Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας
Υφυπουργείο Έρευνας, Καινοτομιας Και Ψηφιακής Πολιτικής
Ανακοινώνεται η έναρξη Δημόσιας Διαβούλευσης της Εθνικής Στρατηγικής για την Τεχνητή Νοημοσύνη (ΤΝ), που εκπονήθηκε από την Εθνική Εξειδικευμένη Επιτροπή για την Τεχνητή Νοημοσύνη (National AI Taskforce), η οποία συστάθηκε με Απόφαση του Υπουργικού Συμβουλίου (αρ. απόφασης 97.538, ημερ. 22/1/2025), υπό την προεδρία του Επικεφαλής Επιστήμονα για Έρευνα, Καινοτομία και Τεχνολογία, και με έντεκα (11) μέλη προερχόμενα από τον δημόσιο και ιδιωτικό τομέα, την ακαδημαϊκή και ερευνητική κοινότητα.
Η Στρατηγική αποτελεί το ολοκληρωμένο εθνικό πλαίσιο πολιτικής της Κυπριακής Δημοκρατίας για την αξιοποίηση των δυνατοτήτων της ΤΝ, με όραμα, έως το 2032, η Κύπρος να αναγνωρίζεται ως ο αξιόπιστος κόμβος ΤΝ στην Ανατολική Μεσόγειο, ως μια αξιόπιστη ευρωπαϊκή δικαιοδοσία για την παροχή υπηρεσιών που αξιοποιούν την ΤΝ και ως γέφυρα μεταξύ της Ευρωπαϊκής Ένωσης και των γειτονικών περιοχών.
H Στρατηγική αναπτύσσεται γύρω από 8 αλληλένδετους Εθνικούς Στρατηγικούς Στόχους:
- Καθιέρωση της Κύπρου ως αξιόπιστης δικαιοδοσίας για την ΤΝ.
- Αύξηση της εθνικής παραγωγικότητας μέσω της υπεύθυνης υιοθέτησης της ΤΝ.
- Ανάπτυξη ενός ισχυρού και χωρίς αποκλεισμούς οικοσυστήματος ΤΝ.
- Μετασχηματισμό των δημόσιων υπηρεσιών μέσω της αξιοποίησης της ΤΝ.
- Ανάπτυξη, προσέλκυση και διατήρηση δεξιοτήτων και ανθρώπινου δυναμικού στον τομέα της ΤΝ.
- Διασφάλιση ασφαλών, κυρίαρχων και διαλειτουργικών δεδομένων και υποδομών.
- Εδραίωση ισχυρής διακυβέρνησης, δεοντολογίας και λογοδοσίας σε κάθε χρήση της ΤΝ.
- Ανάπτυξη κυρίαρχων εθνικών δυνατοτήτων μέσω στρατηγικών συνεργασιών.
Το προσχέδιο της Εθνικής Στρατηγικής για την ΤΝ βρίσκεται αναρτημένο πιο κάτω και καλούνται όλοι οι ενδιαφερόμενοι να υποβάλουν τα σχόλια, εισηγήσεις και παρατηρήσεις τους μέσω της πλατφόρμας «η-Διαβούλευση» μέχρι την 31η Αυγούστου 2026.
Όλες οι απόψεις και προτάσεις που θα υποβληθούν θα αξιολογηθούν και, όπου κριθεί σκόπιμο, θα ενσωματωθούν στην τελική έκδοση της Στρατηγικής.
Παράκληση όπως τα σχόλια γίνονται σύμφωνα με την πιο κάτω δομή:
Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο
Σχόλιο / Εισήγηση
Αιτιολόγηση σχολίου / Εισήγησης
Για οποιεσδήποτε διευκρινίσεις σχετικά με τη διαδικασία της διαβούλευσης, μπορείτε να επικοινωνείτε με το Υφυπουργείο Έρευνας, Καινοτομίας και Ψηφιακής Πολιτικής.
- Ανοικτή
- Αναρτήθηκε
20 Ιούλ 2026 @ 0:00 - Ανοικτή σε σχόλια ως
31 Αυγ 2026 @ 23:50 - 89 σχόλια
Περιεχόμενα
| 01 - ΕΘΝΙΚΗ ΣΤΡΑΤΗΓΙΚΗ ΓΙΑ ΤΗΝ ΤΕΧΝΗΤΗ ΝΟΗΜΟΣΥΝΗ ΤΗΣ ΚΥΠΡΙΑΚΗΣ ΔΗΜΟΚΡΑΤΙΑΣ | 6 σχόλια |
This comprehensive, cohesive, and ambitious strategic document captures the vision for the development, utilization, and responsible governance of Artificial Intelligence in Cyprus, aligning with European developments to establish a strong framework for digital transformation and public service upgrading. With the aim of further enhancing the effectiveness, implementability, and long-term sustainability of the Strategy with regard to the healthcare pillar, the following observations are submitted:
The healthcare pillar should explicitly include the use of AI for fraud, waste and abuse detection, including anomalous claims identification, provider behavioural analytics, prescription abuse detection, organised fraud networks, and real-time risk scoring. These capabilities contribute directly to the financial sustainability of the healthcare system and the efficient use of public funds.
The healthcare pillar should also be expanded to explicitly include AI for population health management, disease prevention, and healthcare system sustainability, including the identification of at-risk populations, healthcare demand forecasting, chronic disease management, and population health analytics. While the Strategy focuses on clinical care and research, AI can also play a significant role in improving population health outcomes, supporting evidence-based policymaking, and ensuring the long-term sustainability of the General Healthcare System through preventive and proactive interventions.
The National AI Strategy sets an ambitious vision for Cyprus. To strengthen it further, the strategy should move from a vision-led document to an execution-led national programme. This means clearly defining how the vision will be achieved, who will execute it, how progress will be measured, what budget is required, and how public and private adoption will be stimulated. The most important enhancement is to separate the long-term 2032 ambition from the implementation plan. For AI, a static long-term execution plan is likely to become outdated quickly. A more appropriate approach is a three-year execution cycle for 2026-2028, refreshed annually and then formally renewed for the next cycle. The strategy should also include a measurable KPI scorecard, a clear delivery roadmap, a RACI-style ownership model, an indicative funding model, and explicit alignment with Cyprus’s Digital Decade and DESI-related performance indicators.
1. Section 1.5, “Implementation Timeline and Success Metrics”
Suggestion: Introduce a rolling three-year implementation roadmap, supported by annual reviews and formal refresh points. Retain 2032 as the long-term national ambition, but divide implementation into shorter execution cycles. Each cycle should identify priority programmes, milestones, responsible entities, funding requirements, dependencies, expected benefits and measurable outcomes. The first cycle should concentrate on establishing governance, baseline indicators, procurement arrangements, enabling infrastructure, first-wave use cases and talent programmes.
Justification: The strategy currently combines short implementation periods with a broad 2026 to 2032 national rollout. A fixed long-term plan may not provide sufficient flexibility for a field experiencing rapid technological, regulatory and market change. A rolling approach would allow Cyprus to adjust priorities based on implementation experience, emerging technologies, EU requirements, available funding and demonstrated use-case value. It would also provide clearer short-term accountability while maintaining continuity with the 2032 vision. The enhanced recommendation note similarly proposes a three-year execution cycle with annual refreshes rather than treating the full period as a static implementation plan
2. Section 3.3, “Governance and Controls”
Suggestion: Include a detailed RACI and decision-rights model for the strategy’s governance and delivery bodies. For each major programme and control gate, the strategy should specify who is responsible for execution, accountable for the outcome, consulted before decisions and informed of progress. The model should cover the National AI Authority, the competent Deputy Ministry, the Interministerial AI Council, specialised committees, delivery bodies, ministries, regulators, municipalities, research institutions and private-sector participants.
Justification: The strategy establishes a three-tier governance model and identifies the National AI Authority, Interministerial AI Council and specialised committees. A complementary RACI would clarify how these bodies interact in practice, particularly where policy, technology, funding, regulation and service ownership overlap. It would reduce ambiguous ownership, duplicated activity and delayed decisions. It would also make escalation arrangements clearer and enable authorities to hold specific entities accountable for milestones, risks, expenditure and benefits.
3. Section 3.4, “AI Adoption Across Government”
Suggestion: Introduce a National AI Procurement Framework for all public-sector AI acquisitions and partnerships. The framework should contain model procurement documents, common technical and functional requirements, risk-based procurement routes, supplier evaluation criteria and standard clauses addressing data access, data residency, model transparency, auditability, cybersecurity, intellectual property, performance, portability, exit rights and vendor lock-in. It should also require relevant AI impact, data protection, security and value assessments before procurement approval.
Justification: The strategy embeds compliance from the earliest stages of design, procurement and operation and calls for AI systems to be explainable, auditable, secure and resilient. A common procurement framework would apply these principles consistently across ministries and agencies rather than requiring each organisation to develop requirements independently. The previous recommendation note specifically identifies procurement discipline as important to avoiding fragmented, vendor-led adoption and inconsistent risk allocation. Standardisation would shorten preparation time, improve comparability of supplier proposals, strengthen contractual protection and support more consistent compliance across the public sector.
4. Section 3.4.4, “Shared Capabilities and Reuse”
Suggestion: Create a Sovereign AI Marketplace for approved and reusable AI assets. The marketplace should operate as a controlled catalogue containing reusable AI models, agents, prompts, APIs, data products, reference architectures, procurement clauses, testing methods, compliance templates and assurance evidence. Each asset should have a named owner, approved use conditions, risk classification, version history, support model and maintenance responsibilities.
Justification: The strategy promotes shared national capability, interoperability and reusable foundations, but an explicit marketplace would provide the mechanism through which reuse takes place. A controlled catalogue would support a “build once, reuse where appropriate” model, allowing ministries and potentially municipalities to adopt validated components rather than repeatedly procuring or developing similar solutions. The existing recommendation note proposes linking marketplace assets to the AI registry and compliance framework. This would reduce duplication, accelerate deployment, improve consistency and increase the return generated from public investment in AI components.
5. Section 3.11 and Annex F, “Measuring Impact and National KPIs”
Suggestion: Convert the KPI framework into a National AI Performance Scorecard with complete measurement governance. Every KPI should contain a definition, baseline, annual target, data source, responsible owner, reporting frequency, calculation method, dependencies and escalation threshold. The scorecard should distinguish activity indicators, such as training delivered or pilots launched, from outcome indicators, such as service improvement, productivity, adoption, trust, investment and realised financial or societal benefits.
Justification: The strategy identifies national impact, government and sector adoption, talent, trust and compliance as measurement areas and calls for regular monitoring and continuous improvement. The stated outcome metrics include productivity, GDP-related impact, professionals in the market and FDI attraction. A fully governed scorecard would make these indicators auditable and actionable. Clear baselines and ownership would show whether progress reflects actual improvement, while escalation thresholds would allow governance bodies to intervene when programmes are off track.
6. Section 5, “Immediate Steps for the Strategy Launch”
Suggestion: Add an explicit funding envelope and benefits-realisation model to the launch actions. The Government should define indicative funding by programme category, expected funding sources, responsible budget holders, project-level business-case requirements and arrangements for EU and private co-investment where appropriate. Every major initiative should identify expected financial, service, productivity, resilience or societal benefits and explain how these will be measured after deployment.
Justification: The strategy calls for multi-year investment with clear return-on-investment tracking and includes ambitious national outcomes. However, an explicit portfolio funding and benefits model would strengthen confidence that the ambition is financially and operationally deliverable. The supplementary recommendation note proposes identifying national-budget, EU co-funding and private co-investment opportunities and creating a benefits-realisation capability to track productivity, service quality and fiscal outcomes. This would support transparent prioritisation and allow funding to be directed to initiatives that demonstrate value.
7, Annex C, “Priority Sectors for Leadership”
Suggestion: Include Local Government as a distinct AI adoption and citizen-impact stream. The stream should cover municipal service requests, local-language citizen assistance, urban planning, waste and resource management, infrastructure maintenance, licensing and smart-city services. Municipalities should receive common guidance, access to reusable marketplace assets, implementation support and a controlled pilot-to-scale pathway.
Justification: Annex C concentrates on national priority sectors, while local authorities represent an important citizen-facing delivery layer. The existing recommendation note observes that municipalities can produce visible service improvements and proposes reusable solutions and selected pilots before wider scaling. A dedicated stream would reduce the likelihood of fragmented municipal procurements and unequal access to capability. It would also create opportunities to test practical, lower-complexity use cases close to citizens before considering broader adoption.
8. Sections 2.5.2, 2.5.3 and 3.5, “Productivity, Ecosystem and Priority Sectors”
Suggestion: Define sector-specific private-sector AI adoption targets and introduce practical adoption incentives. Targets should reflect the maturity and circumstances of tourism, professional services, shipping, healthcare, financial services and other priority areas. Supporting measures could include adoption vouchers, grants, test-before-invest facilities, regulatory sandboxes, advisory support, compute credits and skills subsidies, with simplified pathways for SMEs.
Justification: The strategy aims to increase national productivity and build an inclusive ecosystem in which SMEs and non-technology organisations can access AI capabilities, infrastructure and guidance. Explicit targets and incentives would convert this ambition into an investable adoption programme and make private-sector contribution to national outcomes measurable. The enhanced recommendation note specifically proposes grants, vouchers, tax incentives, sandboxes, advisory support, compute credits and skills subsidies. This would help address affordability, expertise and regulatory-readiness barriers, particularly for smaller organisations.
Η Στρατηγική συνολικά έιναι ένα αρκετά συνεκτικό και φιλόδοξο κείμενο, το οποίο καλύπτει ένα ευρύ φάσμα τομέων και πυλώνων. Το γεγονός ότι περιλαμβάνει πολλαπλές θεματικές διαστάσεις και επιχειρεί να συνδέσει την τεχνολογική ανάπτυξη με ζητήματα διακυβέρνησης, δεξιοτήτων, εκπαίδευσης, ασφάλειας, καινοτομίας και κοινωνικής διάστασης είναι θετικό στοιχείο.
Ένα γενικό σχόλιο που θα μπορούσε να ληφθεί υπόψη, αφορά τη συνοχή ως προς τον τρόπο συγγραφής και παρουσίασης των επιμέρους ενοτήτων. Παρατηρείται ότι ορισμένες ενότητες βασίζονται σε μεγάλο βαθμό σε εκτεταμένα bullet points και πιο συνοπτική παράθεση θέσεων, ενώ άλλες είναι γραμμένες με περισσότερο αναλυτικό, επαγγελματικό και ακαδημαϊκά τεκμηριωμένο τρόπο. Θα ήταν σωστό, να υπάρξει μεγαλύτερη ομοιομορφία σε ολόκληρο το κείμενο και να υιοθετηθεί ως βασική προσέγγιση το δεύτερο στυλ, δηλαδή η πιο αναλυτική, συνεκτική και τεκμηριωμένη παρουσίαση. Αυτό θα ενίσχυε τη συνολική ποιότητα, την αναγνωσιμότητα και την αξιοπιστία της Στρατηγικής και θα της προσέδιδε πιο ενιαίο και επαγγελματικό χαρακτήρα.
Τα ειδικότερα σχόλια και οι εισηγήσεις που ακολουθούν αφορούν κυρίως τις θεματικές της Εκπαίδευσης και της Ασφάλειας / Κυβερνοασφάλειας. Για λόγους συνέπειας με το ίδιο το κείμενο της Εθνικής Στρατηγικής, τα σχόλια παρατίθενται στην αγγλική γλώσσα, όπως είναι γραμμένη και η Στρατηγική.
Section 3.6 – Talent, Skills and Workforce Transformation and Annex C – Education and Human Capital Development
Comment / Suggestion:
Introduce a dedicated framework for the responsible adoption and use of AI in Higher Education. The framework should address teaching and learning, assessment redesign, academic integrity, AI-assisted research, student data protection, institutional governance, and the professional development of academic staff.
Justification of Comment / Suggestion:
Although the Strategy refers to lifelong AI learning extending from early schooling to higher education and professional life, the more detailed educational framework focuses mainly on school-age learners, particularly through CALF, which is structured around the age groups 6–8, 9–12, 13–15 and 16–18. Higher Education Institutions face distinct challenges related to generative AI, including assessment validity, academic integrity, research practices, institutional governance, staff competencies and student data protection. A specific Higher Education component would therefore strengthen the completeness of the national education framework.
Symeou, L., Louca, L., Kavadella, A., Mackay, J., Danidou, Y., & Raffay, V. (2025). Development of Evidence-Based Guidelines for the Integration of Generative AI in University Education Through a Multidisciplinary, Consensus-Based Approach. European Journal of Dental Education, 29(2), 285–303. https://doi.org/10.1111/EJE.13069
Annex C – Education and Human Capital Development – National Frameworks and Governance / CALF / EPVL
Comment / Suggestion:
Include specific provisions on assessment transformation and academic integrity in the age of generative AI. National guidance should address acceptable AI use in student work, disclosure of AI assistance, authorship, AI-supported assignments, authentic assessment, oral assessment, and mechanisms for maintaining academic integrity.
Justification of Comment / Suggestion:
The Strategy provides substantial guidance on AI literacy and teacher-mediated use of AI through CALF and EPVL, but does not sufficiently address how widespread generative AI use affects the validity and reliability of traditional assessment methods. Since assessment is a core component of educational quality assurance, national guidance would assist educational institutions in adapting assessment practices while enabling transparent and responsible AI use.
Section 3.6 – Talent, Skills and Workforce Transformation and Annex C – Education and Human Capital Development
Comment / Suggestion:
Establish a structured national AI professional development programme for teachers and academic staff with measurable participation and competency targets. Training should include pedagogical integration of AI, critical evaluation of AI-generated outputs, bias and misinformation detection, data protection, cybersecurity, assessment redesign, accessibility, ethics and responsible AI use.
Justification of Comment / Suggestion:
The Strategy recognises educators as key actors in the responsible integration of AI and places teachers at the centre of the proposed EPVL model. However, successful implementation requires systematic and continuous professional development rather than general AI awareness alone. Measurable training targets and competency requirements would support consistent implementation across the education system.
Section 3.6 – Talent, Skills and Workforce Transformation and Annex C – Education and Human Capital Development
Comment / Suggestion:
Clarify and strengthen the strategic role of universities and research organisations in the implementation of the education pillar. Their role could include contributing to CALF development, educator training, professional certification, evaluation of pilot initiatives, development of educational AI sandboxes, responsible AI research and independent assessment of educational outcomes.
Justification of Comment / Suggestion:
The Strategy promotes collaboration between government, academia and industry and recognises universities as part of the wider AI ecosystem. However, their operational role in the Education and Human Capital Development pillar could be defined more explicitly. Universities can provide research capacity, educational expertise, independent evaluation and specialised training, thereby supporting evidence-based implementation and continuous improvement.
Annex C – Education and Human Capital Development – Cyprus AI Literacy Framework (CALF)
Comment / Suggestion:
Explicitly integrate AI-related cybersecurity and digital safety competencies into CALF across all age groups. These should include, at age-appropriate levels, AI-enabled phishing, social engineering, deepfakes, voice cloning, misinformation, synthetic media manipulation, protection of personal and sensitive information, safe prompting and responsible use of generative AI systems.
Justification of Comment / Suggestion:
CALF already incorporates safe use, bias awareness, verification habits, data rights and responsible experimentation across different age groups. However, AI-related cybersecurity threats are becoming increasingly relevant to children, young people and educators. Explicit inclusion of these competencies would create a stronger link between AI literacy, digital literacy and cybersecurity awareness and would better prepare learners to recognise and respond to AI-enabled threats.
Annex C – Education and Human Capital Development – 2032 Adoption Target / KPIs
Comment / Suggestion:
Complement the proposed AI adoption target with outcome-based educational indicators. Suggested indicators include student AI literacy, educator AI competence, learning effectiveness, accessibility and inclusion, responsible AI use, number of AI-related misuse or safety incidents, equitable access and stakeholder trust.
Justification of Comment / Suggestion:
The Strategy proposes increasing AI adoption across education and labour to 75% by 2032. Adoption rates alone, however, do not demonstrate educational quality or positive learning outcomes. A broader KPI framework would ensure that increased use of AI is accompanied by measurable improvements in knowledge, skills, inclusion, safety and educational effectiveness.
Section 3.13 – Risk Management, Resilience and Adaptation, particularly Section 3.13.3 – Security and Threat Management
Comment / Suggestion:
Develop a unified National AI Security Framework consolidating minimum technical and organisational cybersecurity requirements across the AI lifecycle. The framework should apply from design and procurement through development, deployment, operation, monitoring and decommissioning.
Justification of Comment / Suggestion:
The Strategy already addresses cybersecurity, secure system design, access controls, continuous monitoring, threat intelligence and incident response. However, relevant security provisions are distributed across several sections of the Strategy. A consolidated framework would provide organisations with a clear baseline of minimum security requirements and support consistent implementation across public and private sectors.
Section 3.13.3 – Security and Threat Management and National AI Cybersecurity Centre of Excellence provisions
Comment / Suggestion:
Expand the AI threat model to explicitly address AI-specific cybersecurity threats. The Strategy could explicitly reference prompt injection, data poisoning, model poisoning, adversarial manipulation, model extraction, sensitive information leakage, insecure integrations, compromised AI supply chains and risks associated with autonomous or agentic AI systems.
Justification of Comment / Suggestion:
The Strategy appropriately recognises cyber threats, data breaches and model manipulation. Nevertheless, AI systems introduce attack vectors that differ from those affecting conventional information systems. Explicit recognition of these threats would enable more targeted security controls, testing requirements, incident-response capabilities and cybersecurity training.
Danidou, Y. (2025). ChatGPT, a Life-Changing Phenomenon with Cyber-Security Implications. EU Digital Law in the AI Era, 263–291. https://doi.org/10.1007/978-3-031-96743-6_14
Section 3.3.2 – Control Framework and Section 3.13 – Risk Management, Resilience and Adaptation
Comment / Suggestion:
Introduce mandatory AI security testing for high-risk and critical AI systems before deployment and periodically thereafter. Such testing could include adversarial testing, AI red teaming, vulnerability assessment, penetration testing of the wider AI-enabled environment and documented remediation of identified weaknesses.
Justification of Comment / Suggestion:
The Strategy already establishes risk-based controls, approval gates, ongoing monitoring, security guardrails, incident reporting and remediation. Explicitly requiring security testing and red teaming for high-risk or critical AI systems would operationalise the Strategy’s security-by-design principle and provide stronger assurance before systems are deployed in sensitive environments.
Section 3.12 – International Cooperation and EU Alignment, Section 3.13 – Risk Management, and relevant compliance provisions
Comment / Suggestion:
Strengthen the operational integration between the EU AI Act and cybersecurity-related regulatory frameworks, particularly NIS2, DORA and the Cyber Resilience Act. The Strategy could promote common mechanisms for risk assessment, incident management, assurance, governance and reporting where organisations are subject to multiple regulatory frameworks.
Justification of Comment / Suggestion:
The Strategy explicitly references the EU AI Act, GDPR, NIS2 and DORA. However, organisations in regulated and critical sectors may need to comply simultaneously with several frameworks. Greater operational alignment would reduce duplication, support regulatory consistency and help organisations establish integrated governance and compliance mechanisms. This should be addressed with the cooperation of the Digital Security Authority (DSA) of Cyprus and professionals in the cybersecurity/ NIS2/ DORA area.
Section 3.7 – Infrastructure, Compute and Digital Sovereignty, Section 3.3.2 – Control Framework, and procurement-related provisions
Comment / Suggestion:
Introduce a dedicated third-party and AI supply-chain risk management approach. Requirements should cover foundation models, cloud AI services, APIs, open-source components and external AI providers, including supplier security assurance, data location, access to logs, vulnerability disclosure, incident notification, model changes and updates, portability and exit strategies.
Justification of Comment / Suggestion:
National AI adoption will inevitably depend to some extent on external technologies, cloud providers, foundation models and software components. These dependencies create security, resilience, sovereignty and continuity risks. A specific third-party AI risk framework would complement the Strategy’s emphasis on sovereign capability and secure infrastructure and would strengthen procurement and lifecycle governance.
Section 3.11.2 – National Key Performance Indicators
Comment / Suggestion:
Include specific national AI cybersecurity KPIs in addition to general compliance and trust indicators. These could include the percentage of high-risk AI systems security-assessed before deployment, the percentage of critical AI systems subjected to red teaming, the number and severity of AI-related security incidents, mean detection and response times, the percentage of critical AI suppliers security-assessed, and the number of professionals trained or certified in AI cybersecurity.
Justification of Comment / Suggestion:
The Strategy already provides national KPIs covering adoption, productivity, skills, compliance, trust and public confidence and recommends ISO 42001/ISO 27001 for relevant systems. However, cybersecurity maturity cannot be adequately measured solely through general compliance indicators. Dedicated cybersecurity KPIs would allow progress to be monitored objectively and would support evidence-based improvement of national AI security capabilities.
Section 3.6 – Talent, Skills and Workforce Transformation, Annex C – Education and Human Capital Development, and Section 3.13 – Risk Management, Resilience and Adaptation
Comment / Suggestion:
Strengthen the intersection between Education and Cybersecurity by establishing AI security literacy as a horizontal national competence. Citizens, students, educators, public servants and professionals should be equipped not only to use AI effectively and ethically, but also to recognise and respond to AI-enabled cyber threats, deepfakes, social engineering, misinformation, privacy risks and unsafe handling of sensitive information.
Justification of Comment / Suggestion:
The Strategy develops strong but largely parallel provisions for AI literacy and AI cybersecurity. Connecting these areas more explicitly would strengthen societal resilience and ensure that the expansion of AI adoption is accompanied by corresponding growth in the population’s ability to use AI securely and responsibly. This would also support the Strategy’s broader objectives relating to trust, resilience, human-centred AI and responsible adoption.
General Comments
I would like to acknowledge the considerable work that has gone into preparing the draft Cyprus National AI Strategy 2032. The Strategy is ambitious and, importantly, recognises that successful AI adoption depends not only on technology, but on the data, institutional, governance and human capabilities required to deploy AI responsibly and at scale.
