή τους στο πλαίσιο του Σχεδίου Δράσης.
Παράλληλα, παρότι γίνεται αναφορά στις μικρομεσαίες επιχειρήσεις (ΜμΕ), δεν λαμβάνονται επαρκώς υπόψη οι ιδιαίτερες ανάγκες των πολύ μικρών επιχειρήσεων (micro-enterprises), οι οποίες αποτελούν τη συντριπτική πλειονότητα των επιχειρήσεων στην Κύπρο. Οι επιχειρήσεις αυτές αντιμετωπίζουν διαφορετικές προκλήσεις σε σχέση με τις μεγαλύτερες ΜμΕ και, ως εκ τούτου, απαιτούν στοχευμένα μέτρα και εξατομικευμένη υποστήριξη για την υιοθέτηση και αξιοποίηση των εφαρμογών τεχνητής νοημοσύνης.
Επιπρόσθετα, θα ήταν χρήσιμο να παρουσιαστούν με μεγαλύτερη σαφήνεια τα βήματα που προβλέπονται για την ανάπτυξη των απαραίτητων υποδομών που θα στηρίξουν την εφαρμογή του Σχεδίου. Θα ήταν χρήσιμο να παρουσιαστούν με μεγαλύτερη σαφήνεια το χρονοδιάγραμμα, οι προβλεπόμενες επενδύσεις και η πρακτική υλοποίηση των σχετικών δράσεων. Παρόλο που γίνεται αναφορά σε εθνικές υποδομές AI και υπολογιστικής ισχύος, θα ήταν χρήσιμο να παρουσιαστούν πιο συγκεκριμένες πληροφορίες για τη χωρητικότητα, το χρονοδιάγραμμα και την επάρκεια των υποδομών που θα απαιτηθούν. Παράλληλα, θα ήταν χρήσιμο να παρουσιαστούν εκτιμήσεις σχετικά με τις απαιτούμενες δυνατότητες και τη χωρητικότητα των εν λόγω υποδομών, καθώς και αξιολόγηση του κατά πόσο οι υφιστάμενες υποδομές της χώρας μπορούν να ανταποκριθούν στις ανάγκες που αναμένεται να προκύψουν από την υλοποίηση του Σχεδίου.
Το ΚΕΒΕ θεωρεί ιδιαίτερα σημαντικό να διασφαλιστεί η ουσιαστική συμμετοχή των αντιπροσωπευτικών φορέων της επιχειρηματικής κοινότητας και ιδιαίτερα των οργανισμών που εκπροσωπούν τις ΜμΕ στις προτεινόμενες δομές διακυβέρνησης, παρακολούθησης και αξιολόγησης της Στρατηγικής, ώστε να διασφαλίζεται η συστηματική μεταφορά της εμπειρίας και των αναγκών της αγοράς κατά την εφαρμογή και αξιολόγησή της.
Επιπρόσθετα, θεωρούμε ότι θα ήταν χρήσιμο να παρουσιαστεί με μεγαλύτερη σαφήνεια η τεκμηρίωση και η μεθοδολογία βάσει των οποίων καθορίστηκαν οι ποσοτικοί στόχοι και οι βασικές κατευθύνσεις της Στρατηγικής. Παρόλο που γίνεται αναφορά σε διεθνείς και ευρωπαϊκούς δείκτες, θα ήταν χρήσιμο να παρουσιαστεί συνοπτικά η τεκμηρίωση, οι παραδοχές και τα δεδομένα που λήφθηκαν υπόψη κατά τον καθορισμό των ποσοτικών στόχων, καθώς και η ανάλυση που αποτυπώνει την υφιστάμενη κατάσταση, τον βαθμό ετοιμότητας και τις πραγματικές ανάγκες των κυπριακών επιχειρήσεων και της οικονομίας γενικότερα.
Η διευκρίνιση των στοιχείων, των παραδοχών και της μεθοδολογίας που οδήγησαν στον καθορισμό ιδιαίτερα φιλόδοξων στόχων, όπως η ευρεία υιοθέτηση της Τεχνητής Νοημοσύνης σε επιλεγμένους τομείς, η σημαντική αύξηση της παραγωγικότητας και η ανάπτυξη χιλιάδων επαγγελματιών Τεχνητής Νοημοσύνης, θα ενίσχυε την αξιοπιστία, τη διαφάνεια και την πρακτική εφαρμοσιμότητα της Στρατηγικής, ενώ θα διευκόλυνε και την αξιολόγηση της προόδου κατά την υλοποίησή της.
Το ΚΕΒΕ χαιρετίζει την πρόβλεψη συνεργατικών μηχανισμών και τη σαφή αναγνώριση της σημασίας της συμμετοχής της βιομηχανίας, των επιχειρήσεων και των ΜμΕ στην υλοποίηση της Εθνικής Στρατηγικής Τεχνητής Νοημοσύνης. Εντούτοις, θεωρεί ότι η συμμετοχή των αντιπροσωπευτικών επιχειρηματικών φορέων θα μπορούσε να ενισχυθεί περαιτέρω και να αποκτήσει σαφέστερο θεσμικό και λειτουργικό ρόλο στο πλαίσιο εφαρμογής της Στρατηγικής.