Several elements are particularly strong. The emphasis on data as a strategic national asset, interoperability, secure data sharing and reusable digital infrastructure provides the right foundation for scaled adoption. The principles of “build once, reuse everywhere”, the need for measurable value, and scaling only where impact is demonstrated are also important, particularly given the Strategy’s own recognition of the risk of fragmented pilots and “AI theatre”.
The Strategy also rightly recognises the need for AI adoption with productivity, public-sector transformation, skills, research, innovation and responsible governance, rather than treating AI as a standalone technology policy.
The main challenge for the final Strategy is therefore not to add further ambition, but to translate the existing ambition into a smaller number of clearly prioritised and sequenced actions, with defined ownership, dependencies, potential funding sources, implementation milestones and practically measurable outcomes.
For Cyprus, this is particularly important. Its advantage is unlikely to come from competing with larger economies on the scale of AI investment or compute capacity. It can, however, benefit from its relatively compact ecosystem to coordinate quickly, improve interoperability, test solutions in real operating environments and scale successful applications more rapidly.
The following comments therefore focus primarily on prioritisation, implementation readiness, measurability and governance, with the objective of strengthening the Strategy’s ability to move from ambition to sustained execution.
1. Prioritise national foundations and critical domains before broader international positioning
Article / Section: Sections 1.3 “Priority Sectors for Leadership”, 1.4 “The Strategic Gap and the Implementation Approach”, 1.6 “A Narrow Window”, 2.3 “The Strategic Choice Alignment for the Way Forward”, 2.4 “The Vision: Where Cyprus Will Lead”, and 2.4.1 “Priority Sectors for Leadership”
Comment / Suggestion
The Strategy would benefit from a clearer hierarchy and sequencing of priorities.
In the first phase of implementation, priority should be given to establishing the fundamental capabilities required for effective AI adoption in Cyprus, particularly data quality and governance, interoperability, appropriate digital infrastructure, organisational capability, skills, procurement and effective implementation mechanisms.
At the same time, the definition of “priority sectors” should be reconsidered. The current approach appears to place significant emphasis on contribution to GDP and exposure to AI-driven productivity gains. These are important criteria, but they should not be the only determinants of national priority.
The Strategy should distinguish more clearly between:
1. foundational and nationally critical domains, where resilience and effective operation are prerequisites for the wider economy and society,
2. sectors where AI adoption can generate significant productivity, service-quality or societal improvements, and
3. a smaller number of areas where Cyprus has a credible basis for developing internationally competitive and exportable AI capabilities.
Under the first category, consideration should be given to areas such as water, energy and electricity, transport and mobility, and the built environment/critical infrastructure. Their importance should not be assessed primarily through their direct contribution to GDP, as their effective functioning underpins economic activity, resilience, quality of life and the operation of virtually every other priority sector.
Similarly, the ambition for Cyprus to become a trusted regional AI hub can provide useful long-term direction, but should be treated primarily as a potential outcome of successful implementation, rather than as a near-term objective that drives resource allocation.
A possible sequencing principle would therefore be: foundations and critical national needs first → proven adoption and scaling second → international positioning and specialisation third. Progression should be based on demonstrated readiness and measurable results rather than ambition alone.
If the concept of Cyprus as a “trusted regional AI hub” remains a central strategic ambition, the final Strategy should also define what this means in practical and measurable terms. The relevant capabilities and indicators may already be reflected across different parts of the Strategy, but they are not sufficiently consolidated around this central ambition. A limited set of characteristics and measurable outcomes should therefore define what would constitute success and, importantly, what would differentiate Cyprus from other European and regional jurisdictions. Such differentiation is more likely to arise from Cyprus’s ability to provide a fast, trusted and well-coordinated environment for AI adoption, validation and deployment than from competing with larger economies on absolute scale of compute, hardware or capital.
Justification
The Strategy itself identifies important structural gaps that currently constrain AI adoption: fragmented institutional data and compute resources, immature data governance, limited AI-grade compute, shortages of specialised AI skills and limited applied AI experience within ministries and regulators. It also explicitly identifies the risk of “AI theatre”, where significant experimentation produces limited operational impact.
These observations suggest that Cyprus’s immediate strategic challenge is primarily one of building foundations, execution readiness and institutional capability.
At the same time, the Strategy identifies priority sectors largely on the basis of their contribution to national GDP and exposure to AI-driven transformation and productivity gains. The resulting list includes Government, Financial Services, Healthcare, Tourism, Legal Services, Education, Shipping and Entrepreneurship and Innovation. While these are clearly important areas for AI adoption, economic contribution alone does not capture national criticality or systemic dependency.
For example, water, electricity and energy systems, transport and other critical infrastructures may not necessarily be selected on the basis of their direct GDP contribution, yet weaknesses in these systems can constrain the entire economy and the wider AI ecosystem. The Strategy itself recognises, for example, that access to competitive and sustainable energy resources is important for Cyprus’s attractiveness for digital infrastructure investment.
There is also an important distinction between national priority and international leadership. A domain may be strategically important because AI can materially improve Cyprus’s resilience, productivity or quality of public services without implying that Cyprus should seek to become an international AI leader in that domain. Conversely, international specialisation should be pursued selectively where Cyprus can demonstrate a credible comparative advantage.
Against this background, statements such as that the “only strategic choice” is for Cyprus to become an Eastern Mediterranean AI hub appear stronger than the underlying analysis currently supports. Becoming a recognised regional AI hub would be a welcome consequence of successful implementation, but the more immediate objective should be to make AI work effectively for Cyprus, address critical national needs and demonstrate measurable economic and societal value.
For a country of Cyprus’s scale, disciplined sequencing can itself become a competitive advantage: establish the foundations, demonstrate successful applications, scale what works, and build international positioning on the basis of proven capability and results.
2. Strengthen prioritisation, sequencing and timeline realism through a single implementation roadmap
Article / Section: Section 1.5 “Implementation Timeline and Success Metrics”, Chapter 3 “Strategic Implementation Approach”, Chapter 4 “AI Adoption and Strategic Enablers”, and Chapter 5 “Immediate Steps for the Strategy Launch”
Comment / Suggestion
The Strategy should be complemented by a consolidated implementation roadmap that identifies, for each major initiative: accountable owner; implementation period; dependencies; indicative implementation and recurring cost; funding source; baseline; measurable target outcome; interim milestones; and criteria for continuation, redesign, scaling or termination.
The proposed implementation timeline should also be reviewed for feasibility. The use of broad phases such as 0-6 months, 6-12 months and subsequent periods provides useful direction, but several actions depend on institutional, procurement, data, infrastructure, legislative or capability prerequisites that may themselves require significant time to establish. The timeline should therefore be based on realistic delivery estimates and explicit dependencies, rather than on uniform implementation windows.
The roadmap should clearly distinguish between foundational capabilities, such as data governance, interoperability, infrastructure, procurement capability and workforce readiness, and value-generating applications. Dependencies should be explicit so that initiatives are undertaken in the correct sequence.
Justification
The Strategy includes a substantial number of proposed actions across infrastructure, governance, Centres of Excellence, data, skills, innovation, compliance mechanisms and sectoral programmes. This breadth creates execution risk if initiatives are launched concurrently without sufficient consideration of implementation capacity and critical-path dependencies.
In particular, some actions presented within relatively short implementation windows may require prior decisions on governance, staffing and funding; procurement or contracting; access to and preparation of data; integration with existing systems; development of standards; or coordination across multiple public bodies. A six-month target may therefore be realistic for initiating or designing an intervention, but not necessarily for establishing it as an operational and effective national capability.
The roadmap should therefore distinguish, where appropriate, between decision/design, establishment, pilot, operational deployment and scale-up, rather than treating an initiative as a single milestone. A consolidated and realistically phased implementation roadmap would provide the bridge between Strategy and execution and allow leadership to understand which actions are critical-path dependencies, which can proceed in parallel and which should only commence once the necessary foundations have been demonstrated.
3. Make the National Strategic Objectives more specific and measurable
Article / Section: Sections 1.2 “The National Strategic Objectives and Priority Sectors”, 2.5 “National Strategic Objectives”, 3.11 “Measuring Impact and National KPIs”, Annex C and Annex F
Comment / Suggestion
The eight National Strategic Objectives are generally broad and directional rather than specific and measurable objectives. Concepts such as a “trusted jurisdiction”, “strong and inclusive AI ecosystem” or “sovereign capability” provide strategic direction, but do not by themselves define what success should look like by 2032.
The Strategy does provide considerably more detail elsewhere, particularly through the sector-specific initiatives and KPIs in Annex C and the measurement framework in Annex F. However, the link back to each National Strategic Objective is not always clear.
It is suggested that each objective be linked directly to a small number of defined 2032 outcomes, intermediate milestones, key initiatives, measurable KPIs and accountable owners, for example:
Strategic Objective → 2032 Outcome → Key Initiatives → Milestones → KPIs → Owner
This would not require adding further initiatives, but rather organising and, where necessary, completing the existing information into a clear delivery framework.
Justification
The National Strategic Objectives are intended to provide a common reference point for policy, investment and delivery. For this purpose, they should be sufficiently specific to allow progress and accountability to be assessed. While Annex C provides further sector-level detail and Annex F introduces an outcomes-focused measurement framework, Annex F itself is described as indicative and adaptive. The Strategy therefore contains many of the necessary components, but the roadmap connecting the high-level objectives to concrete delivery and measurable results is not sufficiently explicit. Strengthening this connection would make the Strategy more actionable and make it easier to determine, throughout implementation, whether each National Strategic Objective is actually being achieved.
4. Strengthen the KPI framework and distinguish measurable targets from ambitions and scenarios
Article / Section: Section 1.5 “Implementation Timeline and Success Metrics”, Section 2.5 “National Strategic Objectives”, Section 3.11 “Measuring Impact and National KPIs”, Annex C and Annex F “National KPIs and Measurement Framework”
Comment / Suggestion
The Strategy rightly places strong emphasis on measurable outcomes. However, the KPI framework should be strengthened to ensure that the measures presented as targets are specific, measurable and supported by a credible implementation pathway. Each core KPI should, as a minimum, specify:
baseline → target → measurement methodology/data source → accountable owner → reporting frequency → target date.
At Strategy level, priority should be given to a limited number of outcome and impact KPIs, rather than primarily measuring activities or outputs.
The final Strategy should also distinguish clearly between:
• committed and measurable targets,
• strategic ambitions, and
• scenario-based estimates or potential impacts.
Where a baseline, measurement methodology or credible attribution to the Strategy cannot yet be established, the figure should not be presented as a committed KPI.
Justification
The Strategy itself states that AI should deliver “demonstrable public and economic value, rather than activity without outcomes” and that national KPIs should be clear, comparable and actionable. This is a strong principle. At the same time, the Strategy contains ambitious quantitative statements relating, among others, to productivity improvement, AI adoption, high-skilled employment, workforce positioning and reductions in citizen waiting times. Some may be appropriate targets; others may be better understood as ambitions or potential scenarios. The distinction is important.
For example, a national productivity target requires a defined baseline, measurement methodology, expected sectoral contributions and a credible link between the interventions under the Strategy and the resulting productivity improvement. Without this, it will be difficult to determine how much of any observed change can reasonably be attributed to the Strategy.
This creates a significant implementation and accountability risk: if success is not defined and measured consistently from the outset, progress may ultimately be assessed on activity rather than results, despite the Strategy’s stated intention to do the opposite. A smaller number of robust, measurable and defensible KPIs would therefore provide a stronger basis for implementation and accountability than a larger set of ambitious but difficult-to-measure targets.
5. Significantly simplify the governance model and build implementation capacity within existing structures
Article / Section: Sections 1.4.3 “Governance and Accountability”, 3.3 “Governance and Controls”, particularly 3.3.1 “Governance Structure”, and Annex E “AI Officers”
Comment / Suggestion
The proposed governance architecture should be significantly simplified, taking into account the size of Cyprus and the need for fast and accountable implementation.
Rather than establishing multiple new permanent governance and delivery structures, consideration should be given to a leaner model centred on:
• DMRID, with a properly resourced and highly skilled central AI team responsible for coordinating implementation, monitoring progress, establishing common standards and capabilities, and reporting against the Strategy;
• the National AI Taskforce, continuing to provide expert strategic and technical advice and challenge;
• a clearly designated and appropriately skilled AI focal point/officer within each Ministry and major public organisation, responsible for local implementation and coordination with the central team; and
• existing competent regulatory and specialist authorities retaining responsibility within their established mandates.
Additional committees or structures should be created only where there is a clearly demonstrated function that cannot be performed effectively within this model.
The same principle should apply beyond governance bodies to the proposed Centres of Excellence, hubs, observatories, programmes and other new institutional mechanisms. Before establishing a new structure, the implementation plan should demonstrate the specific capability gap it addresses, why that function cannot be delivered through an existing institution or programme, the resources required to sustain it, and how its contribution to the Strategy will be measured. The objective should be to build capability, rather than institutional complexity.
Justification
The Strategy currently envisages a National AI Authority, Interministerial AI Council, National AI Taskforce, National AI Infrastructure Council, National Ethics and Values Committee, National AI Misinformation and Security Council, National AI Skills Observatory, Government Innovation Hub, Industrial Centre of Excellence, National AI Cybersecurity Centre of Excellence, AI Officers and AI Champions.
While the functions addressed are individually relevant, the combined architecture appears disproportionately complex for the scale of the Cypriot public administration. There is a risk that the governance mechanism itself becomes an implementation challenge, creating overlapping mandates, additional interfaces, diffused accountability and slower decision-making.
Moreover, the Strategy already provides much of the basis for a simpler model. It states that ministries and public bodies should retain responsibility for AI adoption and that initiatives should be embedded within existing policy, operational and accountability structures. The objective should therefore be to strengthen implementation capacity within existing institutional structures wherever possible, rather than create a parallel, potentially disconnected AI administration.
For a small country, simplicity, clarity of ownership and speed of decision-making should themselves be considered governance design principles.
6. Prioritise practical public-sector capability and reusable foundations before advanced or “moonshot” use cases
Article / Section: Sections 3.4 “AI Adoption Across Government”, 4.2 “AI Infrastructure Enablers”, 4.4 “AI Adoption Enablers”, and relevant use cases in Annex C
Comment / Suggestion
The public-sector AI programme should initially concentrate on a small number of high-value, feasible and reusable applications, supported by common data and technology foundations, before progressing to more advanced or speculative applications.
Priority should be given to use cases that: address a clearly defined existing problem; use data that is already available or can realistically be made available; can demonstrate measurable improvements in cost, processing time, service quality or productivity; have manageable implementation and regulatory risk; and create capabilities that can subsequently be reused across government.
Advanced “moonshots” should remain part of the longer-term innovation pipeline but should not compete for implementation resources with the foundational transformation required first.
Justification
The Strategy already contains the very strong principles of “Build Once, Reuse Everywhere” and a “Value-First Portfolio”, and proposes selecting six moonshots from sixteen flagship transformation programmes.
These principles should be applied even more rigorously. Given the uneven level of organisational and data maturity identified elsewhere in the Strategy, early success is likely to come from solving concrete operational problems and creating reusable capabilities rather than pursuing the most technologically sophisticated applications first. The objective during the initial implementation period should be to demonstrate that AI can deliver tangible, measurable improvements in actual government operations. Successful solutions can then be scaled and more ambitious use cases pursued as the underlying capability matures.
This would also provide practical evidence, institutional experience and public confidence upon which the Strategy’s longer-term ambitions can be built.
7. Use needs-based terminology for vulnerable groups rather than demographic proxies
Article / Section: Relevant references in the Strategy to pensioners, older persons or other demographic groups in the context of digital inclusion, AI literacy, accessibility and citizen services; Section 3.6 “Talent, Skills and Workforce Transformation” where applicable.
Comment / Suggestion
Where the Strategy seeks to identify citizens who may require additional support to access AI-enabled or digital services, it is suggested that it consistently use terminology such as “vulnerable groups”, “persons at risk of digital exclusion” or “persons requiring additional accessibility or digital support”, rather than referring to pensioners or people with disabilities alone.
Where useful, the Strategy can identify specific factors contributing to vulnerability or exclusion, such as digital literacy, disability, socioeconomic circumstances, language barriers or limited access to technology.
Justification
Age or pensioner status does not, by itself, determine digital capability or vulnerability. Conversely, people in younger age groups may face significant barriers to accessing digital or AI-enabled services. A needs-based definition is therefore more accurate, inclusive and useful for policy design.
Indeed, the Strategy itself already uses the broader formulation “citizens in vulnerable or disadvantaged circumstances” in the FutureAI CY programme. Applying this approach consistently would avoid unnecessary demographic assumptions and allow interventions to be targeted according to actual need.
It would also reinforce an important principle for the digitalisation of public services: AI-enabled channels should improve accessibility and inclusion, while appropriate alternative channels and support should remain available for people who require them.
### 1. Εθνική AI Literacy για όλους τους φοιτητές και φοιτήτριες
**Αριθμός άρθρου/εδαφίου αναφοράς:** *Education and Human Capital Development – Context and ambition / Strategic objectives and 2032 target*, σελ. 77–78. Ειδικότερα, η Στρατηγική αναφέρει ως βασική κατεύθυνση τη δημιουργία μιας «AI-literate» Κύπρου, καθώς και τη δια βίου εκπαίδευση στην AI από την πρωτοβάθμια εκπαίδευση μέχρι την ανώτατη εκπαίδευση και την επαγγελματική ζωή.
**Εισήγηση:** Προτείνω τη δημιουργία ενός εθνικού πλαισίου βασικής AI Literacy για όλους τους φοιτητές και τις φοιτήτριες των κυπριακών πανεπιστημίων, ανεξαρτήτως κλάδου σπουδών. Η AI δεν θα πρέπει να αντιμετωπίζεται ως δεξιότητα που αφορά αποκλειστικά τους φοιτητές Πληροφορικής, αλλά ως βασική οριζόντια δεξιότητα για κάθε νέο επιστήμονα και επαγγελματία. Το πλαίσιο θα μπορούσε να υλοποιείται μέσω ενός σύντομου πιστοποιημένου μαθήματος ή micro-credential και να περιλαμβάνει πρακτική χρήση Generative AI, prompting, αξιολόγηση της αξιοπιστίας των απαντήσεων, hallucinations, προστασία προσωπικών δεδομένων, copyright, ακαδημαϊκή ακεραιότητα, AI Act και υπεύθυνη χρήση της AI. Ως πανεπιστημιακός που διδάσκω κάθε χρόνο το μάθημα *Introduction to Generative AI* σε φοιτητές και φοιτήτριες, διαπιστώνω στην πράξη ότι η ανάγκη δεν είναι απλώς να μάθουν να χρησιμοποιούν εργαλεία όπως το ChatGPT, αλλά να μάθουν να τα χρησιμοποιούν **κριτικά, υπεύθυνα και παραγωγικά**.
**Αιτιολόγηση σχολίου / Εισήγησης:** Η Στρατηγική θέτει ως στόχο μια AI-literate Κύπρο και τη δημιουργία δεξιοτήτων σε όλο το εκπαιδευτικό και επαγγελματικό οικοσύστημα. Η πρόταση μετατρέπει αυτή τη γενική κατεύθυνση σε μια συγκεκριμένη και άμεσα εφαρμόσιμη δράση στην ανώτατη εκπαίδευση, διασφαλίζοντας ότι κάθε νέος απόφοιτος θα διαθέτει ένα ελάχιστο κοινό επίπεδο AI γνώσεων.
—
### 2. Εθνικό Πρόγραμμα AI Εκπαίδευσης και Πιστοποίησης Εκπαιδευτικών
**Αριθμός άρθρου/εδαφίου αναφοράς:** *Education and Human Capital Development – National frameworks and governance / EPVL (Ethical, Pedagogical Validation Layer)*, σελ. 78–79. Η Στρατηγική προβλέπει teacher-mediated χρήση της AI, δηλαδή η τεχνολογία να υποστηρίζει τον εκπαιδευτικό και όχι να τον αντικαθιστά, ενώ προβλέπει επίσης εθνικά μαθησιακά αποτελέσματα και πλαίσια για AI Literacy.
**Εισήγηση:** Προτείνω τη δημιουργία ενός εθνικού προγράμματος επιμόρφωσης και πιστοποίησης εκπαιδευτικών στην AI, το οποίο θα καλύπτει εκπαιδευτικούς όλων των βαθμίδων. Η εκπαίδευση δεν θα πρέπει να περιορίζεται στη γνωριμία με το ChatGPT, αλλά να επικεντρώνεται στην πρακτική αξιοποίηση της Generative AI για δημιουργία και διαφοροποίηση εκπαιδευτικού υλικού, σχεδιασμό δραστηριοτήτων και αξιολογήσεων, εξατομικευμένη υποστήριξη μαθητών, παροχή feedback, εντοπισμό AI-generated εργασιών, αλλά και στην ασφαλή και υπεύθυνη χρήση της AI με σεβασμό στα προσωπικά δεδομένα, την ακαδημαϊκή ακεραιότητα και την ανθρώπινη κρίση. Θα μπορούσε να δημιουργηθεί ένα **Cyprus AI Educator Certificate**, με βασικό, ενδιάμεσο και προχωρημένο επίπεδο, το οποίο θα επικαιροποιείται τακτικά καθώς εξελίσσονται οι τεχνολογίες.
**Αιτιολόγηση σχολίου / Εισήγησης:** Η ίδια η Στρατηγική αναγνωρίζει ότι η ασφαλής χρήση AI στην εκπαίδευση πρέπει να είναι **teacher-mediated** και να μην αντικαθιστά τον εκπαιδευτικό. Επομένως, πριν απαιτήσουμε από τους εκπαιδευτικούς να ενσωματώσουν την AI στην τάξη, πρέπει να τους δώσουμε οργανωμένη, πρακτική και πιστοποιημένη εκπαίδευση. Η προσωπική μου εμπειρία από τη διδασκαλία του *Introduction to Generative AI* σε φοιτητές επιβεβαιώνει ότι η αποτελεσματική χρήση της AI απαιτεί καθοδήγηση και όχι απλώς πρόσβαση στα εργαλεία.
—
### 3. Cyprus AI Student Passport – Πιστοποίηση πραγματικών AI δεξιοτήτων
**Αριθμός άρθρου/εδαφίου αναφοράς:** *Education and Human Capital Development – Flagship programme: FutureAI CY* και *Education and Human Capital Development Pillar – What this pillar is expected to deliver*, σελ. 80–81. Η Στρατηγική προβλέπει stackable micro-credentials 5–15 ECTS, πρακτική εκπαίδευση μέσω workshops και sandboxed exercises, καθώς και πιστοποίηση δεξιοτήτων που συνδέεται με τις ανάγκες της αγοράς εργασίας.
**Εισήγηση:** Προτείνω τη δημιουργία ενός **Cyprus AI Student Passport**, ενός ψηφιακού πιστοποιητικού δεξιοτήτων που θα συνοδεύει τον φοιτητή από το πανεπιστήμιο προς την αγορά εργασίας και θα καταγράφει όχι μόνο την παρακολούθηση μαθημάτων AI αλλά κυρίως τις πρακτικές δεξιότητες που έχει αποκτήσει. Το Passport θα μπορούσε να αποτελείται από διαφορετικά επίπεδα, όπως AI Literacy, AI Productivity, AI Data Analysis, AI Automation και Sector-Specific AI, και για την απόκτηση κάθε επιπέδου ο φοιτητής να ολοκληρώνει ένα πραγματικό πρακτικό project. Με αυτόν τον τρόπο ένας απόφοιτος δεν θα δηλώνει απλώς ότι «έχει παρακολουθήσει μάθημα AI», αλλά θα μπορεί να αποδεικνύει συγκεκριμένες AI δεξιότητες και εφαρμογές που είναι χρήσιμες στον κλάδο εργασίας του.
**Αιτιολόγηση σχολίου / Εισήγησης:** Η Στρατηγική ήδη προτείνει micro-credentials, πρακτική εκπαίδευση, sandboxed exercises και σύνδεση των δεξιοτήτων με τις ανάγκες της αγοράς εργασίας. Η εισήγηση επεκτείνει αυτή τη λογική ειδικά για τους φοιτητές, δημιουργώντας μια **μεταφέρσιμη και αποδείξιμη πιστοποίηση AI skills**. Παράλληλα, μεταφέρει την έμφαση από το «παρακολούθησα ένα σεμινάριο» στο «μπορώ να αποδείξω ότι μπορώ να χρησιμοποιήσω την AI για να λύσω ένα πραγματικό πρόβλημα».
Possible Ethical and Bioethical Additions to the Cyprus National AI Strategy 2032, Constantinos N. Phellas, Chair of the Cyprus National Bioethics Committee
1. Possible locations for the additions:
Section 1.4.8, immediately after “Responsible Deployment” (printed pp. 5-6),
Suggestion for consideration: Add a short paragraph linking the existing principles to necessity, proportionality, public interest and additional safeguards for people who may be particularly vulnerable
Why it may be useful: This could give the Executive Summary a clearer ethical test without making it too technical.
Section 3.3.1.5, National Ethics and Values Committee (printed p. 24)
Suggestion for consideration: Expand the current one-sentence description to clarify the Committee’s advisory role, membership, independence, transparency and relationship with existing authorities.
Why it may be useful: The Strategy already names the Committee, but a little more detail may make its function easier to understand and implement.
Immediately after Section 3.3.1.5
Suggestion for consideration: Add a separate paragraph outlining a possible consultative role for the Cyprus National Bioethics Committee within health, biomedical research and related areas.
Why it may be useful: Keeping this role separate may help preserve the Committee’s statutory identity and avoid suggesting that it is responsible for ethics across every AI sector.
New Section 3.9.7, after “AI Social Contract Principles” (printed pp. 43-44)
Suggestion for consideration: Consider an Ethical and Fundamental Rights Impact Assessment for higher-risk or materially rights-affecting public-sector systems, together with consultation, publication and redress provisions.
Why it may be useful: This would connect the ethics chapter more directly to practical decision-making and public accountability.
Annex B, Stage 2 and Control Gate 2 (printed pp. 58-59)
Suggestion for consideration: Refer to the ethical assessment, and where relevant specialist bioethical advice, as part of the evidence considered at Control Gate 2.
Why it may be useful: This may be the clearest place to show that ethics is part of implementation rather than a separate statement of principle.
Annex F, Trust, Ethics and Compliance Indicators (printed pp. 93-94)
Suggestion for consideration: Add a small set of outcome-focused ethics and trust indicators
Why it may be useful: This could help measure whether people can understand and challenge decisions, whether unequal outcomes persist and whether concerns are addressed.
2. Suggested wording for consideration
2.1 Possible addition to Section 1.4.8: Ethics, Trust and Responsible AI
Placement: after the existing bullet “Responsible Deployment: Continuous monitoring and withdrawal criteria.”
Suggested wording for consideration
Ethical governance under this Strategy should not be understood as being exhausted by legal compliance. Alongside applicable legal requirements, AI initiatives should pursue a legitimate public or organisational purpose and should be assessed for necessity, proportionality and compatibility with human dignity, individual autonomy, equality, solidarity, democratic values and the public interest. Where reasonably possible, decision-makers should consider whether the objective could be achieved through a less intrusive or non-AI alternative and should identify how benefits and risks are distributed, including whether the system could deepen existing social, economic, health or digital inequalities.
Additional safeguards should be considered where AI affects children, patients, persons with disabilities, older persons, migrants, employees or others who may face vulnerability or unequal power. Ethical acceptability should be revisited when there are material changes in the data, model, intended purpose or deployment context. Where evidence of benefit remains uncertain and the potential harm is serious or irreversible, appropriate measures may include controlled testing, restricted deployment, temporary suspension or withdrawal.
2.2 Possible replacement text for Section 3.3.1.5: National Ethics and Values Committee
Placement: replace the current single sentence under Section 3.3.1.5.
Suggested wording for consideration
The National Ethics and Values Committee should serve as a multidisciplinary and pluralistic advisory body supporting the ethical implementation of this Strategy. Its membership could include expertise in ethics and philosophy, bioethics, law and human rights, data protection, social sciences, AI and engineering, cybersecurity, accessibility and disability, labour and education, together with appropriate civil-society and stakeholder representation. Appointments should be transparent, and members should declare relevant conflicts of interest.
The Committee could develop or recommend a common ethical framework and an Ethical and Fundamental Rights Impact Assessment methodology; advise on novel, high-impact or socially contested uses; identify where additional safeguards, restricted deployment, further consultation or withdrawal may need to be considered; and review ethical issues that cut across sectors. To support public trust, it could publish non-confidential opinions, periodic guidance and an annual account of its work.
The Committee should complement rather than replace the National AI Authority, the competent authorities under the EU AI Act, the Commissioner for Personal Data Protection, sector regulators or the courts. Its recommendations would be submitted to the National AI Taskforce. Where a serious ethical concern about a proposed public-sector deployment remains unresolved, the matter could be referred to the National AI Authority and, where appropriate, the Interministerial AI Council before the relevant control gate is passed.
2.3 Possible new paragraph: Role of the Cyprus National Bioethics Committee
Placement: immediately after the revised Section 3.3.1.5, with a cross-reference in the Healthcare and Life Sciences pillar.
Suggested wording for consideration
One possible approach would be to give the Cyprus National Bioethics Committee a standing consultative role within this governance structure, for example through a nominated representative and a formal consultation protocol. The Committee would remain institutionally independent and would offer specialised advice within its statutory remit where AI is used in healthcare, biomedical research, genetics or genomics, pharmaceuticals, human biological material, clinical decision support, health-data reuse or other applications that may affect bodily integrity, patient autonomy or the clinician-patient relationship.
Consultation could be considered for nationally significant or high-impact initiatives such as the National Health Data Repository, intelligent triage, the Virtual AI Patient Orchestrator, digital or virtual human twins, AI-enabled medical devices and health research using sensitive or linked datasets. Its contribution might include guidance on consent, secondary use, vulnerability, proportionality, uncertainty and acceptable risk; support for public deliberation; and advice to the National Ethics and Values Committee or relevant Data Access Committees. The role should be designed so that it does not duplicate conformity assessment, data-protection supervision or clinical regulation. Any extension beyond the Committee’s current legal remit would require appropriate legal and institutional consideration.
2.4 Possible new Section 3.9.7: Ethical and Fundamental Rights Impact Assessment
Placement: after Section 3.9.6 “AI Social Contract Principles” and before the Strategic Outcome.
Suggested wording for consideration
For higher-risk or materially rights-affecting AI systems procured, piloted or deployed by or on behalf of a public authority, the responsible body should complete an integrated Ethical and Fundamental Rights Impact Assessment (E-FRIA), incorporating the fundamental-rights impact assessment required by the EU AI Act where applicable and coordinated with any Data Protection Impact Assessment. The assessment could cover the system’s purpose, necessity and proportionality; the people likely to be affected; foreseeable benefits and harms; data provenance and representativeness; risks of discrimination or exclusion; accessibility; human oversight; explainability and contestability; cybersecurity; environmental and workforce effects; possible misuse or expansion beyond the original purpose; residual risk; and review or withdrawal criteria.
Where the likely impact is material, consultation should include relevant stakeholders, particularly affected groups, frontline professionals and those who may be vulnerable. A non-confidential summary could normally be published before deployment, subject to justified legal or security exceptions. The assessment should be revisited following a substantial modification, material model or data drift, a serious incident or a significant change in context. Citizen-facing systems should provide clear notice of AI use, an accessible route to human review and an identifiable public body responsible for responding to concerns and providing redress.
2.5 Possible addition to Annex B: Stage 2 and Control Gate 2
Suggested wording for consideration
At Stage 2, the E-FRIA should be initiated and proportionate stakeholder engagement undertaken. Before Control Gate 2 is passed, the responsible authority should be satisfied that the use is necessary and proportionate, that less intrusive alternatives have been considered where appropriate, that safeguards and human oversight are workable, and that the remaining risks are justified and manageable. For health and biomedical systems within the Cyprus National Bioethics Committee’s remit, evidence of appropriate bioethical consultation could form part of the gate documentation. Where evidence remains limited, approval could be time-limited and linked to clear review, suspension and decommissioning triggers.
2.6 Possible addition to Annex F: Trust, Ethics and Compliance Indicators
Suggested wording for consideration
Ethics and trust KPIs could focus on how safeguards work in practice rather than only on whether policies exist. Possible indicators include the proportion of relevant systems completing and publishing an E-FRIA before deployment; the number, type and resolution time of complaints and requests for human review; reversal and override rates; differences in outcomes across protected or vulnerable groups; serious incidents and time to remediation; systems suspended or withdrawn following ethical concerns; stakeholder participation; accessibility compliance; and public trust, with appropriate demographic and socioeconomic disaggregation. Care should be taken not to discourage transparent incident reporting; early identification and correction of problems should be treated as evidence of responsible governance.
3. Why a limited role for the Cyprus National Bioethics Committee may be helpful
Existing institutional basis. The Cyprus National Bioethics Committee is already established by law as an independent body concerned with ethical, social, humanitarian and legal questions arising from developments in biotechnology, biology, medicine, genetics and pharmaceuticals. This existing institutional basis may offer continuity and public legitimacy, particularly in areas where AI is closely connected to health or biomedical innovation.
Relevant bioethical perspective. Healthcare AI may affect informed consent, bodily integrity, allocation of treatment, diagnostic responsibility, confidentiality and the clinician-patient relationship. These questions are not fully answered by technical accuracy, cybersecurity or data-protection compliance alone. A bioethical perspective can help examine autonomy, benefit and harm, justice, vulnerability, solidarity and the fair treatment of uncertainty.
Opportunity to build on existing capacity. The Committee already works with bioethical advice, public information and research-ethics structures. Drawing on that experience may be more coherent than establishing a separate health-ethics body solely for AI. It may also help connect AI governance with existing practices in clinical and biomedical research.
A point requiring legal and institutional review:
The Strategy may be able to establish advisory, assurance and control-gate arrangements for public bodies, but it should not imply that a committee has licensing, enforcement or adjudicative powers unless those powers are provided by law. The same caution applies to the Cyprus National Bioethics Committee: its contribution should remain within its statutory remit unless any wider role is supported by an appropriate legal or formal inter-institutional arrangement.
Ενότητα 3.3.2 «Control Framework», Ενότητα 3.4 «AI Adoption Across Government», Ενότητα 4.4 «AI Adoption Enablers» και Παράρτημα Β «AI Use Case Lifecycle and Control Gates».
Σχόλιο / Εισήγηση:
Γίνεται εισήγηση όπως, στο πλαίσιο της εφαρμογής της Εθνικής Στρατηγικής ΤΝ, ετοιμαστεί ένας πρακτικός οδηγός, ο οποίος να μπορεί να χρησιμοποιείται από Υπουργεία και δημόσιους οργανισμούς κατά την υλοποίηση εφαρμογών ΤΝ.
Ο οδηγός θα ήταν χρήσιμο να περιλαμβάνει βασικά πρότυπα και διαδικασίες για την καταγραφή και αξιολόγηση ενός AI use case, τον έλεγχο της διαθεσιμότητας και καταλληλότητας των δεδομένων, την αξιολόγηση κινδύνων και συμμόρφωσης, τον καθορισμό αρμοδιοτήτων, την πιλοτική εφαρμογή, καθώς και τον τρόπο με τον οποίο θα αξιολογείται το αποτέλεσμα πριν από την πλήρη εφαρμογή μιας λύσης.
Αιτιολόγηση σχολίου / Εισήγησης:
Η Στρατηγική καθορίζει τα βασικά στάδια που πρέπει να ακολουθούνται κατά τον κύκλο ζωής μιας εφαρμογής ΤΝ, καθώς και τους σχετικούς μηχανισμούς ελέγχου. Ωστόσο, πιστεύω ότι η ύπαρξη ενός πιο πρακτικού οδηγού εφαρμογής θα διευκόλυνε τους οργανισμούς να μεταφέρουν τις πρόνοιες της Στρατηγικής στην καθημερινή λειτουργία τους.
Παράλληλα, θα μπορούσε να συμβάλει στην εφαρμογή μιας πιο κοινής προσέγγισης μεταξύ των οργανισμών, ιδιαίτερα σε θέματα όπως η αξιολόγηση των προτεινόμενων εφαρμογών, η διαχείριση των κινδύνων, οι απαιτούμενες εγκρίσεις και η παρακολούθηση των αποτελεσμάτων.
Με τον τρόπο αυτό θα περιοριζόταν και το ενδεχόμενο κάθε οργανισμός να αναπτύξει διαφορετικές διαδικασίες και πρότυπα για παρόμοια θέματα, ενώ θα διευκολυνόταν η εφαρμογή και η παρακολούθηση της Εθνικής Στρατηγικής σε πιο ομοιόμορφη βάση.
Σημειώνεται επίσης ότι στο Παράρτημα Γ της Στρατηγικής προβλέπεται η κατάρτιση AI adoption plan από κάθε sizeable organisation, ενώ ειδική αναφορά γίνεται και στους ρυθμιζόμενους τομείς, μεταξύ των οποίων περιλαμβάνεται και ο τομέας της ενέργειας.
Η πρόνοια αυτή ενισχύει την ανάγκη ύπαρξης ενός πρακτικού και ενιαίου οδηγού εφαρμογής, ώστε οι οργανισμοί που θα κληθούν να ετοιμάσουν και να εφαρμόσουν τα σχετικά σχέδια να έχουν κοινό σημείο αναφοράς ως προς τα στάδια, τις απαιτήσεις, τις εγκρίσεις, την αξιολόγηση κινδύνων και την παρακολούθηση των αποτελεσμάτων.
Pillar A — Data Security and Activity Monitoring
R1 — Data Activity Monitoring Requirements
The proposed solution must provide continuous, real-time monitoring of every data interaction — whether initiated by a human user or a non-human identity — across structured, semi-structured, and unstructured data stores. The solution must be capable of parsing database queries, capturing NoSQL and streaming protocols, and logging object-level access to file and document repositories, and must enforce sensitivity-aware policies with automated response capabilities that act before damage is done. Behavioural baselines must be established per identity and calibrated for machine-speed access patterns, such that anomalous agent behaviour — for example, the bulk reading of sensitive records within minutes under legitimate credentials — is detected where thresholds tuned for human query volumes would remain silent.
The solution must provide end-to-end traceability when data crosses security boundaries, including cases where an agentic system combines data from multiple stores and writes derived outputs to downstream systems. Integration with national security operations tooling (SIEM/SOAR) and with the audit and assurance mechanisms of the Strategy’s governance model is required. Deployment as a mandatory architectural layer of the National Data Layer and the API Fabric is expected.
R2 — Data Discovery and Classification Requirements
The proposed solution must provide automated discovery and classification of sensitive data across ministries and public bodies, supporting a single national classification scheme with mandatory labelling for datasets entering the National Data Layer, sectoral data spaces, or regulatory sandboxes. Classification must cover structured and unstructured sources, must recognise special-category data under GDPR, and must feed sensitivity-aware access, sharing, and monitoring policies. Classification coverage must be a measurable precondition for connecting any system to the API Fabric, and posture-management capabilities are expected to continuously identify unprotected, misplaced, or over-exposed sensitive data.
Pillar B — Third-Party AI Risk
R3 — Third-Party and Vendor AI Risk Requirements
A defined assessment regime for AI vendors and foundation-model providers must be established, covering security posture, data handling and residency, model transparency and documentation, concentration risk, exit strategy, and ongoing monitoring obligations. The regime must generalise the third-party ICT risk discipline already imposed on the financial sector under DORA to all government AI procurement. Dependency concentration on non-EU model and platform providers must be tracked as a named sovereignty metric within the national KPI framework, and tooling that supports continuous third-party risk monitoring as the supplier landscape evolves is expected.
Pillar C — Quantum Readiness
R4 — Quantum-Safe Cryptography Requirements
The proposed solution must incorporate quantum-safe cryptography capabilities that protect sensitive data and communications against both current and future threats posed by cryptographically relevant quantum computers. Post-quantum cryptographic (PQC) algorithms standardised by the National Institute of Standards and Technology (NIST) — including lattice-based, hash-based, and other quantum-resistant primitives — must be supported. The solution must include cryptographic discovery and inventory capabilities, identifying where classical algorithms such as RSA and ECC are in use across the enterprise, enabling the organisation to assess exposure and prioritise migration efforts. A hybrid cryptography approach must be supported, allowing classical and post-quantum algorithms to operate in tandem during transition periods to ensure backward compatibility without compromising security posture.
The solution must be capable of integrating with existing PKI infrastructure, hardware security modules (HSMs), and key management systems at enterprise and government scale. Alignment with open industry standards and frameworks — including NIST PQC standards and ETSI/ISO quantum-safe guidance — is required. A quantum-safe roadmap and advisory services must be available to support the organisation through the full cryptographic migration lifecycle, from risk assessment and gap analysis through implementation and validation. Tooling that supports automation and continuous compliance monitoring as standards evolve is expected to be included as part of the overall offering. Long-lived sensitive data — national health, legal, and financial records with decades-long sensitivity — must be prioritised against “harvest now, decrypt later” exposure.
R5 — Quantum Computing Requirements
The solution must provide access to quantum computing resources and associated development tooling capable of supporting both current and emerging enterprise use cases, including optimisation, simulation, machine learning, and cryptographic research. Access to gate-based quantum hardware with a credible and published roadmap for qubit scaling, error mitigation, and fault tolerance is required. The solution must include a quantum software development environment that supports hybrid classical-quantum workflows, enabling development teams to build, test, and deploy quantum algorithms alongside existing classical workloads. Cloud-based access to quantum systems must be available, with flexible consumption models suitable for research, prototyping, and production-grade workloads. Support for an open, extensible SDK ecosystem — enabling portability and reducing vendor lock-in — is expected, along with access to a broader quantum computing community, curated algorithm libraries, and pre-built industry-specific applications to accelerate time to value.
Πρόκειται για ένα ολοκληρωμένο, συνεκτικό και ιδιαίτερα φιλόδοξο στρατηγικό κείμενο, το οποίο αποτυπώνει με πληρότητα το όραμα και τις βασικές κατευθύνσεις για την ανάπτυξη, αξιοποίηση και υπεύθυνη διακυβέρνηση της Τεχνητής Νοημοσύνης στην Κυπριακή Δημοκρατία. Η Στρατηγική ευθυγραμμίζεται με τις ευρωπαϊκές εξελίξεις και διαμορφώνει ένα ισχυρό πλαίσιο για την προώθηση της καινοτομίας, του ψηφιακού μετασχηματισμού και της αναβάθμισης των δημόσιων υπηρεσιών.
Με στόχο την περαιτέρω ενίσχυση της αποτελεσματικότητας, της εφαρμοσιμότητας και της μακροπρόθεσμης βιωσιμότητας της Στρατηγικής, υποβάλλονται οι ακόλουθες παρατηρήσεις:
1. Διακυβέρνηση και θεσμικός συντονισμός
Προτείνεται να αποσαφηνιστούν περαιτέρω οι ρόλοι, οι αρμοδιότητες και οι ευθύνες των εμπλεκόμενων φορέων, καθώς και οι μηχανισμοί συντονισμού μεταξύ των εθνικών δομών διακυβέρνησης. Με τον τρόπο αυτό θα ενισχυθεί η αποτελεσματική συνεργασία μεταξύ των αρμόδιων φορέων, θα αποφεύγονται επικαλύψεις αρμοδιοτήτων και θα διασφαλίζεται η συνεκτική και αποτελεσματική εφαρμογή της Στρατηγικής.
2. Δεδομένα, διαλειτουργικότητα και ευρωπαϊκή διάσταση
Προτείνεται να ενισχυθεί η αναφορά στη διακυβέρνηση δεδομένων υψηλής αξίας, στην εφαρμογή κοινών προτύπων διαλειτουργικότητας και στη συστηματική αξιοποίηση των ευρωπαϊκών υποδομών και πρωτοβουλιών.
Παράλληλα, θα ήταν ωφέλιμο να δοθεί μεγαλύτερη έμφαση στη διασφάλιση της ποιότητας των δεδομένων, στη διακρατική συνεργασία και στην ασφαλή διασυνοριακή ανταλλαγή δεδομένων, ώστε να ενισχύεται η διαλειτουργικότητα, να διευκολύνεται η συνεργασία μεταξύ των κρατών μελών και να προάγεται η ανάπτυξη συμβατών και επαναχρησιμοποιήσιμων λύσεων, αποφεύγοντας παράλληλα αποσπασματικές ή μη συμβατές προσεγγίσεις.
3. Υλοποίηση και βιωσιμότητα
Προτείνεται να προβλεφθούν σαφέστερα κριτήρια αξιολόγησης για τη μετάβαση από πιλοτικές εφαρμογές σε πλήρη παραγωγική λειτουργία, καθώς και διαδικασίες αξιολόγησης της επιχειρησιακής ωριμότητας και ετοιμότητας των έργων.
Επιπλέον, θα ήταν χρήσιμο να ενισχυθεί η πρόβλεψη για την επαναχρησιμοποίηση κοινών υπηρεσιών, τεχνολογικών δομικών στοιχείων και υποδομών, ώστε να αποφεύγονται επικαλύψεις επενδύσεων και να επιτυγχάνονται οικονομίες κλίμακας.
Παράλληλα, κρίνεται σημαντικό να δοθεί μεγαλύτερη έμφαση στη μακροχρόνια επιχειρησιακή και οικονομική βιωσιμότητα των λύσεων που θα αναπτυχθούν, περιλαμβανομένου του σχεδιασμού για τη συντήρηση, την αναβάθμιση, τη συνεχή παρακολούθηση και τη διασφάλιση της χρηματοδότησής τους μετά την ολοκλήρωση της αρχικής υλοποίησης.
4. Δείκτες παρακολούθησης και αξιολόγησης
Πέραν των ποσοτικών δεικτών υιοθέτησης, προτείνεται να συμπεριληφθούν ποιοτικοί δείκτες που να αξιολογούν την ποιότητα των παρεχόμενων υπηρεσιών, τον βαθμό διαλειτουργικότητας μεταξύ πληροφοριακών συστημάτων, τον βαθμό πραγματικής αξιοποίησης των λύσεων Τεχνητής Νοημοσύνης, την επίδρασή τους στην αποδοτικότητα της δημόσιας διοίκησης, την προστιθέμενη αξία που δημιουργείται για τους πολίτες, τις επιχειρήσεις και τους δημόσιους οργανισμούς, καθώς και τον βαθμό ικανοποίησης των τελικών χρηστών.
5. Τομέας Υγείας
Λαμβάνοντας υπόψη τη στρατηγική σημασία του τομέα της υγείας, προτείνεται να δοθεί μεγαλύτερη έμφαση στη διασυνοριακή ανταλλαγή δεδομένων υγείας, στην ασφαλή δευτερογενή αξιοποίηση δεδομένων υγείας για σκοπούς έρευνας, καινοτομίας και ανάπτυξης εφαρμογών Τεχνητής Νοημοσύνης, με παράλληλη διασφάλιση της ιδιωτικότητας, της κλινικής ασφάλειας και της συμμόρφωσης με το ισχύον κανονιστικό πλαίσιο. Επιπρόσθετα, προτείνεται η ενίσχυση των μηχανισμών διακυβέρνησης και προστασίας των δεδομένων υγείας, καθώς και η περαιτέρω ευθυγράμμιση με τις σχετικές ευρωπαϊκές πρωτοβουλίες, υποδομές, κανονιστικά πλαίσια και βέλτιστες πρακτικές.
Πιο συγκεκριμένα, εισηγούμαστε την προσθήκη των ακόλουθων παραγράφων:
Annex C – Priority Sectors for Leadership
Healthcare and Life Sciences
National frameworks and governance
Implementation will be aligned with the European Health Data Space (EHDS), under the strategic leadership of the Ministry of Health and the operational coordination of the National eHealth Authority. Building on Cyprus’ operational participation in the MyHealth@EU infrastructure for the secure cross-border exchange of electronic health data for primary use, Cyprus will continue to expand cross-border digital health services while advancing the national implementation of the HealthData@EU infrastructure for the secure secondary use of health data, with full operational readiness targeted by the end of 2027. Together, these European infrastructures will provide the trusted digital foundation for AI-enabled healthcare services, clinical care, research, innovation, public health, and evidence-based policymaking, ensuring interoperability, security, and compliance with the EHDS, the AI Act, GDPR, and national legislation.
International alignment
Cyprus will promote the adoption and consistent implementation of internationally recognised semantic and technical interoperability standards, including HL7 FHIR, SNOMED CT, ICD, and the European Electronic Health Record Exchange Format (EEHRxF), enabling trusted cross-border health services, high-quality health data for research and innovation, and interoperable AI-enabled healthcare across Europe.
Annex D – Research and Innovation
Focus Area 3: Healthcare
Εισηγούμαστε επίσης την προσθήκη της πιο κάτω βιβλιογραφικής αναφοράς, καθώς αποτελεί την πλέον πρόσφατη επίσημη μελέτη της Ευρωπαϊκής Επιτροπής για την ανάπτυξη και αξιοποίηση της Τεχνητής Νοημοσύνης στον τομέα της υγείας. Η μελέτη παρέχει τεκμηριωμένες κατευθύνσεις πολιτικής και βέλτιστες πρακτικές για την ασφαλή, αξιόπιστη και υπεύθυνη υιοθέτηση της Τεχνητής Νοημοσύνης στα εθνικά συστήματα υγείας, σε πλήρη ευθυγράμμιση με τις ευρωπαϊκές πολιτικές και προτεραιότητες.
European Commission, Directorate-General for Health and Food Safety. Study on the Deployment of AI in Healthcare: Final Report. Publications Office of the European Union, Luxembourg (2025). DOI: 10.2875/2169577.
Επιπρόσθετα, εισηγούμαστε την προσθήκη της ακόλουθης ερευνητικής προτεραιότητας, η οποία αντικατοπτρίζει τις βασικές συστάσεις της πιο πάνω μελέτης:
• Trusted health data infrastructures, interoperability, and secure data sharing to enable the European Health Data Space (EHDS) and support explainable, trustworthy, and human-centred AI through robust validation, continuous evaluation, and regulatory compliance.
Οι πιο πάνω παρατηρήσεις υποβάλλονται με γνώμονα την περαιτέρω ενίσχυση της εφαρμοσιμότητας, της αποτελεσματικότητας και της μακροπρόθεσμης βιωσιμότητας της Εθνικής Στρατηγικής Τεχνητής Νοημοσύνης. Η ενσωμάτωση των εισηγήσεων αυτών αναμένεται να ενισχύσει τον θεσμικό συντονισμό, να προωθήσει τη διαλειτουργικότητα και την αξιοποίηση κοινών υποδομών, να διευκολύνει την αποτελεσματική υλοποίηση των προβλεπόμενων δράσεων και να μεγιστοποιήσει τα οφέλη για τους πολίτες, τις επιχειρήσεις και τη δημόσια διοίκηση. Παράλληλα, θα συμβάλει στη διατήρηση της συνεχούς ευθυγράμμισης της Κυπριακής Δημοκρατίας με το ευρωπαϊκό κανονιστικό και τεχνολογικό περιβάλλον στον τομέα της Τεχνητής Νοημοσύνης.