Προς τούτο, εισηγούμαστε τη θεσμοθέτηση μόνιμων μηχανισμών διαβούλευσης και συμμετοχής των επιχειρηματικών φορέων στα αρμόδια συμβουλευτικά και συντονιστικά όργανα της Στρατηγικής, ώστε να αξιοποιείται συστηματικά η εμπειρία της αγοράς, να αναδεικνύονται έγκαιρα οι ανάγκες των επιχειρήσεων και να ενισχύεται η αποτελεσματικότητα των σχετικών δράσεων. Παράλληλα, θα πρέπει να διασφαλιστεί η ενεργός συμμετοχή των επιχειρηματικών φορέων στη διαμόρφωση των προγραμμάτων στήριξης και κατάρτισης, καθώς και στον σχεδιασμό, την υποστήριξη και την υλοποίηση δράσεων ενημέρωσης, ευαισθητοποίησης και υποστήριξης των ΜμΕ.
Επιπρόσθετα, θα ήταν χρήσιμο να εξεταστεί η δυνατότητα αξιοποίησης των οργανωμένων επιχειρηματικών φορέων ως ενδιάμεσων οργανισμών διάχυσης γνώσης, κατάρτισης και υποστήριξης των ΜμΕ, μέσω κατάλληλων συνεργατικών σχημάτων, προγραμμάτων στήριξης ή άλλων μηχανισμών που θα διευκολύνουν την αποτελεσματική μεταφορά γνώσης και τεχνογνωσίας προς τις επιχειρήσεις. Οι φορείς αυτοί μπορούν να λειτουργήσουν ως κρίσιμος σύνδεσμος μεταξύ κράτους και επιχειρήσεων για την προώθηση της υιοθέτησης της Τεχνητής Νοημοσύνης, ιδιαίτερα από τις ΜμΕ.
Δεδομένου ότι η επιτυχία της Στρατηγικής θα εξαρτηθεί σε μεγάλο βαθμό από τον βαθμό υιοθέτησης της Τεχνητής Νοημοσύνης από τις επιχειρήσεις και ιδιαίτερα τις ΜμΕ, θεωρούμε σημαντικό η επιχειρηματική κοινότητα να αποτελεί ενεργό εταίρο τόσο στον σχεδιασμό όσο και στην υλοποίηση των σχετικών δράσεων.
Επιπρόσθετα, θεωρούμε ότι η Στρατηγική θα ενισχυόταν περαιτέρω εάν συνοδευόταν από ένα ενδεικτικό χρηματοδοτικό πλάνο, το οποίο να παρουσιάζει το εκτιμώμενο κόστος υλοποίησης των βασικών δράσεων, τις πιθανές πηγές χρηματοδότησης και την ενδεικτική κατανομή πόρων ανά πυλώνα παρέμβασης. Η ύπαρξη ενός τέτοιου πλαισίου θα συνέβαλλε στην καλύτερη αξιολόγηση της εφικτότητας των προτεινόμενων μέτρων και των ιδιαίτερα φιλόδοξων στόχων της Στρατηγικής, καθώς και στην αποτελεσματικότερη παρακολούθηση της υλοποίησής της.
Τέλος, ενώ η Στρατηγική περιλαμβάνει συγκεκριμένους και φιλόδοξους ποσοτικούς στόχους αναφορικά με την υιοθέτηση της Τεχνητής Νοημοσύνης, την παραγωγικότητα, την ανάπτυξη δεξιοτήτων και την κατάρτιση του ανθρώπινου δυναμικού, θα μπορούσε να εξεταστεί η συμπερίληψη πρόσθετων δεικτών που να αποτυπώνουν τον βαθμό συνεργασίας μεταξύ δημόσιου και ιδιωτικού τομέα στο πλαίσιο εφαρμογής της Στρατηγικής. Ενδεικτικά, οι δείκτες αυτοί θα μπορούσαν να αφορούν τον αριθμό θεσμοθετημένων διαβουλεύσεων με την επιχειρηματική κοινότητα, τη συμμετοχή φορέων της αγοράς σε δράσεις υλοποίησης της Στρατηγικής, τον αριθμό επιχειρήσεων που προσεγγίζονται μέσω οργανωμένων δικτύων υποστήριξης και την αξιοποίηση συνεργατικών μηχανισμών για τη στήριξη των ΜμΕ.
Συνοπτικά, το ΚΕΒΕ υποστηρίζει τους στόχους του προτεινόμενου Σχεδίου Δράσης για την Τεχνητή Νοημοσύνη. Ωστόσο, θεωρεί ότι απαιτείται μεγαλύτερη έμφαση στις ανάγκες των πολύ μικρών επιχειρήσεων, στους τομεακούς αντίκτυπους, στις απαραίτητες υποδομές, στη συμμετοχή των βασικών ενδιαφερόμενων μερών και στην τεκμηριωμένη διακυβέρνηση, ώστε να διασφαλιστεί η επιτυχής εφαρμογή και η μακροπρόθεσμη αποτελεσματικότητα της στρατηγικής.