Παρατηρήσεις του Υπουργείου Εσωτερικών επί του Σχεδίου Εθνικής Στρατηγικής Τεχνητής Νοημοσύνης
Κεφάλαιο 3.2 – Data as a Strategic National Asset
Θέμα: Ψηφιακή ωριμότητα ως προϋπόθεση εφαρμογής της Τεχνητής Νοημοσύνης
Το Υπουργείο Εσωτερικών υποστηρίζει πλήρως την προσέγγιση της Στρατηγικής όσον αφορά τη σημασία της διακυβέρνησης των δεδομένων, της διαλειτουργικότητας και της αρχής Data by Design.Προτείνεται, ωστόσο, να αναγνωριστεί ρητά ότι η αφετηρία των δημόσιων οργανισμών ως προς τον ψηφιακό μετασχηματισμό δεν είναι κοινή.Για Υπουργεία με μεγάλο εύρος υπηρεσιών προς τους πολίτες και σημαντικό αριθμό υφιστάμενων πληροφοριακών συστημάτων, όπως το Υπουργείο Εσωτερικών, η επιτυχής εφαρμογή της Τεχνητής Νοημοσύνης προϋποθέτει την προηγούμενη ή παράλληλη ενίσχυση των βασικών ψηφιακών υποδομών, τη βελτίωση της ποιότητας των δεδομένων, την επίτευξη διαλειτουργικότητας και την εφαρμογή ενιαίου πλαισίου διακυβέρνησης δεδομένων. Ως εκ τούτου, προτείνεται να προβλεφθεί σταδιακή εφαρμογή της Τεχνητής Νοημοσύνης, ανάλογα με τον βαθμό ψηφιακής ωριμότητας κάθε οργανισμού.
Κεφάλαιο 3.3 – Governance and Accountability
Θέμα: Έκδοση Οδηγού για την εκπόνηση Θεσμικών Στρατηγικών Τεχνητής Νοημοσύνης (Institutional AI Strategies)
Η Στρατηγική προβλέπει ότι κάθε Υπουργείο και δημόσιος οργανισμός που θα αναπτύσσει ή θα χρησιμοποιεί εφαρμογές Τεχνητής Νοημοσύνης οφείλει να εκπονήσει τη δική του Institutional AI Strategy, ευθυγραμμισμένη με την Εθνική Στρατηγική και τον Κανονισμό AI Act.
Προτείνεται να προβλεφθεί η έκδοση ενιαίου Οδηγού (Implementation Guide) για την εκπόνηση των Θεσμικών Στρατηγικών Τεχνητής Νοημοσύνης των Υπουργείων και των δημόσιων οργανισμών, ώστε να διασφαλιστεί κοινή μεθοδολογία και ομοιόμορφη εφαρμογή της Εθνικής Στρατηγικής.
Επιπλέον, η στρατηγική κάθε Υπουργείου πιθανώς να επηρεαζεται από την στρατηγική άλλου Υπουργείου. Ποιος θα συντονίζει και θα ευθυγραμμίζει τη διαδικασία.
Αρ. Άρθρου και εδαφίου
Annex C – Healthcare and Life Sciences (pages 67–70)
National Health Data Repository
Σχόλιο / Εισήγηση
Expand the scope of the proposed National Health Data Repository to explicitly include AI-enabled capabilities that support precision medicine and clinical research, specifically:
• AI-enabled longitudinal disease registries for rare diseases, cancer, cardiovascular, neurological and other high-impact conditions, including genomics where appropriate.
• Continuous AI-assisted re-analysis of unresolved clinical and genomic cases as new validated scientific evidence becomes available, enabling healthcare professionals to identify cases requiring expert review.
• AI-assisted identification of potentially eligible participants for ethically approved clinical research studies and clinical trials, while ensuring GDPR compliance, human oversight and patient privacy.
• Interoperability, where appropriate, with the European Health Data Space (EHDS), European Reference Networks (ERNs) and relevant European disease registries to facilitate multinational research collaborations and clinical trials.
Αιτιολόγηση σχολίου / Εισήγησης
The Strategy already establishes a strong foundation through the proposed National Health Data Repository. However, it primarily focuses on secure data storage and interoperability and does not explicitly describe how AI can leverage these data to advance precision medicine and clinical research.
The proposed enhancements would extend the functionality of the existing infrastructure without requiring new national systems. They would:
• improve diagnosis and follow-up of patients with complex and rare diseases through continuous AI-assisted review of emerging evidence;
• support evidence-based healthcare planning through longitudinal disease registries;
• facilitate faster recruitment into approved clinical trials, improving patient access to innovative therapies;
• strengthen Cyprus’s participation in European research initiatives through interoperability with EHDS, European Reference Networks and relevant disease registries; and
• enhance Cyprus’s competitiveness in precision medicine, translational research and international clinical research, while remaining fully aligned with the Strategy’s objectives on trusted AI, healthcare innovation and European integration.
Anro Technologies Limited (trading as AnroAgents), HE 439985, Cyprus. Comment 7 of 7.
7. OFFER OF PARTICIPATION
Article / paragraph: Section 3.8 (Research, Innovation and Ecosystem Development); AI Industrial Centre of Excellence; industry sandboxes programme.
Comment / Suggestion: We formally register our interest in participating in the AI Industrial Centre of Excellence working groups on agentic AI reference architectures and interoperability, and in the industry sandbox programme as a Cyprus-resident vendor of agentic customer-facing systems.
Rationale: The Centre’s mandate to publish interoperability roadmaps requires input from companies running agentic systems in production against real customers and real EU AI Act obligations, not only from research institutions and large integrators. We are a Cyprus-registered company doing precisely this, at SME scale, in the priority sectors the Strategy names — tourism, professional services, e-commerce and others — and we have already implemented the standards the roadmap will have to choose between, including the parts that turned out to be harder than the specifications suggest.
To be precise about what is on offer: working-group participation, and the standards contributions described in comments 1 and 2, are offered without charge. Delivery work, if the Republic procures any, we would bid for on open terms like any other supplier. We would rather the national reference implementation be built once, publicly and correctly, than separately by each vendor that needs one.
This is the last of our seven comments. They have been submitted here in sequence and also sent to the consultation officer as a single document, which sets them out in full with the same section references. We thank the National AI Taskforce for a substantive and distinguishingly candid document — in particular for stating the 9.27% adoption figure plainly rather than burying it. Our comments are offered in support of the Strategy’s direction.
Kind regards,
Iana Bolshakova
Co-Founder and CBDO @AnroAgents
Anro Technologies Limited (trading as AnroAgents), HE 439985, Cyprus. Comment 6 of 7.
6. RESERVE A LANE IN THE TRANSFORMATION-PROJECT PROCUREMENTS FOR CYPRUS-RESIDENT SMEs, AND FIX THE TARGETS THAT ANNEX F WILL MEASURE
Article / paragraph: Section 3.4 — Value-First Portfolio, “16 flagship transformation programmes”; Section 5, item 6 (AI Adoption Plan) — “Launch of procurements for the first 6 transformational AI solutions within 8 months”; Section 3.4.4 (Shared Capabilities and Reuse); Objective 3 (inclusive ecosystem) and Objective 8 (Sovereign Capability through Partnerships); Annex F (National KPIs and Measurement Framework).
Comment / Suggestion: Add to the procurement provisions: (a) division of the sixteen flagship transformation programmes, and of the first six transformational solutions to go to market, into lots sized so that a company of 10-50 people can bid for a lot; (b) a distinct “quick wins” procurement track with capped contract values and proportionate prequalification — turnover and reference requirements that a three-year-old Cypriot company can actually satisfy; (c) a reporting KPI in Annex F for the share of AI contract value awarded to Cyprus-resident SMEs.
Rationale: Objective 8 seeks sovereign capability through partnerships, and Objective 3 an inclusive ecosystem — but procurement design, not strategy text, determines who wins. Standard prequalification thresholds (multi-year turnover, prior contracts of comparable size) mechanically exclude every Cypriot AI company, because none of them has previously delivered a national-scale AI programme; nobody has. The predictable outcome is that the entire portfolio goes to a small number of international integrators, the capability leaves the island with them at the end of each contract, and the AI Innovation Fund’s stated ambition of growing Cypriot ventures is contradicted by the state’s own spending. Lot-splitting costs the state nothing and is the only instrument here that actually builds domestic capability rather than describing it. Without an explicit KPI, this will not happen.
Second point, on Annex F itself. We ask above for one more KPI, so we should say plainly that the targets Annex F is meant to measure do not currently reconcile. We count four:
• 75% industry adoption by 2030 — Section 5, item 4, National AI Compliance Funding programme.
• 50% across government and priority sectors — Section 3.4, AI Adoption Across Government.
• 75% AI adoption by 2032, attributed to the Digital Decade target — Annex C, Government and Public Sector pillar. Two difficulties here: it states 75% for broadly the scope that Section 3.4 puts at 50%, and the Digital Decade target it invokes is 75% of enterprises by 2030, not 2032.
• 13% to 75% across education and labour by 2032 — Section 3.5, Education, and Annex C.
The second and third overlap in scope with different numbers, and the headline figure of 75% resolves to different bases and different dates depending on where it appears. Annex F will inherit whichever ambiguity is left unresolved, and a target that cannot be measured will not be managed. We suggest fixing one headline definition with an explicit base, scope and date, labelling the sectoral targets distinctly, and correcting the Digital Decade attribution. This is cheap to fix now and expensive to fix after Annex F is published.
Anro Technologies Limited (trading as AnroAgents), HE 439985, Cyprus. Comment 5 of 7.
5. FUND OPEN GREEK-LANGUAGE EVALUATION SETS FOR CONVERSATIONAL AGENTS THROUGH PHAROS-CY
Article / paragraph: Section 3.5 (Priority Sectors) — Tourism, “multilingual AI services”; Section 3.7.5 (Integration with EuroHPC and the European AI Factory Ecosystem); Section 3.8.6 (Pharos-CY as Cyprus’s AI Factory Antenna); Section 3.5 — Legal Services, “legal language model trained on Cyprus law”.
Comment / Suggestion: Include in the Pharos-CY AI Factory Antenna mandate the creation and open publication of Greek-language evaluation datasets and benchmarks for conversational and agentic systems — covering Cypriot Greek usage, public-administration and tourism/hospitality terminology, and safety behaviours (refusal, escalation, hallucination on domain facts). Publish under an open licence with a public leaderboard.
Rationale: The Strategy asks for multilingual public services and a Cypriot legal language model, but provides no way to tell whether any given system is actually good at Greek. Without shared benchmarks, “supports Greek” is a claim on a sales deck, procurement cannot discriminate between a competent system and a machine-translated one, and the state will buy the latter at the price of the former. Evaluation infrastructure is a classic public good: too expensive for any single vendor to build, cheap at national scale, and it disproportionately helps local suppliers, who are the ones with genuine Greek-language capability to demonstrate. It is also the least glamorous and most load-bearing item in this submission. We ship Greek in production today and would contribute test cases and vendor-side validation.
Anro Technologies Limited (trading as AnroAgents), HE 439985, Cyprus. Comment 4 of 7.
4. PUBLISH A PROPORTIONATE BASELINE FOR LIMITED-RISK CONVERSATIONAL AND AGENTIC SYSTEMS
Article / paragraph: Section 3.3.2 (Control Framework), Section 3.9 (Ethics, Trust and Responsible AI), NAICF Comply.
Comment / Suggestion: Commit to publishing, alongside NAICF, a short and concrete baseline for limited-risk conversational and agentic systems — the Article 50 transparency tier of the EU AI Act rather than the Chapter III high-risk regime. The baseline should be checkable and finite: disclosure that the user is interacting with an AI system; logging and retention of interactions; a guaranteed path to a human; data residency and sub-processor disclosure; scope limits on what actions the agent may take without confirmation. Vendors meeting the published baseline should receive a presumption of conformity for that tier, valid across the public sector and recognised in AdoptNAICF applications.
Rationale: Most AI that an SME will ever deploy — a website assistant, a booking agent, an internal search tool — is limited-risk under the AI Act. Where no proportionate national baseline exists, the market fills the gap with a maximalist reading, and SMEs are advised that every customer-facing assistant requires a full high-risk conformity exercise. The practical result is not better protection; it is that the SME does nothing, and the adoption figure does not move. A published baseline is simultaneously the cheapest consumer protection measure in the Strategy and its single most effective adoption accelerator, because it replaces an open-ended legal unknown with a checklist. It also gives Cyprus a concrete, exportable artefact for the “trusted jurisdiction” claim: a compliance baseline that a foreign SME can read in ten minutes is a better advertisement than a certification scheme it cannot afford.
Anro Technologies Limited (trading as AnroAgents), HE 439985, Cyprus. Comment 3 of 7.
3. THE 75% INDUSTRY ADOPTION TARGET IS UNREACHABLE UNLESS THE FUNDING INSTRUMENT FUNDS RUNNING SOFTWARE
Article / paragraph: Section 5, item 4 — National AI Compliance Funding programme, “targeted interventions aimed at achieving 75% industry adoption of AI technologies in Cyprus by 2030”; Section 2.2 — the 9.27% baseline and the recorded rate of progression; Section 2.5.3 (Objective 3); Section 3.5 — “Supporting Small and Medium-Sized Enterprises” (AdoptNAICF and the Industrial AI Centre of Excellence).
Comment / Suggestion: State in the Strategy that instruments intended to move industry adoption will fund the operation of production AI systems, not only advice about them. Concretely: AdoptNAICF support payable against twelve months of subscription and onboarding costs for a production AI product, disbursed to the vendor rather than reimbursed to the buyer; and a lower-friction track for micro-enterprises under ten employees, with a fixed sum and a one-page application. We note and support the earlier submission to this consultation raising subscription eligibility, and add to it the disbursement route and the micro-enterprise track.
Rationale: The Strategy sets 75% industry adoption by 2030 and, in the same document, records the starting point: 9.27% in 2025, reached “after an annual progression of 17.3% since 2024”. Those two numbers do not meet. Held at the recorded rate, 9.27% compounds to roughly 20.6% by 2030 — short of the target by a factor of about three and a half. Reaching 75% from 9.27% in five years requires sustained growth of roughly 52% a year, three times the rate the document itself observes. Extending the horizon to 2032 does not rescue the arithmetic; it moves the required rate to about 35% a year.
A gap of that size is not an awareness gap, and no volume of advisory work closes it. For a Cypriot firm with eight employees, the barrier is a recurring line item of a few hundred euro a month against uncertain payback, plus the two weeks of someone’s attention needed to configure the thing. An instrument that funds studies, assessments and pilots but not the running product yields a well-documented pipeline of abandoned proofs of concept — the “AI theatre” the Strategy itself names among its execution risks. Paying for the first year of live operation puts the system in front of real customers, where it either pays for itself and the firm renews unsubsidised, or it does not and the state has bought a cheap and honest answer. Either outcome is worth more than a report.
Anro Technologies Limited (trading as AnroAgents), HE 439985, Cyprus. Comment 2 of 7.
Declaration of interest. We sell agentic AI to Cypriot SMEs and would tender for national work in this field. Some of our recommendations, if adopted, would benefit us — as they would any vendor in this market.
2. MAKE THE NATIONAL AI REGISTRY MACHINE-READABLE AND QUERYABLE BY AGENTS
Article / paragraph: Section 5 (Immediate Steps), item 4 — “National AI application and certification registry” and “Development of an AI Registry”; Section 3.5, Legal Services — AIREG.
Comment / Suggestion: Specify that both registries will publish their non-confidential records through a documented public API in an open, machine-readable schema — and that this schema will be an existing agent capability description standard (OASF or equivalent), not a bespoke format. Every registered AI solution should be discoverable programmatically by capability, sector, risk classification, certification status, data residency and supported languages.
Rationale: As drafted, the registries are pure compliance instruments — a cost imposed on vendors with no return. Making them machine-readable converts the same artefact into a distribution channel at effectively zero marginal cost. Concretely: a procurement officer’s assistant, a foreign buyer’s agent, or an SME looking for a compliant supplier could query “certified, EU-resident, Greek-language customer-service agents operating in Cyprus” and get a structured answer. This is the difference between a registry that vendors comply with reluctantly and one they compete to be listed in. It also gives substance to the claim in Objective 1 that Cyprus is a trusted jurisdiction — trust that cannot be verified programmatically does not travel across borders.
This is not a theoretical ask. We already generate and publish OASF 1.0.0 records automatically for every agent on our platform and keep them current as agents change, so the marginal cost to a vendor already operating to the standard is close to zero — and the registry inherits a schema that has been tested against real deployments rather than designed in advance of them. We offer the schema mapping work to the Republic at no cost.
Offer, with its limits stated. We will produce the mapping as a written deliverable: a field-by-field mapping of the registry’s attributes onto OASF (sector to domains, capability to skills, endpoint to locators and modules); an explicit list of the regulatory attributes OASF does not currently accommodate — risk tier, conformity status, provider identity, data residency — together with a proposed extension to carry them, which we would submit upstream to the standard rather than leave as a Cyprus-local variant; a draft OpenAPI contract for the public query surface; and a version-drift policy. That last item is not hypothetical: OASF ships new schema versions, and a registry pinned to one of them decays silently. We run automated monitoring of exactly this drift in production and would contribute the policy alongside the mapping. Building, hosting or operating the registry endpoint itself is outside this free offer; if the Republic procures that work, we would tender for it on the same footing as any other supplier.
Submission to the Public Consultation on the National AI Strategy of the Republic of Cyprus 2032
Submitted by: Anro Technologies Limited (trading as AnroAgents), HE 439985, VAT CY10439985O, Cyprus.
Contact: Iana Bolshakova, Co-Founder and CBDO — yana@anroit.com.
This is comment 1 of 7; the full submission has also been sent to the consultation officer as a single document.
About the submitter. Anro Technologies Limited is a Cyprus-registered company operating AnroAgents, a platform for deploying AI agents for small and medium-sized businesses (conversational sales and service agents, retrieval over a customer’s own knowledge base, calendar and CRM integrations, Agen2Agent transactions and communication, directory of agents). The platform is deployed in tourism/hospitality, e-commerce, professional services, and other industries. Ships in six languages including Greek, and integrates with WordPress and Shopify — the two systems that carry the majority of Cypriot SME web presence.
Relevant to the comments below, we operate the following in production, from Cyprus, today:
• A node of the AGNTCY Agent Directory Service, live since June 2026 and joined to the public peer-to-peer directory network, with public gRPC and P2P endpoints.
• Automated generation and publication of OASF 1.0.0 records for agents on our platform, including classification against the OASF skills and domains taxonomy, with records refreshed when an agent changes.
• An A2A (Agent2Agent) gateway that makes directory-listed agents actually invokable agent-to-agent over JSON-RPC, with agent cards, rate limiting and per-agent isolation — that is, discovery and invocation, not discovery alone.
• An MCP (Model Context Protocol) server, published as a public npm package.
We state this not as a credential but because the recommendation below asks the Republic to commit to specific standards, and we think that request carries more weight from a party that has already implemented them and can describe what does and does not work.
1. NAME THE OPEN AGENT-INTEROPERABILITY STANDARDS THE STRATEGY WILL BUILD ON
Article / paragraph: Section 2.5.6 (Objective 6), Section 3.2.3 (Interoperability and Secure Data Sharing), Section 3.7.3 (Digital Sovereignty and Strategic Autonomy), and the Government and Public Sectors flagship — AI Industrial Centre of Excellence, tasked to “publish interoperability roadmaps and reference architectures” for agentic AI.
Comment / Suggestion: The Strategy commits repeatedly to interoperability, portability and vendor diversity for agentic AI, but does not name a single concrete standard. We propose that the Strategy state explicitly that Cyprus will adopt existing open, vendor-neutral agent interoperability standards as the national baseline rather than commission a national one. Specifically:
• A2A (Agent2Agent) — under the Linux Foundation — for agent-to-agent task delegation;
• MCP (Model Context Protocol) for agent-to-tool and agent-to-data-source connection;
• OASF (Open Agentic Schema Framework) and the AGNTCY Agent Directory model for describing, publishing and discovering agent capabilities.
The recommended wording for the Centre of Excellence mandate: “reference architectures shall be based on open, vendor-neutral agent interoperability standards adopted by recognised open-source foundations, and shall not introduce Cyprus-specific protocol variants where an international standard exists.”
Rationale: The Strategy’s own risk analysis (Section 3.7.3) identifies vendor lock-in and supply-chain dependency as strategic threats. In agentic systems, lock-in does not happen at the model layer, which is easily swapped — it happens at the orchestration and capability-description layer, which is not. A national protocol variant, however well designed, would be the fastest possible route to the outcome the Strategy is trying to avoid: it would make Cypriot deployments incompatible with the European and global agent ecosystem, raise the integration cost of every foreign supplier entering Cyprus, and make every Cypriot vendor’s product unexportable. Cyprus is too small a market to set a standard and large enough to be hurt by adopting the wrong one. Committing to the existing open standards costs nothing, is available today, and directly serves the “bridge between the EU and neighbouring regions” positioning: a bridge has to be built to a gauge both sides already use.
Offer: we propose that the Centre of Excellence establish a national reference deployment and conformance testbed for agent interoperability — a live directory node against which any vendor, Cypriot or foreign, can validate that its agent publishes a well-formed capability record and answers a standards-compliant invocation. We already run such a node in production from Cyprus and offer it as the pilot instance, together with the conformance test cases, at no cost to the state. If the Republic prefers the reference deployment to sit with a public body — the Centre of Excellence, Pharos-CY or CyNet — we will contribute the implementation and the operational runbook rather than compete for the role. The point is that the capability should exist and be publicly testable; who hosts it matters less.
Feedback on the Cyprus National AI Strategy 2032
On behalf of Smart Nautilus Ltd., I would like to congratulate the Government of Cyprus and the National AI Taskforce for preparing a comprehensive and forward-looking National AI Strategy. The Strategy establishes a strong foundation for the responsible adoption of Artificial Intelligence through governance, digital infrastructure, education, innovation and regulatory alignment.
As Cyprus moves towards implementation, I believe greater emphasis should be placed on execution, commercialization and the development of globally competitive AI capabilities.
To ensure that Cyprus continues to advance its vision and strengthen its capabilities within an increasingly competitive global landscape, the objectives and targets established under this strategic pillar should be realistic, measurable, and achievable. Their successful implementation should be supported by continuous monitoring, regular performance evaluation, and close collaboration between government, academia, industry, and other key stakeholders. Furthermore, the Strategy should remain adaptive and responsive to emerging technologies, evolving market demands, and international developments, ensuring that the national AI ecosystem continues to evolve through ongoing innovation, refinement, and sustainable development.
In particular, I recommend that the Government considers the following before final implementation:
1. Establish National AI Flagship Projects
The Strategy would benefit from a number of flagship national programmes demonstrating AI in practice. These should focus on sectors where Cyprus already has international competitive advantages, including maritime, ports, energy, water management, healthcare and public administration.
2. Expand the Maritime AI Vision
Cyprus is one of the world’s leading maritime centres. The Strategy should include a dedicated roadmap for Maritime AI covering autonomous robotics, smart ports, underwater inspection, vessel performance optimisation, biofouling management, maritime cybersecurity, digital twins and environmental monitoring. This represents an opportunity for Cyprus to become an international leader rather than simply an adopter of AI technologies.
3. Create a National Maritime AI & Autonomous Systems Centre of Excellence
A specialised Centre of Excellence bringing together government, universities and industry would accelerate research, certification, testing and commercial deployment of AI-powered maritime technologies while attracting international investment and talent.
4. Introduce Regulatory AI Sandboxes / Smart-box
Innovation should be supported through controlled regulatory environments that allow companies to safely test AI applications before commercial deployment, particularly in maritime, healthcare, finance, defence and critical infrastructure.
5. Strengthen Public-Private Partnerships
Successful implementation will depend on close collaboration between government, academia and industry. A structured national AI innovation consortium and industry advisory council would improve coordination and accelerate adoption.
6. Support Commercialisation and Export
The Strategy should include clear measures to transform research into commercial success through support for patents, technology transfer, venture creation, scale-up financing and international market expansion. Success should be measured not only by AI adoption but also by the number of globally competitive AI companies created in Cyprus.
7. Modernise Public Procurement
Public procurement should encourage innovation through pilot projects, outcome-based procurement and simplified procedures that enable startups and SMEs to participate in delivering AI solutions for the public sector.
8. Strengthen AI Security and Digital Sovereignty
As AI becomes critical national infrastructure, additional focus should be placed on AI security, trusted data, model integrity, cyber resilience and protection of critical infrastructure to ensure long-term national resilience.
9. Define Measurable Sector-Specific KPIs
Beyond national indicators, each priority sector should include measurable targets, implementation milestones and annual reporting mechanisms to ensure accountability and continuous improvement.
Overall, the National AI Strategy 2032 provides an excellent foundation for Cyprus to become a trusted AI nation. By strengthening implementation mechanisms, promoting commercialization, investing in flagship projects and leveraging Cyprus’ strategic advantages, particularly in maritime innovation, the country can position itself not only as a user of Artificial Intelligence, but as a recognized developer and exporter of AI technologies.
Smart Nautilus welcomes the opportunity to contribute its expertise in artificial intelligence, autonomous robotics, maritime digitalization and smart infrastructure to support the successful implementation of the National AI Strategy 2032.
Smart Nautilus remain committed to support and enhance the capabilities of the cluster using expertise, knowledge and evidence based technologies to advance the future applications!
With my very best regards
Athos Patsalides
Smart Nautilus
10. Γενική τοποθέτηση — Προσθήκη αυτοτελούς κεφαλαίου δημοκρατικής διακυβέρνησης
Article / paragraph
General comment on the Strategy as a whole, with particular reference to Sections 2.5.7, 3.3, 3.4, 3.9, 3.11, 3.13, Annex A, Annex B and Annex F.
Proposed amendment / recommendation
Να προστεθεί στην Εθνική Στρατηγική αυτοτελές κεφάλαιο με τίτλο:
«Δημοκρατική διακυβέρνηση, κοινοβουλευτική εποπτεία, δικαιώματα του πολίτη και κοινωνική λογοδοσία της Τεχνητής Νοημοσύνης».
Το κεφάλαιο να ενοποιεί και να καθιστά επιχειρησιακά εφαρμόσιμες τις πρόνοιες για:
• κοινοβουλευτική και δημόσια εποπτεία,
• δικαιώματα του πολίτη και ανθρώπινη επανεξέταση,
• δημόσιο μητρώο κρατικών συστημάτων ΤΝ,
• προστασία ανηλίκων και ευάλωτων ομάδων,
• δημοκρατική και εκλογική ακεραιότητα,
• διαφάνεια και έλεγχο δημόσιων προμηθειών,
• συμμετοχική και πολυμετοχική διακυβέρνηση,
• δίκαιη εργασιακή μετάβαση,
• ανεξάρτητη αξιολόγηση, δημοσιοποίηση περιστατικών και δημόσια λογοδοσία.
Να συνοδεύεται από συγκεκριμένο σχέδιο εφαρμογής, αρμόδιους φορείς, χρονοδιαγράμματα, δείκτες και ετήσια συζήτηση στη Βουλή.
Justification
Η Εθνική Στρατηγική περιλαμβάνει σημαντικές αρχές ανθρωποκεντρικής, αξιόπιστης και υπεύθυνης ΤΝ. Οι σχετικές πρόνοιες, όμως, είναι κατανεμημένες σε διαφορετικά κεφάλαια και παραρτήματα και κινδυνεύουν να παραμείνουν γενικές κατευθύνσεις χωρίς ενιαίο δημοκρατικό και δικαιωματικό πλαίσιο.
Η Στρατηγική πρέπει να απαντά όχι μόνο στο πώς θα υιοθετήσει η Κύπρος την ΤΝ, αλλά και στα ακόλουθα:
• Ποιος αποφασίζει πού και με ποιον τρόπο θα χρησιμοποιείται;
• Ποιος ελέγχει τα συστήματα, τα δεδομένα και τις συμβάσεις;
• Πώς προστατεύονται και ασκούνται στην πράξη τα δικαιώματα;
• Πώς αμφισβητούνται οι αλγοριθμικά υποβοηθούμενες αποφάσεις;
• Πώς προστατεύεται η δημοκρατική διαδικασία;
• Πώς κατανέμονται δίκαια τα οφέλη και οι κίνδυνοι;
Η επιτυχία της Στρατηγικής δεν πρέπει να κριθεί από τον αριθμό των εφαρμογών ΤΝ, αλλά από το κατά πόσο αυτές βελτιώνουν πραγματικά τη ζωή των πολιτών, μειώνουν τη γραφειοκρατία, προστατεύουν δικαιώματα, διατηρούν τον ανθρώπινο έλεγχο και ενισχύουν τη δημοκρατική λογοδοσία.
Η Τεχνητή Νοημοσύνη πρέπει να υπηρετεί τον άνθρωπο, τη δημοκρατία και το δημόσιο συμφέρον. Η Κύπρος έχει την ευκαιρία να αποτελέσει όχι μόνο χώρα ταχείας υιοθέτησης της ΤΝ, αλλά πρότυπο μικρού, ευέλικτου και δημοκρατικά υπεύθυνου κράτους.
9. Μετρήσιμη εφαρμογή, δημόσια λογοδοσία και ανεξάρτητη αξιολόγηση
Article / paragraph
Sections 1.5 (Implementation Timeline and Success Metrics), 3.11 (Measuring Impact and National KPIs), particularly 3.11.1–3.11.4, 4.1.6 (Continuous Feedback Loop), 5 (Immediate Steps for the Strategy Launch), and Annex F (National KPIs and Measurement Framework).
Proposed amendment / recommendation
Κάθε στρατηγικός στόχος, πρόγραμμα και σημαντικό έργο να συνδέεται με:
• σαφώς καθορισμένο υπεύθυνο φορέα και ονομαστικά καθορισμένη θεσμική ευθύνη,
• συγκεκριμένο χρονοδιάγραμμα και ενδιάμεσα ορόσημα,
• προβλεπόμενη χρηματοδότηση και συνολικό κόστος κύκλου ζωής,
• αρχικές τιμές αναφοράς, ποσοτικούς στόχους και μεθοδολογία μέτρησης,
• δείκτες εισροών, εκροών, αποτελεσμάτων και κοινωνικών επιπτώσεων,
• ετήσια δημόσια έκθεση προόδου σε ανοικτή και μηχαναγνώσιμη μορφή,
• ανεξάρτητη εξωτερική αξιολόγηση σε προκαθορισμένα χρονικά διαστήματα,
• δημόσια παρουσίαση και συζήτηση των αποτελεσμάτων στη Βουλή,
• μηχανισμό διορθωτικής δράσης όταν υπάρχουν αποκλίσεις ή ανεπαρκή αποτελέσματα.
Να δημοσιεύονται επίσης:
• σοβαρά περιστατικά αστοχίας, παραβίασης δεδομένων, διακρίσεων ή άλλων επιπτώσεων,
• συστήματα που αναστέλλονται, τροποποιούνται ή αποσύρονται,
• διορθωτικές ενέργειες και χρόνοι αποκατάστασης,
• αποτελέσματα αξιολόγησης δημόσιας αξίας και ικανοποίησης πολιτών,
• εκτιμήσεις κόστους-οφέλους και εξοικονόμησης διοικητικού κόστους.
Οι εθνικοί δείκτες να περιλαμβάνουν, πέρα από ΑΕΠ, παραγωγικότητα, επενδύσεις και αριθμό επαγγελματιών, δείκτες δικαιωμάτων, εμπιστοσύνης, προσβασιμότητας, ισότητας, ποιότητας εργασίας, ενεργειακής επίπτωσης και επιτυχούς ανθρώπινης επανεξέτασης.
Justification
Η Στρατηγική ορθά δηλώνει ότι πρέπει να μετρώνται αποτελέσματα και όχι απλώς ο αριθμός έργων ή πιλοτικών εφαρμογών. Για να είναι αυτό εφαρμόσιμο, οι δείκτες πρέπει να συνδέονται με βάσεις αναφοράς, αρμόδιους φορείς, χρηματοδότηση και σαφείς συνέπειες όταν τα αποτελέσματα δεν επιτυγχάνονται.
Η λογοδοσία πρέπει να αφορά όχι μόνο την οικονομική και διοικητική απόδοση, αλλά και τις επιπτώσεις στα δικαιώματα, στην κοινωνική συνοχή και στην εμπιστοσύνη.
Η διαφάνεια πρέπει να καλύπτει τις επιτυχίες, αλλά και τα λάθη, τις αποτυχίες, τις αναστολές έργων και τα διορθωτικά μέτρα. Αυτό είναι απαραίτητο για πραγματική οργανωσιακή μάθηση και όχι απλώς για επικοινωνιακή παρουσίαση προόδου.
8. Συμμετοχική και πολυμετοχική διακυβέρνηση
Article / paragraph
Sections 3.3.1 (Governance Structure), 3.3.1.3 (National AI Taskforce), 3.3.1.5 (National Ethics and Values Committee), 3.3.1.6 (National AI Misinformation and Security Council), 4.1.6 (Continuous Feedback Loop), and 3.11.3–3.11.4.
Proposed amendment / recommendation
Να δημιουργηθεί μόνιμο Εθνικό Φόρουμ για την ΤΝ και την Ψηφιακή Δημοκρατία, με συμβουλευτικό, συμμετοχικό και αξιολογικό ρόλο στην εφαρμογή και περιοδική αναθεώρηση της Στρατηγικής.
Στο Φόρουμ να συμμετέχουν:
• η εκτελεστική και η νομοθετική εξουσία,
• οι αρμόδιες ανεξάρτητες και ρυθμιστικές αρχές,
• πανεπιστήμια, ερευνητικά κέντρα και επαγγελματικές επιστημονικές ενώσεις,
• επιχειρήσεις, νεοφυείς εταιρείες και εκπρόσωποι μικρομεσαίων επιχειρήσεων,
• εργαζόμενοι, συντεχνίες και επαγγελματικοί φορείς,
• οργανώσεις ανθρωπίνων δικαιωμάτων και προστασίας καταναλωτών,
• οργανώσεις παιδιών, γονέων, εκπαιδευτικών και νέων,
• δημοσιογράφοι, φορείς fact-checking και εκπρόσωποι της κοινωνίας των πολιτών,
• εκπρόσωποι ατόμων με αναπηρία, ηλικιωμένων και άλλων ευάλωτων ομάδων,
• πολίτες που θα επιλέγονται μέσω δομημένων, αντιπροσωπευτικών διαβουλευτικών διαδικασιών.
Το Φόρουμ να:
• σχολιάζει το ετήσιο πρόγραμμα εφαρμογής και τις ετήσιες εκθέσεις,
• προτείνει νέους δείκτες και τομείς προτεραιότητας,
• αναδεικνύει αναδυόμενους κοινωνικούς κινδύνους,
• οργανώνει δημόσιες ακροάσεις και θεματικούς διαλόγους,
• δημοσιεύει ανεξάρτητη γνώμη πριν από κάθε ουσιώδη αναθεώρηση της Στρατηγικής.
Η σύνθεσή του να αποτρέπει την κυριαρχία οποιασδήποτε μίας κατηγορίας συμφερόντων και να εφαρμόζονται κανόνες διαφάνειας και δήλωσης συγκρούσεων συμφερόντων.
Justification
Η προβλεπόμενη διακυβέρνηση στηρίζεται σε κυβερνητικά, τεχνοκρατικά και εξειδικευμένα σώματα. Αυτά είναι αναγκαία, αλλά δεν υποκαθιστούν τη συνεχή κοινωνική συμμετοχή.
Η ΤΝ επηρεάζει διαφορετικές ομάδες με διαφορετικούς τρόπους. Η αναγνώριση κινδύνων, η αξιολόγηση δημόσιας αξίας και η διαμόρφωση κοινωνικής αποδοχής δεν μπορούν να επιτευχθούν μόνο μέσω τεχνικής εμπειρογνωμοσύνης.
Η κοινωνία δεν πρέπει απλώς να ενημερώνεται μετά τη λήψη αποφάσεων. Πρέπει να συμμετέχει στον καθορισμό προτεραιοτήτων, στην αναγνώριση επιπτώσεων και στην αξιολόγηση των αποτελεσμάτων.
7. ΤΝ, εργασία και δίκαιη μετάβαση
Article / paragraph
Sections 2.5.2 (Objective 2: Responsible productivity), 2.5.5 (Objective 5: Skills and Talent), 3.3.1.7 (National AI Skills Observatory), 3.6 (Talent, Skills and Workforce Transformation), particularly 3.6.3 and 3.6.4, and Annex C – Education and Human Capital Development / FutureAI CY.
Proposed amendment / recommendation
Να δημιουργηθεί εθνικός μηχανισμός παρακολούθησης των επιπτώσεων της ΤΝ στην απασχόληση, στα επαγγελματικά καθήκοντα, στις συνθήκες εργασίας, στην ποιότητα των θέσεων εργασίας και στις μισθολογικές ανισότητες, με κεντρικό ρόλο του National AI Skills Observatory.
Να προβλεφθούν:
• έγκαιρη χαρτογράφηση επαγγελμάτων και καθηκόντων που επηρεάζονται,
• task-impact assessments πριν από μεγάλης κλίμακας εισαγωγή ΤΝ,
• προγράμματα επανακατάρτισης πριν από την απώλεια ή ουσιώδη μεταβολή θέσεων εργασίας,
• συμμετοχή εργαζομένων και συντεχνιών στον σχεδιασμό και στην αξιολόγηση συστημάτων που επηρεάζουν την εργασία,
• προστασία από αδιαφανή αλγοριθμική πρόσληψη, αξιολόγηση, επιτήρηση, πειθαρχία ή απόλυση,
• δικαίωμα ενημέρωσης και ανθρώπινης επανεξέτασης αποφάσεων αλγοριθμικής διαχείρισης,
• αξιολόγηση των επιπτώσεων στην ένταση της εργασίας, στην αυτονομία, στην επαγγελματική ευθύνη και στην ψυχική υγεία,
• δίκαιη κατανομή των ωφελειών από την αυξημένη παραγωγικότητα,
• ειδική υποστήριξη μικρών επιχειρήσεων, αυτοεργοδοτουμένων, μεγαλύτερων σε ηλικία εργαζομένων και ευάλωτων ομάδων,
• ετήσια δημόσια έκθεση για μεταβολές στην αγορά εργασίας, συμμετοχή σε επανακατάρτιση και πραγματικά αποτελέσματα απασχόλησης.
Οι δείκτες επιτυχίας να μετρούν όχι μόνο αριθμούς καταρτισθέντων ή νέων ειδικών, αλλά διατήρηση απασχόλησης, ποιότητα εργασίας, επαγγελματική κινητικότητα και κατανομή των παραγωγικών ωφελειών.
Justification
Η Στρατηγική δηλώνει ότι η ΤΝ θα χρησιμοποιείται για ενίσχυση και όχι αντικατάσταση της ανθρώπινης εργασίας και προβλέπει επανακατάρτιση. Χρειάζεται, όμως, σαφέστερος μηχανισμός πρόληψης, συμμετοχής και αξιολόγησης των πραγματικών συνεπειών.
Η αύξηση της παραγωγικότητας δεν πρέπει να αποτελεί τον μοναδικό δείκτη επιτυχίας. Μπορεί να συνυπάρξει με εντατικοποίηση της εργασίας, αποδυνάμωση επαγγελματικής αυτονομίας, αδιαφανή επιτήρηση ή άνιση κατανομή των ωφελειών.
Η δίκαιη μετάβαση απαιτεί έγκαιρη πρόβλεψη, κοινωνικό διάλογο και δυνατότητα παρέμβασης πριν οι επιπτώσεις καταστούν μη αναστρέψιμες.
6. Διαφανείς, ελέγξιμες και υπεύθυνες δημόσιες προμήθειες ΤΝ
Article / paragraph
Sections 2.5.7, 2.5.8 (Sovereign Capability through Partnerships), 3.1.2 (Design Principles), 3.3.2 (Control Framework), 3.4.1 (Priority Areas for Government Adoption and AI-first procurement), 3.6.3 (Public-Sector Capability), and Annex B.
Proposed amendment / recommendation
Να θεσπιστεί ειδικό, δεσμευτικό πλαίσιο για τις δημόσιες προμήθειες συστημάτων ΤΝ, το οποίο να υπερβαίνει τα συνήθη κριτήρια τιμής και βασικής τεχνικής επάρκειας.
Κάθε σχετική σύμβαση να διασφαλίζει:
• πρόσβαση του κράτους σε επαρκή τεχνική τεκμηρίωση,
• δυνατότητα ανεξάρτητου τεχνικού, νομικού, δεοντολογικού και κυβερνοασφαλιστικού ελέγχου,
• σαφείς όρους για την κυριότητα, τη χρήση, την επαναχρησιμοποίηση και τη διαγραφή δεδομένων,
• δυνατότητα μεταφοράς δεδομένων, μοντέλων και υπηρεσιών σε άλλο προμηθευτή,
• αποφυγή τεχνολογικού εγκλωβισμού και αδικαιολόγητης αποκλειστικότητας,
• διαλειτουργικότητα, φορητότητα και χρήση ανοικτών προτύπων όπου είναι εφικτό,
• τεκμηριωμένη απόδοση, ακρίβεια και καταλληλότητα για τον συγκεκριμένο σκοπό,
• συνεχή παρακολούθηση αστοχιών, μεροληψίας και μεταβολής απόδοσης,
• ρήτρες ευθύνης, διόρθωσης, αποζημίωσης, αναστολής και ασφαλούς τερματισμού,
• πλήρη audit logs και διατήρηση αποδεικτικών στοιχείων,
• δημοσιοποίηση του συνολικού κόστους κύκλου ζωής και των μετρήσιμων αποτελεσμάτων,
• αξιολόγηση της ενεργειακής και περιβαλλοντικής επίπτωσης όπου αυτή είναι ουσιώδης.
Να καθοριστούν πρότυπα τεύχη προδιαγραφών και συμβατικών ρητρών από την Εθνική Αρχή ΤΝ, σε συνεργασία με το Γενικό Λογιστήριο, τη Νομική Υπηρεσία, τις αρμόδιες εποπτικές αρχές και ανεξάρτητους εμπειρογνώμονες.
Justification
Η Στρατηγική προτείνει μετάβαση προς AI-first procurement και ενσωματώνει control gates πριν από την προμήθεια και την ανάπτυξη. Χωρίς ειδικούς συμβατικούς και τεχνικούς κανόνες, όμως, το κράτος κινδυνεύει να αγοράζει συστήματα τα οποία δεν μπορεί να ελέγξει, να μεταφέρει, να διορθώσει ή να παύσει με ασφάλεια.
Η εξάρτηση από κλειστά συστήματα και αποκλειστικούς προμηθευτές μπορεί να περιορίσει την ψηφιακή κυριαρχία, να αυξήσει το μακροπρόθεσμο κόστος και να δυσχεράνει τον έλεγχο της νομιμότητας και της αποτελεσματικότητας.
Η υπεύθυνη προμήθεια αποτελεί κρίσιμο σημείο πρόληψης. Πολλοί κίνδυνοι μπορούν να περιοριστούν μόνο εάν οι κατάλληλες απαιτήσεις ενσωματωθούν πριν από την υπογραφή της σύμβασης και όχι μετά την έναρξη λειτουργίας.
5. Προστασία παιδιών και εφήβων
Article / paragraph
Sections 2.5.5 (Objective 5: Skills and Talent), 3.6.1 (AI Literacy and Awareness), 3.9 (Ethics, Trust and Responsible AI), Annex C – Education and Human Capital Development, including the Cyprus AI Literacy Framework (CALF) and the Ethical Pedagogical Validation Layer (EPVL).
Proposed amendment / recommendation
Η προστασία παιδιών και εφήβων να αποτελέσει αυτοτελή, οριζόντια και μετρήσιμη προτεραιότητα της Εθνικής Στρατηγικής και όχι μόνο διάσταση της εκπαίδευσης ή της ψηφιακής παιδείας.
Να συμπεριληφθούν συγκεκριμένα μέτρα για:
• περιορισμό εθιστικών, χειριστικών και παραπλανητικών σχεδιαστικών πρακτικών,
• προστασία από την αλγοριθμική προώθηση αυτοκαταστροφικού, βίαιου, σεξουαλικού ή άλλου βλαβερού περιεχομένου,
• αποτροπή της εμπορικής εκμετάλλευσης προσωπικών δεδομένων ανηλίκων,
• προστασία από grooming, σεξουαλική εκμετάλλευση, πλαστοπροσωπία και τεχνητά παραγόμενο κακοποιητικό υλικό,
• ασφαλή, ηλικιακά κατάλληλη και παιδαγωγικά τεκμηριωμένη χρήση συστημάτων παραγωγικής ΤΝ στην εκπαίδευση,
• ανεξάρτητη αξιολόγηση εκπαιδευτικών συστημάτων ΤΝ πριν από ευρεία εφαρμογή,
• εκπαίδευση παιδιών, γονέων, εκπαιδευτικών, επαγγελματιών ψυχικής υγείας και λειτουργών προστασίας,
• εύχρηστους και ασφαλείς μηχανισμούς αναφοράς, υποστήριξης και αποκατάστασης,
• συστηματική έρευνα και παρακολούθηση των επιπτώσεων των ΜΚΔ και της ΤΝ στην ψυχική υγεία, στη γνωστική ανάπτυξη και στις κοινωνικές σχέσεις.
Οι δείκτες εφαρμογής να περιλαμβάνουν όχι μόνο επίπεδα AI literacy, αλλά και δείκτες ασφάλειας, ευημερίας, προσβασιμότητας και ισότιμης συμμετοχής.
Justification
Το Annex C περιλαμβάνει σημαντικά στοιχεία, όπως ηλικιακά διαβαθμισμένο πλαίσιο AI literacy και μηχανισμό παιδαγωγικής επικύρωσης. Ωστόσο, η προστασία των ανηλίκων δεν εξαντλείται στη σχολική χρήση της ΤΝ.
Τα παιδιά αποτελούν αναπτυσσόμενα άτομα με αυξημένη ευαλωτότητα σε χειριστικές τεχνικές, κοινωνική σύγκριση, ακατάλληλο περιεχόμενο, πλαστοπροσωπία και αλγοριθμική ενίσχυση βλαβερών προτύπων.
Η ψηφιακή και αλγοριθμική παιδεία πρέπει να συνδυάζεται με πρόληψη, ασφαλή σχεδιασμό, λογοδοσία των παρόχων και προσβάσιμους μηχανισμούς προστασίας. Η Εθνική Στρατηγική πρέπει να αντιμετωπίζει τον ανήλικο ως φορέα ειδικών δικαιωμάτων και όχι απλώς ως μελλοντικό χρήστη ή εργαζόμενο.
4. ΜΚΔ, deepfakes, παραπληροφόρηση και δημοκρατική ακεραιότητα
Article / paragraph
Sections 3.3.1.6 (National AI Misinformation and Security Council), 3.9.2–3.9.6 (Ethics, Trust and Responsible AI), 3.13 (Risk Management, Resilience and Adaptation), Annex A (Ethics and Fundamental Rights), and the Strategy-wide provisions on trustworthy and human-centred AI.
Proposed amendment / recommendation
Να διευρυνθεί και να εξειδικευτεί η εντολή του National AI Misinformation and Security Council και να προστεθεί αυτοτελές πλαίσιο δράσης για τις επιπτώσεις της παραγωγικής ΤΝ και των Μέσων Κοινωνικής Δικτύωσης στη δημοκρατία, στην ενημέρωση και στην εκλογική διαδικασία.
Το πλαίσιο να περιλαμβάνει:
• εθνικό πρωτόκολλο ταχείας αναγνώρισης, επαλήθευσης και δημόσιας επισήμανσης deepfakes,
• ειδικό σχέδιο προστασίας εκλογών και δημοψηφισμάτων,
• πλήρη διαφάνεια στην ψηφιακή πολιτική διαφήμιση, στη χρηματοδότηση και στη στόχευσή της,
• υποχρεωτική και ευδιάκριτη σήμανση περιεχομένου που παράγεται ή αλλοιώνεται ουσιωδώς μέσω ΤΝ,
• μηχανισμούς εντοπισμού συντονισμένης μη αυθεντικής συμπεριφοράς, δικτύων ψεύτικων λογαριασμών και αυτοματοποιημένης χειραγώγησης,
• πρωτόκολλα για περιπτώσεις πλαστοπροσωπίας δημόσιων προσώπων, δημοσιογράφων και κρατικών υπηρεσιών,
• συνεργασία κράτους, Βουλής, πανεπιστημίων, δημοσιογράφων, ρυθμιστικών αρχών και οργανώσεων της κοινωνίας,
• πρόσβαση ανεξάρτητων ερευνητών σε κατάλληλα δεδομένα για τη μελέτη συστημικών κινδύνων των πλατφορμών,
• ετήσια δημόσια έκθεση για απειλές, περιστατικά, τάσεις και μέτρα αντιμετώπισης.
Να διασφαλίζεται ότι τα μέτρα προστατεύουν τη δημοκρατική διαδικασία χωρίς να εγκαθιδρύουν μηχανισμό κρατικής λογοκρισίας ή αδικαιολόγητο περιορισμό της ελευθερίας έκφρασης.
Justification
Η Στρατηγική αναγνωρίζει την παραπληροφόρηση ως πεδίο εποπτείας, αλλά η προβλεπόμενη εντολή παραμένει γενική. Τα ΜΚΔ και η παραγωγική ΤΝ έχουν πλέον καταστεί κρίσιμες υποδομές της δημόσιας σφαίρας και μπορούν να επηρεάσουν άμεσα την πολιτική συμμετοχή, τις εκλογές και την εμπιστοσύνη στους θεσμούς.
Η μαζική παραγωγή παραπλανητικού περιεχομένου, η πλαστοπροσωπία, η αδιαφανής μικροστόχευση και η αυτοματοποιημένη προπαγάνδα απαιτούν σαφείς διαδικασίες πρόληψης, ταχείας αντίδρασης και δημόσιας λογοδοσίας.
Η παρέμβαση πρέπει να είναι δικαιωματικά ισορροπημένη: να αντιμετωπίζει τη συντονισμένη χειραγώγηση και την εξαπάτηση, διαφυλάσσοντας ταυτόχρονα την ελευθερία έκφρασης, τον πλουραλισμό και την ανεξαρτησία της δημοσιογραφίας.
3. Χάρτης Δικαιωμάτων του Πολίτη απέναντι στην ΤΝ
Article / paragraph
Sections 1.1 (Human-Centred AI, Trust and Transparency, and Social Contract Rights Protection), 1.4.8 (Ethics, Trust and Responsible AI), 2.5.7, 3.1.2 (Design Principles), 3.4.3 (Human Oversight and Accountability), 3.9.3–3.9.6, and Annex A (Ethics and Fundamental Rights).
Proposed amendment / recommendation
Η Εθνική Στρατηγική να συνοδεύεται από σαφή και κατανοητό Χάρτη Δικαιωμάτων του Πολίτη όταν αυτός αλληλεπιδρά με σύστημα ΤΝ ή επηρεάζεται από αυτοματοποιημένη ή αλγοριθμικά υποβοηθούμενη απόφαση.
Ο Χάρτης να κατοχυρώνει τουλάχιστον:
• το δικαίωμα ενημέρωσης ότι χρησιμοποιείται σύστημα ΤΝ,
• το δικαίωμα σε ουσιαστική και κατανοητή εξήγηση της απόφασης ή σύστασης,
• το δικαίωμα ανθρώπινης παρέμβασης, επανεξέτασης και υπερίσχυσης της ανθρώπινης κρίσης,
• το δικαίωμα ένστασης, αποτελεσματικής προσφυγής και έγκαιρης αποκατάστασης,
• το δικαίωμα πρόσβασης και διόρθωσης λανθασμένων ή ελλιπών δεδομένων,
• την προστασία από διακρίσεις και αλγοριθμική μεροληψία,
• την προστασία της ιδιωτικότητας και τον περιορισμό της χρήσης δεδομένων στον δηλωμένο σκοπό,
• το δικαίωμα πρόσβασης σε εναλλακτικό, μη αποκλειστικά ψηφιακό τρόπο εξυπηρέτησης,
• το δικαίωμα ενημέρωσης για τον υπεύθυνο φορέα και τον τρόπο υποβολής παραπόνου.
Να καθοριστεί ρητά ότι καμία κρίσιμη απόφαση για κοινωνικές παροχές, υγεία, εκπαίδευση, εργασία, φορολογία, αστυνόμευση, μετανάστευση, αδειοδότηση ή πρόσβαση σε δημόσιες υπηρεσίες δεν θα λαμβάνεται αποκλειστικά από αυτοματοποιημένο σύστημα.