CCCI Comments on the Proposed National Artificial Intelligence Strategy
The CCCI considers that the proposed Artificial Intelligence Action Plan is highly ambitious and reflects a strong commitment to advancing the digital transformation of the Cypriot economy. However, we believe that certain important issues warrant further analysis and clarification in order to ensure the effective and inclusive implementation of the Strategy.
First, it would be beneficial to consider a stronger emphasis on and integration of the trade and energy sectors, which are expected to be directly and substantially affected by the deployment of artificial intelligence technologies. Given the importance of these sectors to the Cypriot economy, their clearer incorporation into the Action Plan is considered necessary.
At the same time, although the Strategy refers to small and medium-sized enterprises (SMEs), it does not sufficiently address the specific needs of micro-enterprises, which constitute the overwhelming majority of businesses in Cyprus. These enterprises face challenges that differ from those of larger SMEs and therefore require targeted measures and tailored support to facilitate the adoption and effective use of artificial intelligence applications.
Furthermore, it would be useful to provide greater clarity regarding the steps foreseen for the development of the infrastructure necessary to support the implementation of the Strategy. Additional information on the timeline, expected investments, and practical implementation of the relevant actions would be beneficial. While reference is made to national AI infrastructure and computing capacity, more specific information regarding the capacity, timeline and adequacy of the required infrastructure would be valuable. In addition, it would be useful to provide estimates concerning the required capabilities and capacity of such infrastructure, as well as an assessment of whether the country’s existing infrastructure will be able to meet the demands expected to arise from the implementation of the Strategy.
CCCI considers it particularly important to ensure the meaningful participation of representative business organisations, especially those representing SMEs, in the proposed governance, monitoring and evaluation structures of the Strategy, so as to facilitate the systematic transfer of market knowledge and business needs throughout its implementation and evaluation.
In addition, we believe that greater clarity should be provided regarding the evidence base and methodology used in determining the quantitative targets and overall direction of the Strategy. Although reference is made to international and European indicators, it would be helpful to present, in summary form, the evidence, assumptions and data considered when establishing the quantitative targets, as well as the analysis reflecting the current situation, the level of preparedness and the actual needs of Cypriot businesses and the economy more broadly.
Clarifying the evidence, assumptions and methodology underpinning highly ambitious targets, such as the widespread adoption of Artificial Intelligence across selected sectors, significant productivity gains and the development of thousands of AI professionals, would further strengthen the credibility, transparency and practical applicability of the Strategy, while also facilitating the monitoring and evaluation of progress during its implementation.
CCCI welcomes the inclusion of collaborative mechanisms and the clear recognition of the importance of involving industry, businesses and SMEs in the implementation of the National Artificial Intelligence Strategy. Nevertheless, we believe that the participation of representative business organisations could be further strengthened and provided with a clearer institutional and operational role within the implementation framework of the Strategy.
To this end, we propose the establishment of permanent consultation and participation mechanisms for business organisations within the relevant advisory and coordination bodies of the Strategy, so that market expertise can be systematically utilised, business needs identified at an early stage, and the effectiveness of the relevant initiatives enhanced. At the same time, the active involvement of business organisations should be ensured in the design of support and training programmes, as well as in the planning, support and implementation of awareness-raising, outreach and SME support initiatives.
Furthermore, consideration could be given to leveraging organised business organisations as intermediary bodies for the dissemination of knowledge, training and support to SMEs through appropriate collaborative schemes, support programmes or other mechanisms that facilitate the effective transfer of know-how and expertise to businesses. Such organisations can serve as a critical link between government and the business community in promoting the adoption of Artificial Intelligence, particularly among SMEs.
Given that the success of the Strategy will largely depend on the degree of AI adoption by businesses, and SMEs in particular, we consider it important for the business community to be an active partner both in the design and implementation of the relevant actions.
In addition, we believe that the Strategy would be further strengthened if it were accompanied by an indicative financing plan outlining the estimated implementation costs of the key actions, potential sources of funding, and an indicative allocation of resources across the various pillars of intervention. Such a framework would contribute to a more informed assessment of the feasibility of the proposed measures and ambitious targets, while also supporting more effective monitoring of implementation.
Finally, while the Strategy includes specific and ambitious quantitative targets regarding AI adoption, productivity, skills development and workforce training, consideration could be given to the inclusion of additional indicators that capture the level of cooperation between the public and private sectors in the implementation of the Strategy. Indicative indicators could include the number of institutionalized consultations with the business community, the participation of market stakeholders in implementation activities, the number of businesses reached through organised support networks, and the use of collaborative mechanisms aimed at supporting SMEs.
In conclusion, CCCI supports the objectives of the proposed Artificial Intelligence Action Plan. However, we believe that greater emphasis should be placed on the needs of micro-enterprises, sector-specific impacts, the required infrastructure, stakeholder participation and evidence-based governance, in order to ensure the successful implementation and long-term effectiveness of the Strategy.
.