Justification
Η Στρατηγική αναγνωρίζει ήδη την εξηγησιμότητα, την αμφισβήτηση, την ανθρώπινη επανεξέταση και την ανθρώπινη εποπτεία. Οι αρχές αυτές πρέπει να μετατραπούν σε συγκεκριμένα, εύκολα αναγνωρίσιμα και εφαρμόσιμα δικαιώματα.
Ο πολίτης δεν αρκεί να πληροφορείται ότι ένα σύστημα χαρακτηρίζεται «υπεύθυνο» ή «αξιόπιστο». Πρέπει να γνωρίζει τι δικαιούται να απαιτήσει, ποιος φέρει ευθύνη, σε ποιον μπορεί να απευθυνθεί και μέσα σε ποιο χρονικό διάστημα πρέπει να λάβει απάντηση.
Ένας ενιαίος Χάρτης θα ενισχύσει τη νομική σαφήνεια, τη διοικητική συνέπεια και την εμπιστοσύνη, ιδιαίτερα σε περιπτώσεις όπου οι αποφάσεις επηρεάζουν ουσιωδώς δικαιώματα ή την καθημερινή ζωή.
2. Δημόσιο μητρώο συστημάτων ΤΝ του κράτους
Article / paragraph
Sections 2.5.7, 3.3 (Governance and Controls), 3.3.2 (Control Framework), 3.4 (AI Adoption Across Government), 3.9.3 (Transparency and Explainability), 3.9.6 (AI Social Contract Principles), and Annex B (AI Use Case Lifecycle and Control Gates).
Proposed amendment / recommendation
Να δημιουργηθεί δημόσιο, ενιαίο και διαρκώς ενημερωμένο μητρώο όλων των συστημάτων ΤΝ και των ουσιωδών αλγοριθμικών εργαλείων που χρησιμοποιούνται, αναπτύσσονται, δοκιμάζονται ή προμηθεύονται από υπουργεία, υφυπουργεία, δήμους, οργανισμούς δημοσίου δικαίου και άλλους δημόσιους φορείς.
Για κάθε σύστημα να δημοσιεύονται, στον βαθμό που δεν επηρεάζεται η εθνική ασφάλεια, η κυβερνοασφάλεια ή νόμιμο εμπορικό απόρρητο:
• ο σκοπός και το πεδίο χρήσης,
• ο υπεύθυνος δημόσιος φορέας και ο αρμόδιος λειτουργός,
• ο κατασκευαστής, προμηθευτής ή φορέας ανάπτυξης,
• οι βασικές κατηγορίες δεδομένων που χρησιμοποιούνται,
• η ταξινόμηση κινδύνου και η νομική βάση,
• οι προβλεπόμενες μορφές ανθρώπινης εποπτείας,
• η κατάσταση έγκρισης και το στάδιο του κύκλου ζωής,
• οι εκτιμήσεις επιπτώσεων και οι έλεγχοι συμμόρφωσης,
• οι διαδικασίες ενημέρωσης, ένστασης και ανθρώπινης επανεξέτασης,
• τα αποτελέσματα ελέγχων ακρίβειας, μεροληψίας και ασφάλειας,
• το κόστος ανάπτυξης, αγοράς, αδειοδότησης και συντήρησης,
• τυχόν σοβαρά περιστατικά, αναστολές ή αποσύρσεις.
Το μητρώο να συνδέεται με τα control gates του Annex B και να ενημερώνεται πριν από την επιχειρησιακή χρήση κάθε συστήματος και μετά από κάθε ουσιώδη τροποποίησή του.
Justification
Η Στρατηγική απαιτεί τεκμηρίωση, ιχνηλασιμότητα, ελεγκτικότητα, ταξινόμηση κινδύνου και συνεχή παρακολούθηση, αλλά δεν τα μετατρέπει με σαφήνεια σε ενιαίο δημόσιο μηχανισμό πληροφόρησης.
Ο πολίτης πρέπει να γνωρίζει πότε και με ποιον τρόπο χρησιμοποιείται ΤΝ κατά την άσκηση δημόσιας εξουσίας ή την παροχή υπηρεσιών. Το μητρώο θα ενισχύσει τη διαφάνεια, θα επιτρέψει ουσιαστικό κοινοβουλευτικό, επιστημονικό και κοινωνικό έλεγχο, θα περιορίσει τις αλληλοεπικαλύψεις και θα διευκολύνει τη συμμόρφωση με το ευρωπαϊκό θεσμικό πλαίσιο.
Η δημοσιοποίηση δεν απαιτεί αποκάλυψη πηγαίου κώδικα ή πληροφοριών που δημιουργούν κίνδυνο ασφάλειας. Απαιτεί, όμως, επαρκή διαφάνεια ώστε η λειτουργία του ψηφιακού κράτους να μην μετατρέπεται σε αδιαφανή άσκηση εξουσίας.
1. Μόνιμος μηχανισμός κοινοβουλευτικής εποπτείας
Article / paragraph
Sections 2.5.7 (Objective 7: Embed strong governance, ethics and accountability across all AI use), 3.3 (Governance and Controls), 3.3.1 (Governance Structure), 3.11.3 (Monitoring and Reporting), and 4.1.2 (Governance and Policy Foundations).
Proposed amendment / recommendation
Να προστεθεί ρητή πρόνοια για θεσμική και συστηματική κοινοβουλευτική εποπτεία της εφαρμογής της Εθνικής Στρατηγικής για την Τεχνητή Νοημοσύνη.
Η εποπτεία μπορεί να ασκείται μέσω ειδικής κοινοβουλευτικής επιτροπής ή, ως μεταβατική λύση, μέσω μόνιμης διακομματικής υπο-επιτροπής ή θεσμοθετημένου μηχανισμού συντονισμού μεταξύ των αρμόδιων κοινοβουλευτικών επιτροπών.
Ο μηχανισμός αυτός πρέπει να παρακολουθεί:
• την εφαρμογή της Εθνικής Στρατηγικής και την πρόοδο έναντι των εθνικών δεικτών,
• τη συμμόρφωση με τον ευρωπαϊκό Κανονισμό για την ΤΝ και το ευρύτερο ευρωπαϊκό ψηφιακό κεκτημένο,
• τη χρήση συστημάτων ΤΝ από το κράτος και τους οργανισμούς δημοσίου δικαίου,
• τις δημόσιες συμβάσεις, τις σχετικές δαπάνες και την τεχνολογική εξάρτηση,
• τις επιπτώσεις στην εργασία, την εκπαίδευση, την υγεία, την ασφάλεια και τα ανθρώπινα δικαιώματα,
• την παραπληροφόρηση, τα deepfakes, την πολιτική μικροστόχευση και την εκλογική ακεραιότητα,
• την προστασία παιδιών, εφήβων και άλλων ευάλωτων ομάδων στο ψηφιακό περιβάλλον.
Να προβλέπεται τουλάχιστον ετήσια παρουσίαση στη Βουλή από την Εθνική Αρχή ΤΝ, με δημόσια συζήτηση της έκθεσης προόδου, των σημαντικών περιστατικών, των αποκλίσεων από τους στόχους και των αναγκαίων διορθωτικών μέτρων.
Justification
Η προτεινόμενη δομή διακυβέρνησης είναι κατά κύριο λόγο εκτελεστική και τεχνοκρατική. Προβλέπει Εθνική Αρχή ΤΝ, Διυπουργικό Συμβούλιο, συμβουλευτικά και εποπτικά σώματα, χωρίς όμως να εντάσσει ρητά τη νομοθετική εξουσία στη συνεχή εποπτεία της εφαρμογής.
Η ΤΝ επηρεάζει την άσκηση δημόσιας εξουσίας, την κατανομή δημόσιων πόρων, τα δικαιώματα των πολιτών, την αγορά εργασίας και τη δημοκρατική διαδικασία. Η λογοδοσία, επομένως, δεν μπορεί να εξαντλείται σε εσωτερική διοικητική παρακολούθηση.
Η αποσπασματική εξέταση θεμάτων ΤΝ από διαφορετικές κοινοβουλευτικές επιτροπές δεν εξασφαλίζει θεσμική μνήμη, οριζόντιο συντονισμό και συνεχή εξειδίκευση. Ένας σταθερός κοινοβουλευτικός μηχανισμός θα συμπληρώσει, χωρίς να υποκαταστήσει, τα εκτελεστικά και ρυθμιστικά όργανα της Στρατηγικής.
The National AI Strategy for Cyprus is a strong, an ambitious, comprehensive and pragmatic roadmap that seeks to transform the island’s public service and economy. It is a strong and honest strategy that aims for long-term resilience across sectors and sets an important precedent for future government strategies. I appreciate that it makes an honest assessment of the existing weaknesses and gaps, and I believe this can also serve as an impetus to close these. The principles of human-centred and ethical AI, trust and accountability are cross-cutting issues that are mentioned across the document and this is also an important element when re-designing government services. The strategic philosophy behind this strategy is that AI can be an enabler of productivity and public sector transformation, and a strategic asset to enhance national resilience in many ways, always when developed and deployed responsibly and with oversight, and within an EU framework.
The below feedback in this e-consultation, although valuable and constructive, I believe cannot all be reflected in the document due to some obvious reasons: 1. The strategy will end up becoming too long, exhaustive and will result into a politicized document, which would go against the very purpose of the strategy, which is to serve as a guiding, overarching document for a whole-of-government reform. 2. And because the technical, bureaucratic details addressed can be put forth in posterity, to the appropriate ministries and institutions.
After reading the document, I would like to provide the following feedback:
On page 2: on the bullet point referring to “Human Oversight and Social Rights Protection”, I would add in the last sentence “in sensitive areas like health…and private data”. Privacy of data are of outmost importance to citizens and this needs to be explicitly stated.
Page 3: Under 1.3, first bullet point on Government and Public Sector: adding “data re-categorization/classification”. Justification: Data re-categorization for AI is the process of updating, cleaning, and restructuring how information is labeled and organized so that machine learning models and language tools can understand it better. It involves defining clear categories, removing old or messy tags, and using automated tools to re-tag files or databases (Forbes, 2025). This is important as public institutions tend to suffer from fragmented data, old datasets and outdate legacy systems. Data modernization (mentioned in page 10) requires first data classification, which is about understanding what private data exist and where it resides.
Under that same section 1.3 I would also add a bullet point “Cybersecurity”. Although it is mentioned later in the document, in the executive summary it is not, and I believe it is a very important element to add in that list of priority sectors for leadership. Could also be added under 1.4.2 “Data as a Strategic National Asset”.
Page 14, under section 2.4.1 “Priority Sectors for Leadership”: Here I would suggest the addition of another sector, which should also be of national importance. It would be valuable to consider the addition something similar to Urban (Re)Development: Using AI for city and rural digital twins for natural disaster risk management, such as wildfires and flooding, is a of existential matter to us. Considering the reality we are currently facing, with extremely high temperatures and wildfires, and flood during sudden rainfall, for which Cyprus is usually unprepared, embedding AI applications for predictive analytics and forecasting, as well as the re-design of public spaces and urban life should be seen as a priority. The qualitative assessment of such initiatives can be life-saving and can usher a new, more proactive and sustainable future for the island and its people.
Could also promote cost-efficient ways of using energy, while helping design smarter, environmentally friendly buildings, public housing and spaces. Environment is not mentioned in strategy, and I believe that it should be seen as an urgent, priority sector for public leadership.
Page 16 under 2.5.4 “Transform public services through AI-enabled delivery”: First sentence “AI will be used to modernize public administration and improve service delivery *on a national and municipal level*. Justification: because it is important to understand that albeit the national government is the guiding institution and provides the mandate and resources, local governance is an important element in the implementation of all these national initiatives. Local governance accounts for a lot of the local service delivery that meets the needs of people in a specific neighborhood or village. Extending that mandate to them, and including them in the strategy as part of the wider governance ecosystem, while providing them with the relevant resources and capacity-building can help strengthen local, public service delivery.
Page 29: Under 3.4.5 Capacity Building and Change Management. Consider adding concepts such as systems thinking and mapping. These include identifying actors, actions, data gaps and interconnectedness of issues- Important for innovation, alignment of solutions, and for promoting a product operating model for AI. This means creating a new, permanent, cross-functional teams and method of working that manage and improve digital products after they go live.
The Cyprus National AI Strategy 2032 constitutes an important and timely framework for the country’s digital, economic and institutional transformation. Its vision of establishing Cyprus as a trusted artificial intelligence hub in the Eastern Mediterranean, a reliable European jurisdiction for AI-enabled services and a bridge between the European Union and neighbouring regions is ambitious and broadly consistent with Cyprus’s economic structure, institutional position and comparative advantages. The emphasis placed on trustworthy, human-centred and responsible AI, together with the focus on economic productivity, public-sector modernisation, skills development, research, innovation and digital sovereignty, provides a sound foundation for national action up to 2032.
The Strategy appropriately recognises that the successful adoption of AI depends not only on technology, but also on data quality, institutional capacity, governance, skills, infrastructure and public trust. Its eight National Strategic Objectives offer a coherent framework for strengthening Cyprus’s position as a trusted jurisdiction, increasing national productivity, developing an inclusive AI ecosystem, transforming public services, expanding the national talent base, securing data and infrastructure, embedding ethics and accountability, and developing sovereign capability through trusted partnerships. The identification of priority sectors, including government, financial services, healthcare, tourism, legal services, education, shipping and entrepreneurship, is also well aligned with the structure of the Cypriot economy and the areas in which AI could generate significant public and economic value.
To strengthen the Strategy’s implementation, it is proposed that the final document be accompanied by a detailed, costed and regularly updated Action Plan for the period 2026–2032. The Strategy already establishes an implementation timeline, immediate actions, responsible governance structures and indicative success metrics. These provisions could be further developed by specifying, for each major action, the responsible organisation, implementation lead, timetable, interim milestones, expected deliverables, estimated budget, funding source, staffing requirements and technological dependencies. The Action Plan should also identify the principal legal, operational, cybersecurity and procurement risks associated with each initiative, together with the measures required to manage them.
Particular attention should be given to the full lifecycle cost of national AI investments. The financial assessment of each initiative should not be limited to the initial development or procurement cost, but should also cover operation, maintenance, cybersecurity, auditing, data management, model monitoring, licensing, technical support, upgrading and eventual replacement or decommissioning. This would support more realistic budgeting, improve long-term sustainability and reduce the risk of launching projects that cannot subsequently be maintained or scaled.
The proposed governance structure is comprehensive and reflects the need for central coordination combined with decentralised implementation. The establishment or designation of a National AI Authority, an Interministerial AI Council, specialised monitoring and advisory bodies, innovation structures, AI Officers and AI Champions can provide the institutional capacity needed for effective delivery. However, the number of bodies involved may create risks of overlapping responsibilities, fragmented decision-making and delays unless their mandates and relationships are defined with precision.
It is therefore recommended that the final Strategy include a clear governance and accountability matrix covering all bodies involved in implementation. The matrix should identify which body sets policy, which body approves initiatives, which body is responsible for implementation, which body performs regulatory or ethical oversight and which body remains accountable for outcomes. It should also establish procedures for resolving institutional disagreements, escalating high-risk matters, addressing delays and responding to implementation failures. The National AI Authority should have a clear legal and institutional basis, sufficient resources, specialised personnel and appropriate functional autonomy, while remaining subject to transparent accountability arrangements and without displacing the responsibilities of ministries, public bodies or existing competent authorities.
The Strategy correctly seeks to avoid the proliferation of disconnected pilot projects and promotes a use-case-driven approach based on measurable value. To operationalise this principle, Cyprus should initially concentrate resources on a limited portfolio of high-impact flagship projects. These projects should be selected according to transparent criteria, including their expected benefit for citizens and businesses, contribution to productivity, capacity to reduce administrative burden, availability and quality of the required data, organisational readiness, level of legal and ethical risk, cost-effectiveness and potential for reuse across multiple public bodies or sectors.
Each pilot project should have predetermined entry and exit criteria. Before development begins, the responsible authority should define the problem being addressed, the expected benefits, the baseline against which progress will be measured and the conditions under which the project will proceed to production, be redesigned, expanded or terminated. Scaling should take place only where an independent or appropriately qualified evaluation demonstrates clear public or economic value, legal compliance, technical reliability and acceptable levels of risk. This approach would reinforce the Strategy’s stated commitment to value-driven deployment and prevent the accumulation of experimental systems that do not produce sustainable outcomes.
The Strategy’s measurement framework is a positive element, particularly its focus on productivity, economic growth, skills, investment, adoption, trust and compliance. Nevertheless, the indicative National KPI and Measurement Framework should be converted into a final, operational and verifiable monitoring system. Each principal indicator should include a baseline value, a numerical target, a target date, a defined data source, a measurement methodology, a reporting frequency and a clearly identified organisation responsible for collection and verification.
The national indicators should measure outcomes rather than activity alone. In addition to measuring the number of projects, professionals trained or organisations adopting AI, the framework should assess actual changes in service-processing times, administrative costs, workforce productivity, accessibility, citizen satisfaction, business competitiveness, innovation outputs, investment attraction and public trust. Where macroeconomic objectives such as productivity and GDP impact are retained, the final framework should clarify the assumptions, methodology and external variables affecting those projections. This would allow progress to be assessed transparently and would distinguish the direct contribution of the Strategy from broader economic developments.
It is further proposed that the Government publish a consolidated annual progress report on the implementation of the Strategy. The report should present the status of each principal action, expenditure against budget, progress against milestones, measurable outcomes, identified risks and any corrective measures adopted. Core implementation data should be made available in an accessible and reusable format, subject to legitimate security and confidentiality limitations. This would strengthen transparency, public accountability and independent evaluation while supporting informed adjustments to the Strategy.
The human-centred approach contained in the Strategy is strongly supported. The principles of human oversight, transparency, explainability, fairness, non-discrimination, accountability and access to redress should be translated into clear operational requirements for all high-impact and citizen-facing AI systems. Individuals should be informed in plain and accessible language when they are interacting with an AI system or when an AI system has materially contributed to a decision affecting them. Where decisions concern healthcare, social benefits, education, employment, licensing, access to public services or other sensitive matters, citizens should have access to meaningful human review, an understandable explanation and an effective procedure for contesting the outcome.
Human oversight should be substantive rather than merely formal. Officials responsible for reviewing an AI-assisted decision should have the authority, competence, information and time required to question or overturn the system’s output. The respective responsibilities of the public authority, system provider, operator and individual decision-maker should be documented in advance. No AI system should weaken the accountability of the public body legally responsible for the decision or service concerned.
Data governance is appropriately treated as a foundational requirement of the Strategy. The development of a federated national data architecture, common standards, secure interfaces, controlled access mechanisms and appropriate national data infrastructure can support interoperability while avoiding the unnecessary centralisation of sensitive information. The proposed National Intelligent Digital API Fabric and national data layer should be implemented through strong privacy, security, access-control, auditability and data-quality requirements.
Before data are reused for AI development or operation, the responsible organisation should demonstrate that the intended use is lawful, necessary, proportionate and compatible with the purpose for which the data were collected. Clear rules should govern data ownership, stewardship, access, retention, anonymisation, correction and deletion. Particular care is required in relation to health, financial, biometric, social and other sensitive data. Secure research environments and controlled-access mechanisms should be used where open access would create unacceptable risks.
Cybersecurity and operational resilience should remain central throughout the lifecycle of every AI system. High-impact systems should be subject to proportionate legal, ethical, data-protection, cybersecurity and fundamental-rights impact assessments before procurement or deployment. They should also undergo appropriate testing for reliability, bias, security vulnerabilities, adversarial manipulation and performance deterioration. Monitoring should continue after deployment, with clearly defined procedures for incident reporting, investigation, remediation, suspension and withdrawal where a system no longer meets legal, ethical, security or performance requirements.
The Strategy’s focus on skills and workforce transformation is also strongly supported. AI education should address different levels of need across society, from basic AI literacy for citizens and school students to advanced technical, legal, ethical and sector-specific skills for professionals. Public officials, managers, educators, healthcare professionals, lawyers, accountants and employees in tourism, finance and shipping require training that reflects their responsibilities and the particular risks of their sectors.
Training should not focus only on the use of AI tools, but also on their limitations. Participants should be able to assess the reliability of outputs, identify bias and fabricated information, protect confidential and personal data, understand when human intervention is required and recognise situations in which AI should not be used. Upskilling and reskilling programmes should be informed by labour-market evidence and should provide meaningful support to workers whose tasks or occupations are likely to be significantly affected by automation.
The Strategy should place particular emphasis on small and medium-sized enterprises, which form a central part of the Cypriot economy but may lack the financial capacity, technical expertise, data resources and compliance knowledge required for responsible AI adoption. SMEs should be provided with access to technical guidance, shared computing resources, secure testing environments, training, regulatory support and appropriately designed funding schemes. Public procurement processes should also facilitate the participation of Cypriot startups and SMEs, provided that all requirements relating to security, quality, transparency and accountability are met.
Public procurement will be one of the principal mechanisms through which the State influences the development and use of AI. Procurement rules and model contractual clauses should therefore address data rights, intellectual property, confidentiality, cybersecurity, audit access, documentation, performance standards, human oversight, model updates, subcontracting, incident reporting, liability and termination. Contracts should also provide for data and system portability and an orderly transition to another supplier where necessary.
The Strategy’s commitment to interoperability, reuse and technological sovereignty should be reinforced by the systematic use of open standards and portable architectures where appropriate. Cyprus should avoid becoming dependent on a single supplier, proprietary system or infrastructure provider for critical public services. Strategic partnerships can be essential for a country of Cyprus’s size, but they should be structured to secure knowledge transfer, domestic capability development, access to technical documentation, interoperability and long-term institutional resilience.
The establishment of centres of excellence, innovation hubs, testbeds and shared infrastructure can help connect research with real-world implementation. Their respective mandates should, however, be clearly differentiated. Public funding should be linked to measurable outputs, collaboration with local institutions, knowledge transfer, skills development and the creation of sustainable economic or social value. Research priorities should remain sufficiently flexible to respond to emerging technological developments while maintaining a clear connection to national needs and the Strategy’s priority sectors.
Environmental sustainability should also be integrated into investment and procurement decisions. National AI infrastructure and large-scale AI applications may require significant energy, water and hardware resources. Green AI principles should therefore be converted into measurable requirements relating to energy efficiency, carbon impact, infrastructure utilisation, equipment lifecycle and responsible procurement. Environmental costs should form part of the overall assessment of value and sustainability.
Finally, the success of the Strategy will depend on public trust and continued stakeholder participation. Consultation should not end with the adoption of the final document. Permanent mechanisms should be established for engagement with citizens, businesses, universities, research organisations, professional bodies, trade unions, civil-society organisations and groups that may be disproportionately affected by AI systems. Particular attention should be given to persons with disabilities, older persons, individuals with limited digital skills and communities at risk of exclusion from AI-enabled services.
In conclusion, the Cyprus National AI Strategy 2032 provides a strong and comprehensive strategic direction. The recommendations set out above do not seek to alter its central vision or strategic objectives, but to strengthen their operational implementation. A detailed and costed Action Plan, clearer governance responsibilities, a finalised measurement framework, transparent annual reporting, enforceable safeguards for citizens, robust procurement and data-governance arrangements, and sustained stakeholder participation would enhance the Strategy’s credibility, accountability and long-term effectiveness. Through disciplined implementation and periodic evidence-based review, Cyprus can develop AI capabilities that support productivity, innovation, institutional resilience and economic growth while safeguarding fundamental rights, public trust and the broader public interest.
Contribution to Strengthening the National Artificial Intelligence Strategy 2032
The National Artificial Intelligence Strategy 2032 provides an ambitious and important foundation for positioning Cyprus as a trusted and competitive jurisdiction for Artificial Intelligence, while strengthening productivity, public-sector transformation, innovation, talent, infrastructure and national AI capabilities.
My principal recommendation is not to add another standalone initiative, but to strengthen the Strategy with a National AI Execution & Assurance Architecture that connects strategic objectives with implementation, regulatory requirements, institutional accountability, measurable outcomes and continuous adaptation.
The critical challenge for Cyprus through 2032 will not be AI adoption alone. It will be the ability to manage multiple technological, regulatory, financial and institutional dependencies simultaneously, while maintaining strategic coherence and measurable national value.
1. National AI Execution & Assurance Architecture
The Strategy could be strengthened through an integrated National AI Execution & Assurance Architecture, serving as the connective layer between national strategy, AI programmes, regulation, implementation and impact.
The framework would operate across six interconnected layers:
Strategy → Portfolio → Regulatory → Execution → Assurance → Impact**
Every major national AI initiative should be traceable throughout its lifecycle, from strategic prioritisation through deployment, operational monitoring and impact assessment.
2. National AI Portfolio Management
A unified National AI Portfolio could provide a common management structure for major public AI investments and initiatives.
Each strategic initiative should have a standardised execution profile covering:
• Strategic objective and expected value
• Ownership and accountability
• Required data and infrastructure
• Regulatory and technological dependencies
• Risks and control points
• Budget and resource requirements
• Milestones and KPIs
• Deployment readiness
• Measurable socioeconomic and public-sector impact
This would shift performance measurement from “how many AI projects are initiated” to “how many generate measurable national value”.
3. AI Lifecycle Governance
The Strategy could also be reinforced through a common AI Lifecycle Governance Framework for public-sector AI systems.
Significant AI systems should follow controlled lifecycle stages:
Identify → Assess → Design → Test → Approve → Deploy → Monitor → Review**
Each stage should incorporate appropriate requirements for:
• Regulatory compliance
• Data protection
• Cybersecurity
• Risk assessment
• Human oversight
• Documentation and traceability
• Model quality and security
• Operational resilience
• Post-deployment review and assurance
This would position compliance not as a final administrative checkpoint, but as an embedded component of the AI system lifecycle.
4. National AI Readiness & Execution Index
A National AI Readiness & Execution Index could provide a consistent mechanism for assessing national and institutional readiness and implementation progress.
The Index could measure, among other dimensions:
Infrastructure Readiness | Data Readiness | Regulatory Readiness | Institutional Capacity | Talent | Adoption | Security | Economic Impact
Such a mechanism would allow government to identify bottlenecks, delivery delays and systemic dependencies at an early stage and adjust resources and priorities before strategic initiatives become stalled or remain permanently at pilot stage.
5. From Pilot to Scale
Particular emphasis should be placed on the transition from pilot projects to production-scale deployment.
Major AI initiatives should follow a defined pathway:
Research → Experimentation → Validation → Governance Approval → Procurement → Deployment → Scaling → Impact Measurement**
Clear “stage gates” would reduce the risk of fragmented pilots without a pathway to adoption and ensure that public investment is progressively directed towards solutions demonstrating measurable value, feasibility and institutional readiness.
6. Strategic AI Foresight and Continuous Adaptation
The Strategy should ultimately operate as a “living national framework”, rather than as a static long-term plan.
AI technologies, geopolitical conditions, European regulation, infrastructure requirements and business models are evolving significantly faster than traditional strategic planning cycles.
A structured Annual National AI Strategic Review could therefore assess:
• Technological and geopolitical developments
• Emerging regulatory requirements
• National dependencies
• Investment priorities
• AI adoption and deployment
• Performance of strategic initiatives
• Emerging risks
• New opportunities for the Cypriot economy
This would allow the Strategy to evolve without losing its long-term direction.
Conclusion
Cyprus does not need to compete with larger countries solely on the scale of infrastructure or investment. It can compete through the quality, agility and coherence of its national AI architecture.
A strategic advantage for Cyprus could be its ability to connect AI policy, regulation, data, infrastructure, investment, governance and execution within one coherent national operating framework.
The success of the National AI Strategy 2032 should therefore not be measured solely by the adoption of Artificial Intelligence, but by whether Cyprus develops the institutional capacity to prioritise, design, approve, implement, govern, monitor, scale and measure the value of AI systems consistently.
The proposed National AI Execution & Assurance Architecture would provide an additional execution layer capable of transforming the Strategy from a framework for national direction into a measurable, adaptive and execution-oriented national AI system through 2032.
Submitted by Christina Ioannou
Founder & CEO, Arete Strategy AI Ltd
Policy, Governance & Regulatory Execution Intelligence
http://www.aretestrategyai.org
LinkedIn: https://www.linkedin.com/in/christina-ioannou-8a3bb1177/
The National Artificial Intelligence Strategy 2032 provides an ambitious and important foundation for positioning Cyprus as a trusted and competitive jurisdiction for Artificial Intelligence, while strengthening productivity, public-sector transformation, innovation, talent, infrastructure and national AI capabilities
My principal recommendation is not to add another standalone initiative, but to strengthen the Strategy with a National AI Execution & Assurance Architecture, that connects strategic objectives with implementation, regulatory requirements, institutional accountability, measurable outcomes and continuous adaptation.
The critical challenge for Cyprus through 2032 will not be AI adoption alone. It will be the ability to manage multiple technological, regulatory, financial and institutional dependencies simultaneously, while maintaining strategic coherence and measurable national value.
1. National AI Execution & Assurance Architecture The Strategy could be strengthened through an integrated National AI Execution & Assurance Architecture, serving as the connective layer between national strategy, AI programmes, regulation, implementation and impact. The framework would operate across six interconnected layers: Strategy → Portfolio → Regulatory → Execution → Assurance → Impact Every major national AI initiative should be traceable throughout its lifecycle, from strategic prioritisation through deployment, operational monitoring and impact assessment.
2. National AI Portfolio Management A unified National AI Portfolio could provide a common management structure for major public AI investments and initiatives. Each strategic initiative should have a standardised execution profile covering: * strategic objective and expected value; * ownership and accountability; * required data and infrastructure; * regulatory and technological dependencies; * risks and control points; * budget and resource requirements; * milestones and KPIs; * deployment readiness; * measurable socioeconomic and public-sector impact. This would shift performance measurement from “how many AI projects are initiated” to “how many generate measurable national value”.
3. AI Lifecycle Governance The Strategy could also be reinforced through a common AI Lifecycle Governance Framework for public-sector AI systems. Significant AI systems should follow controlled lifecycle stages: Identify → Assess → Design → Test → Approve → Deploy → Monitor → Review Each stage should incorporate appropriate requirements for: * regulatory compliance; * data protection; * cybersecurity; * risk assessment; * human oversight; * documentation and traceability; * model quality and security; * operational resilience; * post-deployment review and assurance. This would position compliance not as a final administrative checkpoint, but as an embedded component of the AI system lifecycle.
4. National AI Readiness & Execution Index A National AI Readiness & Execution Index could provide a consistent mechanism for assessing national and institutional readiness and implementation progress. The Index could measure, among other dimensions: Infrastructure Readiness | Data Readiness | Regulatory Readiness | Institutional Capacity | Talent | Adoption | Security | Economic Impact Such a mechanism would allow government to identify bottlenecks, delivery delays and systemic dependencies at an early stage and adjust resources and priorities before strategic initiatives become stalled or remain permanently at pilot stage.
5. From Pilot to Scale Particular emphasis should be placed on the transition from **pilot projects to production-scale deployment. Major AI initiatives should follow a defined pathway: Research → Experimentation → Validation → Governance Approval → Procurement → Deployment → Scaling → Impact Measurement Clear “stage gates” would reduce the risk of fragmented pilots without a pathway to adoption and ensure that public investment is progressively directed towards solutions demonstrating measurable value, feasibility and institutional readiness.
6. Strategic AI Foresight and Continuous Adaptation The Strategy should ultimately operate as a “living national framework” , rather than as a static long-term plan. AI technologies, geopolitical conditions, European regulation, infrastructure requirements and business models are evolving significantly faster than traditional strategic planning cycles. A structured “Annual National AI Strategic Revie” could therefore assess: * technological and geopolitical developments; * emerging regulatory requirements; * national dependencies; * investment priorities; * AI adoption and deployment; * performance of strategic initiatives; * emerging risks; * new opportunities for the Cypriot economy.
This would allow the Strategy to evolve without losing its long-term direction. Conclusion Cyprus does not need to compete with larger countries solely on the scale of infrastructure or investment. It can compete through the **quality, agility and coherence of its national AI architecture**. A strategic advantage for Cyprus could be its ability to connect **AI policy, regulation, data, infrastructure, investment, governance and execution** within one coherent national operating framework.
The success of the National AI Strategy 2032 should therefore not be measured solely by the adoption of Artificial Intelligence, but by whether Cyprus develops the institutional capacity to prioritise, design, approve, implement, govern, monitor, scale and measure the value of AI systems consistently. The proposed National AI Execution & Assurance Architecture would provide an additional execution layer capable of transforming the Strategy from a framework for national direction into a measurable, adaptive and execution-oriented national AI system through 2032.
Submitted by: Christina Ioannou Founder & CEO, Areté Strategy AI Ltd Policy, Governance & Regulatory Execution Intelligence https://www.aretestrategyai.org/ https://www.linkedin.com/in/christina-ioannou-8a3bb1177/
The National Artificial Intelligence Strategy 2032 provides an ambitious and important foundation for positioning Cyprus as a trusted and competitive jurisdiction for Artificial Intelligence, while strengthening productivity, public-sector transformation, innovation, talent, infrastructure and national AI capabilities
My principal recommendation is not to add another standalone initiative, but to strengthen the Strategy with a National AI Execution & Assurance Architecture, that connects strategic objectives with implementation, regulatory requirements, institutional accountability, measurable outcomes and continuous adaptation.
The critical challenge for Cyprus through 2032 will not be AI adoption alone. It will be the ability to manage multiple technological, regulatory, financial and institutional dependencies simultaneously, while maintaining strategic coherence and measurable national value.
1. National AI Execution & Assurance Architecture
The Strategy could be strengthened through an integrated National AI Execution & Assurance Architecture, serving as the connective layer between national strategy, AI programmes, regulation, implementation and impact.
The framework would operate across six interconnected layers:
Strategy → Portfolio → Regulatory → Execution → Assurance → Impact
Every major national AI initiative should be traceable throughout its lifecycle, from strategic prioritisation through deployment, operational monitoring and impact assessment.
2. National AI Portfolio Management
A unified National AI Portfolio could provide a common management structure for major public AI investments and initiatives.
Each strategic initiative should have a standardised execution profile covering:
* strategic objective and expected value;
* ownership and accountability;
* required data and infrastructure;
* regulatory and technological dependencies;
* risks and control points;
* budget and resource requirements;
* milestones and KPIs;
* deployment readiness;
* measurable socioeconomic and public-sector impact.
This would shift performance measurement from “how many AI projects are initiated” to “how many generate measurable national value”.
3. AI Lifecycle Governance
The Strategy could also be reinforced through a common AI Lifecycle Governance Framework for public-sector AI systems.
Significant AI systems should follow controlled lifecycle stages:
Identify → Assess → Design → Test → Approve → Deploy → Monitor → Review
Each stage should incorporate appropriate requirements for:
* regulatory compliance;
* data protection;
* cybersecurity;
* risk assessment;
* human oversight;
* documentation and traceability;
* model quality and security;
* operational resilience;
* post-deployment review and assurance.
This would position compliance not as a final administrative checkpoint, but as an embedded component of the AI system lifecycle.
4. National AI Readiness & Execution Index
A National AI Readiness & Execution Index could provide a consistent mechanism for assessing national and institutional readiness and implementation progress.
The Index could measure, among other dimensions:
Infrastructure Readiness | Data Readiness | Regulatory Readiness | Institutional Capacity | Talent | Adoption | Security | Economic Impact
Such a mechanism would allow government to identify bottlenecks, delivery delays and systemic dependencies at an early stage and adjust resources and priorities before strategic initiatives become stalled or remain permanently at pilot stage.
5. From Pilot to Scale
Particular emphasis should be placed on the transition from **pilot projects to production-scale deployment.
Major AI initiatives should follow a defined pathway:
Research → Experimentation → Validation → Governance Approval → Procurement → Deployment → Scaling → Impact Measurement
Clear “stage gates” would reduce the risk of fragmented pilots without a pathway to adoption and ensure that public investment is progressively directed towards solutions demonstrating measurable value, feasibility and institutional readiness.
6. Strategic AI Foresight and Continuous Adaptation
The Strategy should ultimately operate as a “living national framework” , rather than as a static long-term plan.
AI technologies, geopolitical conditions, European regulation, infrastructure requirements and business models are evolving significantly faster than traditional strategic planning cycles.
A structured “Annual National AI Strategic Revie” could therefore assess:
* technological and geopolitical developments;
* emerging regulatory requirements;
* national dependencies;
* investment priorities;
* AI adoption and deployment;
* performance of strategic initiatives;
* emerging risks;
* new opportunities for the Cypriot economy.
This would allow the Strategy to evolve without losing its long-term direction.
Conclusion
Cyprus does not need to compete with larger countries solely on the scale of infrastructure or investment. It can compete through the **quality, agility and coherence of its national AI architecture**.
A strategic advantage for Cyprus could be its ability to connect **AI policy, regulation, data, infrastructure, investment, governance and execution** within one coherent national operating framework.
The success of the National AI Strategy 2032 should therefore not be measured solely by the adoption of Artificial Intelligence, but by whether Cyprus develops the institutional capacity to prioritise, design, approve, implement, govern, monitor, scale and measure the value of AI systems consistently.
The proposed National AI Execution & Assurance Architecture would provide an additional execution layer capable of transforming the Strategy from a framework for national direction into a measurable, adaptive and execution-oriented national AI system through 2032.
Submitted by: Christina Ioannou
Founder & CEO, Areté Strategy AI Ltd
Policy, Governance & Regulatory Execution Intelligence
https://www.aretestrategyai.org/
https://www.linkedin.com/in/christina-ioannou-8a3bb1177/
SUBMISSION TO THE PUBLIC CONSULTATION ON THE NATIONAL AI STRATEGY OF THE REPUBLIC OF CYPRUS 2032
Recognising Multimodal and Embodied Conversational Interfaces as a National Accessibility Capability
Submitted by: Cyber Leo Limited (trading as RAVATAR), HE384983, Limassol, Cyprus
Contact: Ruslan Synytskyy, Chief Executive Officer
Email: rs@ravatar.com
Date: 29 July 2026
EXECUTIVE RECOMMENDATION
The Strategy correctly identifies conversational AI and multilingual assistants as reusable national services rather than isolated sector applications. We support this framing without reservation.
We recommend one clarification, applied consistently across the Strategy: that conversational AI be specified as multimodal, capable of speech, visual presence and natural interaction, and not implicitly limited to text-based interfaces.
This is not a technical preference. The Strategy commits Cyprus to digital inclusion for people with disabilities and for pensioners, and to multilingual access. A text-only interface systematically excludes the populations the Strategy names as priorities: older citizens, people with low digital literacy, people with visual or motor impairments, and non-Greek-speaking residents. Where the interface is the service, the modality of the interface is an accessibility decision, not an implementation detail.
We also recommend that the Strategy establish a national transparency standard for synthetic-persona interfaces, so that Cyprus sets the governance rules for this technology rather than importing them.
The six comments below address:
1. Specification of shared conversational AI services as multimodal
2. A national disclosure standard for synthetic-persona interfaces
3. Accessibility requirements for the Virtual AI Patient Orchestrator
4. Scope of the tourism SME co-funding scheme
5. Sovereign deployment of the citizen-facing interface layer
6. A glossary definition for multimodal conversational interfaces
All proposed amendments are drafted in capability terms and are technology-neutral. None names or favours a specific product, vendor or architecture.
COMMENT 1: SPECIFY SHARED CONVERSATIONAL AI SERVICES AS MULTIMODAL
SECTION REFERENCE
Section 3.4.4 (Shared Capabilities and Reuse); Annex C, Government and Public Sector, Implementation, evidence and compliance; Annex B, Control Gate 1, category “reusable common services”.
COMMENT / SUGGESTION
The Strategy states that Cyprus will build shared, reusable AI services including “conversational AI for continuous citizen service delivery” and “multilingual citizen assistants”, exposed through “a common, modular intelligent government platform”.
We suggest these references be amended to read, in substance:
“conversational AI, including multimodal and embodied interfaces supporting speech, visual presence and accessible interaction, for continuous citizen service delivery”
and that the shared services catalogue explicitly list a multimodal interaction layer as a reusable component alongside identity, payments, document intelligence and case management.
JUSTIFICATION
The Strategy commits, in Section 3.9 and in the OECD-aligned principles at Annex A, that “new solutions must cater to multilingual support and inclusive access tools that ensure that people with disabilities can interact with the services”, and in the Executive Summary to promoting digital inclusion “including people with disabilities and pensioners”.
Section 3.4.4 establishes that capabilities built once will be reused across government. This makes the specification of the shared conversational service unusually consequential: whatever modality is scoped into the reference architecture will propagate into every ministry that adopts it, and will be difficult to retrofit once the platform is procured. The Strategy notes that procurement for the first six transformational solutions is intended to launch within eight months. The specification decision is therefore imminent.
The current wording does not exclude multimodal interfaces. It also does not require them, and in procurement practice an unspecified requirement is an absent requirement. Given that the Strategy sets an explicit target of reducing citizen waiting times by 40% and improving citizen experience, and given that the citizens least well served by existing digital channels are precisely those least able to use a text interface, we consider the clarification proportionate and low-cost.
A second consideration: architectural optionality over a seven-year horizon.
Section 3.7.3 provides that infrastructure choices “should therefore be guided by considerations of interoperability, portability, vendor diversity, supply-chain resilience, security, and long-term sustainability”, and that this “reduces lock-in risks while preserving strategic flexibility”. Section 3.13.4 commits the Strategy to remaining “adaptive rather than static” in the face of technological change.
We suggest these principles apply with particular force to the interaction layer, and that the Strategy would benefit from stating so explicitly.
The Strategy runs to 2032. The shared conversational service will be specified once and inherited by every ministry that adopts it, across the sixteen transformation projects and beyond. Interaction modality is an architectural property of that service: a platform designed for multimodal interaction can serve text, whereas a platform designed for text cannot later serve speech and visual interaction without substantial rework or re-procurement.
The asymmetry is the point. Requiring modality-extensibility in the initial specification is close to costless, because it constrains architecture rather than mandating deployment. Retrofitting it into a procured national platform is expensive, slow, and may not be practicable within the Strategy’s timeframe. This holds regardless of how interaction preferences evolve over the period, which is why we put it forward as a resilience argument rather than a forecast.
We would specifically suggest that shared conversational services be required to expose a modality-independent interaction layer, so that additional modalities can be added without re-architecting the underlying service, and that this be treated as a portability requirement of the kind Section 3.7.3 already contemplates.
We note that this comment asks for a specification of an existing commitment, not for a new programme or new expenditure.
COMMENT 2: ESTABLISH A NATIONAL DISCLOSURE STANDARD FOR SYNTHETIC-PERSONA INTERFACES
SECTION REFERENCE
Section 3.9.3 (Transparency and Explainability); Section 3.9.6 (AI Social Contract Principles); Annex B, Control Gate 2.
COMMENT / SUGGESTION
We recommend the Strategy commit to a national transparency standard governing AI systems that present a synthetic human persona, whether visual, vocal or both. The standard should require, at minimum:
– Persistent disclosure. Continuous, unambiguous indication that the citizen is interacting with an AI system, present throughout the interaction and not only at its start.
– No impersonation of identifiable individuals. Synthetic personas deployed in public services must not replicate the likeness or voice of a real, identifiable person without that person’s explicit, documented and revocable consent.
– One-step human escalation. A visible, always-available route to a human official, with no requirement to restate the request.
– Provenance and audit. Recorded lineage of the persona asset, the underlying models, and the interaction logs, consistent with the auditability requirements already set out in Section 3.9.3.
– Proportionality. Requirements scaled to risk, consistent with the EU AI Act’s risk-based approach, with the strictest application to health, benefits and legal contexts.
JUSTIFICATION
Article 50 of the EU AI Act establishes transparency obligations for systems that interact directly with natural persons and for systems generating synthetic audio, image, video or text. It requires that this information be provided in a clear and distinguishable manner at the latest at the time of first interaction, and that it conform to applicable accessibility requirements. The Strategy itself notes the 2 August 2026 compliance milestone. Synthetic-persona interfaces are an area where the Act sets a floor and where national implementation guidance does not yet exist in most Member States.
We note that the Act’s own linkage of transparency to accessibility supports the point made in Comment 1: disclosure that a citizen cannot perceive is not disclosure. The Strategy commits to leveraging EU AI Act alignment as a source of competitive advantage rather than treating it as a constraint, and this is an area where that ambition can be made concrete.
Cyprus has an opportunity to publish that guidance first. The Strategy states an ambition for Cyprus to be “a testing and deployment environment for EU and regional markets, particularly for regulated and multilingual contexts”. A clear, published national standard for trustworthy synthetic-persona deployment would be a concrete instance of that positioning, and would give operators regulatory certainty in a technology area where uncertainty is currently the main barrier to adoption.
There is a public trust argument as well. The Strategy is explicit that “AI systems must be explainable, auditable, and understandable to those they affect”, and that citizens interacting with AI must be made aware of it. Embodied interfaces raise this question more sharply than text interfaces do. Addressing it in the Strategy rather than after the first incident is the lower-risk path.
We raise this comment notwithstanding that stricter rules apply to our own product category. We consider a published standard preferable to an unregulated market, both for citizens and for responsible operators.
For transparency as to our own position: we are currently implementing AI disclosure, human oversight and interaction logging as architectural requirements of our platform, together with a formal EU AI Act conformity assessment, under a dedicated compliance work package in our European Innovation Council Accelerator programme application. The measures proposed above are therefore ones we are building to, not ones we are proposing for others.
COMMENT 3: SPECIFY ACCESSIBILITY REQUIREMENTS FOR THE VIRTUAL AI PATIENT ORCHESTRATOR
SECTION REFERENCE
Annex C, Healthcare and Life Sciences, Flagship programme(s).
COMMENT / SUGGESTION
The Strategy describes the Virtual AI Patient Orchestrator as “an intelligent, multilingual Virtual AI Patient Orchestrator that functions as a national digital front door”, operating “under clinician oversight, with safety nets for vulnerable populations”.
We suggest the programme description specify that the front door must be accessible by voice and visual interaction, not by text alone, and that accessibility for older patients and patients with disabilities be included among the programme’s evaluation indicators rather than treated as a downstream implementation concern.
We further suggest that a bounded pilot be conducted before national rollout, comparing interaction modalities on a defined patient cohort, with pre-registered indicators covering completion rate, comprehension, time to first clinical assessment and patient-reported experience, disaggregated by age group and language.
JUSTIFICATION
The Strategy already commits to evaluating national triage and care navigation pilots “against WHO-aligned indicators, focusing on triage accuracy, time to first clinical assessment, and reduction of avoidable visits”. Adding accessibility indicators to that set is consistent with the existing evaluation design and adds little cost.
The clinical case is straightforward. A digital front door that is intended to reduce pressure on emergency services succeeds only if the patients most likely to present at emergency departments can use it. Those patients are disproportionately elderly, and elderly patients in Cyprus include a substantial cohort with limited digital literacy. A front door that only the digitally confident can open will shift load rather than reduce it, and may widen rather than narrow the access gap the programme is meant to close.
The Strategy identifies “AI theatre” as a national risk: many pilots, little measured impact. A pre-registered, modality-comparative pilot with disaggregated outcomes is a direct mitigation of that risk and would produce evidence usable across the other citizen-facing programmes.
COMMENT 4: EXTEND THE TOURISM SME CO-FUNDING SCHEME TO MULTIMODAL CONCIERGES
SECTION REFERENCE
Annex C, Tourism and Hospitality, Implementation (Empowered Digital Tourists programme); and the pillar deliverables “Support for sustainable hotels and SMEs” and “Digital concierges and transparent AI use”.
COMMENT / SUGGESTION
The Strategy provides that the Empowered Digital Tourists programme “co-funds multilingual, privacy-compliant GenAI chatbots and recommendation systems for sustainability-certified hotels and tourism SMEs”, and separately anticipates “GenAI-based concierges supporting multilingual guidance, culture and heritage explanations, and human escalation”.
We suggest the co-funding provision be worded to cover multilingual, privacy-compliant conversational AI systems including chatbots, voice assistants and embodied digital concierges, so that the funding instrument matches the concierge capability the same pillar describes.
JUSTIFICATION
As currently drafted, the deliverables table describes digital concierges while the funding mechanism references chatbots. Aligning the two removes an inconsistency and avoids a situation in which the stated capability is not eligible for the stated instrument.
The substantive case is that hospitality is an in-person, multilingual, service-quality-driven sector, and the Strategy is explicit that AI adoption in tourism must preserve “the hospitality, warmth, and cultural authenticity that distinguish Cyprus”. A text chatbot is a poor expression of that objective. A concierge that speaks, in the visitor’s language, with visible AI disclosure and immediate human escalation, is a closer fit to both the service standard and the transparency requirement.
We note the Strategy’s own cited evidence that 8% of chatbot conversations resulted in a confirmed booking, rising to 25% with a single follow-up, with an estimated 10% increase in direct sales. Those figures are drawn from text-based deployments. Extending eligibility would allow Cyprus to generate comparative national evidence on whether multimodal interfaces improve on that baseline, which is information no other Member State currently holds.
We also support the Strategy’s emphasis that this scheme reach SMEs and local communities and not only large hotel chains. Interface quality is one of the few areas where a small operator can match a large chain if the tooling is accessible, and the co-funding mechanism is well designed for that purpose.
COMMENT 5: TREAT THE CITIZEN-FACING INTERFACE LAYER AS A SOVEREIGN CAPABILITY
SECTION REFERENCE
Section 3.7.3 (Digital Sovereignty and Strategic Autonomy); Section 1.4.6; Executive Summary, “AI sovereignty leveraging partnerships”.
COMMENT / SUGGESTION
We suggest that the Strategy identify the citizen-facing conversational interface layer as among the critical layers over which Cyprus should retain sovereign control, alongside compute, data and skills, and that shared conversational services procured for government be required to support deployment within national infrastructure.
JUSTIFICATION
The Strategy frames the national choice as being between “coordinated, sovereign, human-centred AI on Cyprus’s own terms, or piecemeal adoption of foreign platforms that gradually lock the country into other people’s economic and governance models”. It commits to Cyprus “controlling all critical layers, including sovereign compute, governed access to high-value data, core skills, and national AI assurance”.
The interface layer belongs on that list. It is the layer through which every citizen interaction passes, where the transcript of that interaction is generated, and where the tone, language and cultural register of the state’s relationship with its citizens is set. A conversational interface that can only run as a foreign-hosted service creates a dependency at precisely the point of highest sensitivity, and constrains the data-residency and audit guarantees the Strategy commits to elsewhere.
This is not a hypothetical concern. The established providers of multimodal and avatar-based conversational interfaces are, to our knowledge, almost entirely non-EU: Synthesia (United Kingdom), HeyGen (United States), D-ID (Israel), DeepBrain AI (South Korea) and UneeQ (United States). We are not aware of a major EU-headquartered provider in this category. Where a capability category has no European supply, adopting it without a sovereignty requirement produces exactly the dependency the Strategy warns against, and does so silently, because the dependency is created at procurement rather than announced as a policy choice.
The corollary is that a sovereignty requirement in this layer is also an industrial policy instrument. It creates addressable demand for European and Cypriot suppliers in a category where European capability is currently thin, which is consistent with the Strategy’s stated ambition to move Cyprus “from consumer to creator of AI solutions”.
Requiring deployability within national infrastructure does not require Cyprus to build the technology itself, and is consistent with the Strategy’s partnership model. It requires only that the procurement specification permit it, which is a question of how the requirement is written and is therefore appropriate to settle at strategy stage.
This provision would also align the shared services layer with the G-Cloud programme described in Annex C, which is intended to “provide a fully governed, hybrid cloud foundation, expand the AI compute capacity, and establish governed sandboxes”.
COMMENT 6: ADD A GLOSSARY DEFINITION FOR MULTIMODAL CONVERSATIONAL INTERFACES
SECTION REFERENCE
Annex G (Glossary of Key Terms).
COMMENT / SUGGESTION
We suggest the Glossary include an entry along the following lines:
“Multimodal Conversational Interface. An AI system that interacts with a person through more than one channel, such as speech, visual presence, gesture or text, rather than through text alone. Such systems are commonly referred to as conversational avatars or digital humans. They are used to improve accessibility and comprehension for users with limited digital literacy, visual or motor impairments, or limited proficiency in the interface language, and are subject to the transparency obligations applicable to AI systems that interact directly with natural persons.”
JUSTIFICATION
The Strategy refers to conversational AI, multilingual assistants and digital concierges in several places without defining what interaction modalities those terms encompass. The Glossary states that its purpose is to “support consistent understanding and interpretation of the Strategy”. A definition would resolve an ambiguity that will otherwise be resolved differently by each implementing body.
Including the common commercial terminology in the definition, while keeping the operative term capability-based, allows the Strategy to remain technology-neutral in its requirements while ensuring that implementers, procurement officers and suppliers interpret those requirements consistently. Terminology in this field is not yet settled, and a national definition reduces the risk of divergent interpretation across the sixteen transformation projects and the Institutional AI Strategies due in March 2027.
PROPOSED CONTRIBUTION FROM RAVATAR
RAVATAR is a Cyprus-registered technology company developing multi-sensory digital human systems: AI interfaces that see, hear, speak and express in real time, deployable across web, mobile, kiosks and life-sized holographic displays. The company holds copyright in the RAVATAR AI Avatar Platform and the Genesis AI Avatar Studio, both developed and owned in Cyprus, and supports both cloud and fully on-premise deployment with no data egress.
The technology is deployed in operational environments today. Reference deployments include an AI financial advisor at the Luxembourg House of Financial Technology, the country’s national fintech hub; three interactive AI hosts handling approximately 1,200 unscripted interactions with 2,500 participants at the PwC Tax Leadership Conference 2025; holographic deployments with Capgemini at VivaTech Paris and with AMD at GITEX Dubai; a hyper-realistic avatar of Nobel Laureate Sir Konstantin Novoselov developed with Constructor University, Bremen; and a holographic avatar of Howard Carter in ongoing visitor operation at a museum in Egypt. The company reported EUR 440,000 in revenue in 2025 and is currently a Stage 2 applicant to the European Innovation Council Accelerator.
We note these deployments not as commercial references but because they bear on the questions raised above: the accessibility, transparency and sovereign-deployment measures we propose are drawn from operational experience of running such systems in regulated and public-facing settings, including in an EU Member State.
Should it be useful to the National AI Taskforce or to the bodies established under the Strategy, we would be willing to contribute practical experience in:
– Multimodal and embodied conversational interface design
– Multilingual real-time voice and video interaction
– Accessibility evaluation for older and low-digital-literacy users
– Transparency and disclosure design for synthetic-persona systems
– On-premise and sovereign deployment of conversational AI
– Interface-layer requirements for public sector procurement
Any participation should take place through transparent, competitive and outcome-based mechanisms. We would equally welcome the opportunity to contribute to the development of a national disclosure standard under Comment 2 on a non-commercial basis, including where the resulting standard applies to our own product category.
CONCLUSION
The Strategy’s treatment of conversational AI as reusable national infrastructure is, in our view, one of its strongest design decisions. Our comments do not seek to alter that architecture. They seek to ensure that the interface layer built on top of it is usable by the citizens the Strategy names as priorities, and governed by rules Cyprus writes for itself.
Specifying modality is a small edit at strategy stage. It becomes a substantially more expensive correction once reference architectures are published and the first six transformational procurements are underway.
We thank the National AI Taskforce and the Deputy Ministry of Research, Innovation and Digital Policy for the opportunity to contribute.
Ruslan Synytskyy
Chief Executive Officer
Cyber Leo Limited (RAVATAR)
Limassol, Cyprus
Article / paragraph:
Goal 6, Ensuring secure, sovereign and interoperable data and infrastructure, and Section 3.3 on national compute
Comment / Suggestion:
Rather than attempt to fund a national GPU cluster on the domestic budget alone, Cyprus should pursue an EuroHPC AI Factory Antenna, in partnership with the nearest hosting AI Factory in Athens, and use the Antenna as the shared compute layer for Cypriot academia, startups and public bodies. Access should be gated through a voucher system managed alongside the AdoptAI scheme, with reserved capacity for regulated workloads that require EU data residency, in particular health, legal and public sector use cases.
Justification:
Cyprus is a EuroHPC Joint Undertaking participating state. The AI Factories initiative, and the Antenna model for member states that do not host a full Factory, is the practical route by which a country of one million people can give its researchers and its startups access to frontier-scale training and fine-tuning compute without building a hyperscale data centre from scratch. The initial wave of AI Factories has been selected and the Antenna model was created precisely for the situation Cyprus is in.
An Antenna gives Cyprus three things at once. It gives startups and universities real access to serious compute, on terms set inside the EU, without asking the domestic budget to carry the full capital cost. It creates an operational relationship with the Athens Factory, which is culturally and linguistically the easiest partner for Cyprus to work with day to day. And it gives the Strategy a credible answer to the sovereignty question, because the compute sits under EU governance and inside EU data residency rules, rather than under a US or Gulf cloud provider whose terms can change unilaterally.
This suggestion complements, rather than replaces, the point raised by Theo on the environmental limits of large domestic data centres. Sharing an EuroHPC-anchored Antenna, rather than each ministry or company building its own, is the lower-footprint answer to the same problem. It also matches the collaborative posture of the Strategy, which explicitly names EU-level partnerships as one of the routes to national capability.
To make the compute reach the intended users, the access model matters as much as the hardware. A voucher scheme run through the AdoptAI budget, with reserved slots for public sector and regulated workloads, keeps the compute from being fully consumed by whichever few well-connected teams learn to book it first. A published quarterly report of who used how much compute, for what class of workload, would keep the scheme honest.
Samuel Adu-Berekorang
https://www.linkedin.com/in/samueladuberekorangx/
Article / paragraph:
Section 2.5.3, Objective 3, and the AdoptAI voucher scheme.
Comment / Suggestion:
Make the AdoptAI voucher explicitly cover annual subscriptions to EU-resident vertical AI software, not only consulting engagements and one-off pilot projects.
Justification:
Most Cypriot SMEs will not benefit from a consultancy pilot. What they need is a working tool they can log into on Monday morning. If the voucher only pays for advice or bespoke development, the money will flow to a small number of consultancies and the SME will be left with a slide deck and no operational tool once the engagement ends.
If the voucher also covers annual subscriptions to EU-based vertical AI software, the SME gets something it can actually use, the money stays inside the EU tax base, and Cypriot and EU AI vendors get a fair chance to win work that would otherwise default to US SaaS by inertia. The scheme should require the vendor to be established in an EU member state and to host data inside the EU, which keeps it aligned with the sovereignty goals set out elsewhere in the Strategy.
Samuel Adu-Berekorang
https://linkedin.com/in/samueladuberekorangx/
Article / paragraph: Section 1.3, Priority Sectors for Leadership, and Annex C
Comment / Suggestion: Add Sustainability and Climate Compliance as a ninth priority sector, alongside Shipping, Tourism, Financial Services and the others already listed.
Justification: The compliance wave is no longer a future scenario. CBAM entered its definitive regime on 1 January 2026 and is now live for Cypriot importers of cement, iron and steel, aluminium, fertilisers, hydrogen and electricity above the de minimis threshold. CSRD Wave 1 companies are already filing for FY2025 under the revised timeline set by Directive (EU) 2025/794, and listed SMEs are in scope from FY2028. The VSME voluntary standard is the template that banks and large buyers are pushing down the supply chain, which pulls unlisted Cypriot SMEs into reporting through customer contracts rather than through direct legal obligation.
Naming this as a priority sector does two things. First, it lets Cypriot AI vendors build vertical tools for a market that is guaranteed by EU law, which is the kind of defensible niche a small country should pursue. Second, it gives Cypriot SMEs a home-grown path to compliance in Greek, with local data, instead of routing the work through UK or German consultancies. Shipping is already named in the Strategy, and shipping is one of the sectors most exposed to the EU ETS extension to maritime and to CBAM through fuel and materials, so the new sector fits naturally next to what is already in the list.
Samuel Adu-Berekorang
Μια Εθνική Στρατηγική θα ήταν σκόπιμο να διατίθεται και στην ελληνική γλώσσα, ώστε να είναι πλήρως προσβάσιμη σε όλους τους εμπλεκόμενους φορείς και να διευκολύνεται η ευρύτερη κατανόηση και εφαρμογή της.
Παράλληλα, θα ήταν χρήσιμο να ετοιμαστεί και μια συνοπτική, περισσότερο οπτικοποιημένη έκδοση, με χρήση διαγραμμάτων, γραφικών και infographics, η οποία να παρουσιάζει με σαφή και εύληπτο τρόπο το όραμα, τους στρατηγικούς στόχους, τις βασικές δράσεις και το χρονοδιάγραμμα υλοποίησης της Στρατηγικής.
ΔΕΝ ΧΡΕΙΑΖΟΜΑΣΤΕ ΑΠΛΩΣ ΕΞΥΠΝΟ ΚΡΑΤΟΣ. ΧΡΕΙΑΖΟΜΑΣΤΕ ΕΝΑ ΚΡΑΤΟΣ ΠΟΥ, ΟΣΟ ΠΙΟ ΕΞΥΠΝΟ ΓΙΝΕΤΑΙ ΤΕΧΝΟΛΟΓΙΚΑ, ΤΟΣΟ ΠΙΟ ΑΝΘΡΩΠΙΝΟ ΓΙΝΕΤΑΙ ΑΠΕΝΑΝΤΙ ΣΤΟΝ ΠΟΛΙΤΗ.
Η ΤΕΧΝΟΛΟΓΙΑ ΜΠΟΡΕΙ ΝΑ ΜΕΙΩΣΕΙ ΤΗ ΓΡΑΦΕΙΟΚΡΑΤΙΑ, ΝΑ ΕΠΙΤΑΧΥΝΕΙ ΤΙΣ ΔΗΜΟΣΙΕΣ ΥΠΗΡΕΣΙΕΣ ΚΑΙ ΝΑ ΔΗΜΙΟΥΡΓΗΣΕΙ ΝΕΕΣ ΟΙΚΟΝΟΜΙΚΕΣ ΕΥΚΑΙΡΙΕΣ. ΔΕΝ ΠΡΕΠΕΙ, ΟΜΩΣ, ΝΑ ΔΗΜΙΟΥΡΓΗΣΕΙ ΕΝΑ ΚΡΑΤΟΣ ΣΤΟ ΟΠΟΙΟ ΕΝΑΣ ΠΟΛΙΤΗΣ ΘΑ ΛΑΜΒΑΝΕΙ ΜΙΑ ΑΡΝΗΤΙΚΗ ΑΠΟΦΑΣΗ ΑΠΟ ΕΝΑΝ ΑΛΓΟΡΙΘΜΟ ΧΩΡΙΣ ΝΑ ΓΝΩΡΙΖΕΙ ΤΟ ΓΙΑΤΙ ΚΑΙ ΧΩΡΙΣ ΝΑ ΜΠΟΡΕΙ ΝΑ ΜΙΛΗΣΕΙ ΜΕ ΑΝΘΡΩΠΟ.
ΓΙ’ ΑΥΤΟ ΕΙΣΗΓΟΥΜΑΙ ΤΗ ΘΕΣΜΟΘΕΤΗΣΗ ΕΝΟΣ ΧΑΡΤΗ ΔΙΚΑΙΩΜΑΤΩΝ ΤΟΥ ΠΟΛΙΤΗ ΑΠΕΝΑΝΤΙ ΣΤΗΝ ΤΕΧΝΗΤΗ ΝΟΗΜΟΣΥΝΗ.
ΚΑΘΕ ΠΟΛΙΤΗΣ ΠΡΕΠΕΙ ΝΑ ΕΧΕΙ ΔΙΚΑΙΩΜΑ ΕΝΗΜΕΡΩΣΗΣ, ΕΞΗΓΗΣΗΣ, ΑΝΘΡΩΠΙΝΗΣ ΕΠΑΝΕΞΕΤΑΣΗΣ ΚΑΙ ΠΡΟΣΦΥΓΗΣ. ΚΑΘΕ ΚΡΑΤΙΚΟ ΣΥΣΤΗΜΑ ΤΕΧΝΗΤΗΣ ΝΟΗΜΟΣΥΝΗΣ ΠΟΥ ΕΠΗΡΕΑΖΕΙ ΖΩΕΣ ΠΡΕΠΕΙ ΝΑ ΕΙΝΑΙ ΚΑΤΑΓΕΓΡΑΜΜΕΝΟ, ΕΛΕΓΧΟΜΕΝΟ ΚΑΙ ΔΗΜΟΣΙΑ ΥΠΟΛΟΓΟ.
ΔΕΝ ΠΡΕΠΕΙ ΝΑ ΕΠΙΛΕΞΟΥΜΕ ΑΝΑΜΕΣΑ ΣΤΗΝ ΤΕΧΝΟΛΟΓΙΚΗ ΠΡΟΟΔΟ ΚΑΙ ΣΤΗΝ ΑΝΘΡΩΠΙΝΗ ΑΞΙΟΠΡΕΠΕΙΑ.
Η ΤΕΧΝΗΤΗ ΝΟΗΜΟΣΥΝΗ ΠΡΕΠΕΙ ΝΑ ΥΠΗΡΕΤΕΙ ΤΟΝ ΠΟΛΙΤΗ — ΟΧΙ ΝΑ ΚΥΒΕΡΝΑ ΤΗ ΖΩΗ ΤΟΥ.
Προς κάθε ενδιαφερόμενο,
Διάβασα τη στρατηγική στο σύνολό της και, ενώ οι αρχές της είναι αξιοπρεπείς και η σύνταξή της επαγγελματική, έχω σοβαρές επιφυλάξεις — οι περισσότερες εκ των οποίων προκύπτουν από τις ίδιες τις σελίδες του κειμένου.
Οι κεντρικοί στόχοι δεν στέκουν μεταξύ τους. Ο στόχος υιοθέτησης ΤΝ 75% χρονολογείται το 2030 στη σελ. 51, το 2032 στη σελ. 61 και ξανά το 2030 στο κεντρικό γράφημα της σελ. 64 — με σημείο εκκίνησης που η ίδια η στρατηγική δηλώνει στο 9,3%. Φιλοδοξεί εργατικό δυναμικό «στην πρώτη δεκάδα της Ευρώπης» σε ψηφιακές δεξιότητες, μία μόλις σελίδα μετά την παραδοχή ότι βρισκόμαστε κάτω από τον ευρωπαϊκό μέσο όρο στις βασικές ψηφιακές δεξιότητες. Η «αύξηση του ΑΕΠ κατά 12%» (σελ. 6) εμφανίζεται μία φορά, χωρίς μοντέλο ή πηγή, και δεν ξαναεμφανίζεται πουθενά. Το βασικό στατιστικό στοιχείο του ναυτιλιακού πυλώνα παραπέμπει στη Wikipedia· η τεκμηρίωση του χρηματοοικονομικού πυλώνα βασίζεται σε διαφημιστικό υλικό προμηθευτών. Και σε 101 σελίδες δεν υπάρχει ούτε ένα ευρώ κόστους για κανένα πρόγραμμα, ταμείο ή θεσμό που δημιουργεί η στρατηγική — τα οφέλη ποσοτικοποιούνται με ακρίβεια δεκαδικού, το κόστος καθόλου. Χαρακτηριστικό είναι ότι το παράρτημα των δεικτών (KPIs) τιτλοφορείται «(δείγμα)» και επιτρέπει κάθε στόχος να «αναθεωρείται, να επεκτείνεται ή να αντικαθίσταται» χωρίς επίσημη αναθεώρηση της Στρατηγικής. Τα γυαλιστερά γραφήματα δεσμεύονται· τα ψιλά γράμματα αποδεσμεύουν.
Η μεγαλύτερη ανησυχία μου αφορά τον μηχανισμό. Η στρατηγική δημιουργεί περίπου δέκα νέα σώματα — Αρχή ΤΝ, συμβούλια, επιτροπές, παρατηρητήρια, κέντρα αριστείας — συν Λειτουργούς ΤΝ σε κάθε υπουργείο και ετήσιες υπουργικές στρατηγικές ΤΝ, χωρίς κανένα από αυτά να διαθέτει στελέχωση ή προϋπολογισμό. Όλα αυτά θα λειτουργήσουν από τη δημόσια υπηρεσία όπως πραγματικά υπάρχει, όχι όπως τη φαντάζεται το διάγραμμα: ένα σύστημα όπου καμία καριέρα δεν ζημιώθηκε ποτέ από χαμένη προθεσμία ή αποτυχημένο έργο, και όπου το μόνο παραδοτέο που ανταμείβεται αξιόπιστα είναι η παραγωγή εγγράφων. Το προβλέψιμο αποτέλεσμα είναι ακριβώς το «θέατρο ΤΝ» για το οποίο προειδοποιεί η ίδια η στρατηγική στη σελ. 4 — με μια Ομάδα Εργασίας να αξιολογεί μια στρατηγική που συνέταξε η ίδια.
Και εδώ θα ζητούσα μια στιγμή ειλικρίνειας για το ιστορικό μας. Πρόκειται για ένα κράτος που, σχεδόν μία δεκαετία μετά την έναρξη της διαδικασίας, αδυνατεί ακόμη να επιβάλει την αναλογία γάλακτος στο ίδιο του το εμβληματικό τυρί — το χαλλούμι, το πολυτιμότερο εξαγωγικό μας όνομα. Ένα κράτος του οποίου το Υπουργείο Άμυνας φιλοδοξεί να στήσει αμυντική βιομηχανία χωρίς εμφανή κατανόηση του πώς χρηματοδοτούνται και κλιμακώνονται τέτοιες επιχειρήσεις. Ένα κράτος που δαπάνησε 62 εκατομμύρια ευρώ σε «έξυπνες» στάσεις λεωφορείων τοποθετημένες ανάποδα — με συμπαγή κολόνα και παγκάκι να κρύβουν από τον επιβάτη τη θέα του λεωφορείου που έρχεται, λες και οδηγούμε στα δεξιά — σχεδιασμό που ο ίδιος ο Γενικός Ελεγκτής χαρακτήρισε «πρωτοφανή και απαράδεκτο» και τον οποίο το υπουργείο εξακολουθεί να υπερασπίζεται. Ένα κράτος του οποίου το εμβληματικό ενεργειακό έργο, το τερματικό ΥΦΑ στο Βασιλικό, κατέληξε με τερματισμό της σύμβασης του αναδόχου μετά από χρόνια καθυστερήσεων, εκατοντάδες εκατομμύρια δεσμευμένα, έρευνα της Ευρωπαϊκής Εισαγγελίας — και κανένα τερματικό. Το λέω όχι για να είμαι σκληρός αλλά για να είμαι ακριβής: μια κυβέρνηση, ως σώμα δημοσίων λειτουργών, με αυτό το ιστορικό, που προτείνει να διαχειριστεί εικονικούς ανθρώπινους διδύμους, μητρώα ΤΝ σε blockchain και εργαστήρια πιστοποίησης θεμελιωδών μοντέλων, δεν είναι φιλόδοξη — είναι μη σοβαρή. Το χάσμα ανάμεσα στο λεξιλόγιο της στρατηγικής και στην αποδεδειγμένη ανικανότητα του κράτους είναι το σημαντικότερο δεδομένο αυτού του εγγράφου, και πουθενά δεν αναγνωρίζεται μέσα σε αυτό.
Θα πρότεινα την αντίθετη φιλοδοξία, που συμπτωματικά είναι και η μόνη φθηνή. Το ελάχιστο όριο της Πράξης για την ΤΝ ορίζεται στις Βρυξέλλες· δεν μπορούμε να εξαιρεθούμε. Τα κράτη μέλη όμως αποφασίζουν πόσο βαριά θα την εφαρμόσουν, και η υπόλοιπη Ευρώπη προβλέψιμα θα την επιχρυσώσει σε έναν λαβύρινθο συμμόρφωσης. Η μία πραγματική ευκαιρία της Κύπρου είναι να γίνει η ελαφρύτερη και ταχύτερη δικαιοδοσία ΤΝ που επιτρέπει το ευρωπαϊκό δίκαιο: το υποχρεωτικό ελάχιστο, ούτε μία υποχρέωση παραπάνω, με δεσμευτικούς χρόνους απόκρισης από τις ρυθμιστικές μας αρχές. Αυτό απαιτεί από το κράτος να είναι καλό σε ένα μόνο πράγμα — την αυτοσυγκράτηση. Όλα τα υπόλοιπα πρέπει να φύγουν: τα «κυρίαρχα» κέντρα δεδομένων (το απομονωμένο δίκτυο και το κόστος ενέργειας τα αποκλείουν, και η σελ. 61 παραδέχεται ότι δεν υπάρχουν εγκαταστάσεις έτοιμες για ΤΝ), το ταμείο καινοτομίας που υπόσχεται «τρεις μονόκερους» από μια χώρα που δεν έχει παραγάγει κανέναν, και τα έξι μεγαλεπήβολα ερευνητικά προγράμματα — από δίκτυα 6G και κβαντικούς υπολογιστές μέχρι το διάστημα και την άμυνα — όταν η χώρα δαπανά για έρευνα λιγότερο από το 1% του ΑΕΠ της.
Αν παρ’ όλα αυτά τα υπουργεία πρέπει οπωσδήποτε να κάνουν κάτι, μια μισοσοβαρή ιδέα: να ανατεθεί σε ιδιωτικές εταιρείες να εντοπίσουν εξοικονομήσεις στη δημόσια διοίκηση, με αμοιβή αποκλειστικά ως ποσοστό επί των επαληθευμένων εξοικονομήσεων — χωρίς πάγια, χωρίς ημερήσιες χρεώσεις, χωρίς παραδοτέα σε PowerPoint. Θα ήταν η πρώτη πρωτοβουλία στην ιστορία της Δημοκρατίας όπου ο ανάδοχος, ο φορολογούμενος και η αλήθεια κάθονται όλοι στην ίδια πλευρά του τραπεζιού. Και θα παίρναμε επιτέλους εμπειρική απάντηση στο μεγάλο εθνικό ερώτημα: αν οι αναποτελεσματικότητές μας είναι τόσο τεράστιες ώστε αυτές οι εταιρείες να γίνουν οι πρώτοι μας μονόκεροι — ή τόσο δομικά προστατευμένες που ούτε το κίνητρο του κέρδους δεν μπορεί να τις ξεθάψει.
Με εκτίμηση, Ανδρέας
A gap is sitting underneath both Gate 3 and Gate 4. Both gates confirm that a system “meets performance and compliance expectations” and “continues to… deliver expected value.” What they don’t specify is HOW that match is checked: against what, exactly, and by what mechanism, before a citizen or business ever touches the output. As written, the verification is procedural – did the right assessments happen, were the right people signed off – rather than a check against an explicit, machine-readable statement of what the service actually commits to deliver. Procedural conformance and outcome conformance are different things, and a system can pass every approval gate in Annex B while still not delivering the specific experience that was promised at Stage 1.
Proposal:
Add an explicit requirement, at Control Gate 3 (Deployment Readiness), for an ex-ante, machine-checkable acceptance contract: a structured specification of the citizen-facing outcome the system commits to, written before development in a form that can be automatically checked against the delivered system, with backward traceability from the delivered experience to the originating specification. This is distinct from (and a precondition for) the compliance and ethics checks already required at Gate 2, and distinct from runtime admissibility control at Gate 4: it answers “did we build and verify the thing we said we’d build,” not “did we follow the right process” or “is this specific action allowed right now.”
I’ve published open research specifically on this problem – machine-checkable acceptance contracts as a governance mechanism for organizational and AI-mediated service specification, and the more general problem of verification mechanisms that check process conformance without checking ex-ante experience-layer acceptance:
– Machine-Checkable Acceptance Contracts for Organizational Design. https://doi.org/10.5281/zenodo.18946043
– Verification as Operator: Spectral Projection, Rank Deficiencies, and the Persistence of the Audit Society. https://doi.org/10.5281/zenodo.19778588
I’d welcome the chance to discuss whether this pattern – a specification-cascade acceptance contract, verified before deployment, sitting alongside (not replacing) the existing risk/ethics/compliance and runtime-admissibility layers – is something the Strategy’s implementation guidance could reference directly. Cyprus is well positioned to be an early, formal adopter of this kind of standard rather than a follower of it.
With regards,
Dmitry Zharnikov
spectralbranding.com
Recognise meaningful user choice, interoperability, portability and freedom from unjustified platform lock-in as elements of human-centred AI.
Where technically compatible, secure and lawful, users should be able to install, select, change and remove AI assistants and other AI-enabled services on devices and platforms they own or lawfully use. Choosing an alternative provider should not cause unjustified loss of functionality, discriminatory treatment or unreasonable barriers to transferring data and switching services.
This principle is especially important where a device manufacturer, operating-system provider or digital platform controls hardware access, interfaces, default settings, application distribution or data needed by competing AI services.
Cyprus should advocate at European level for effective competition enforcement, appropriate assessment of AI gateways and connected-device operating systems, interoperability with competing AI services, and protection against unjustified self-preferencing, restrictive bundling and defaults that prevent meaningful choice.
At national level, public procurement and government AI frameworks should favour open standards, documented interfaces, configurable defaults, data portability and avoidance of unnecessary single-vendor dependence. Relevant authorities should also provide a process for recording evidence of AI-related lock-in or discriminatory access and referring it to competent European authorities.
These principles should remain subject to proportionate cybersecurity, privacy, technical-integrity, accessibility, child-protection and legal requirements.
Justification: AI assistants and AI-enabled interfaces are becoming gateways through which citizens access information, digital services, connected devices and commercial platforms. A provider controlling the operating system, hardware interface or default assistant can therefore influence which services users can access and how competing services function.
Restrictions on installing alternatives, changing defaults, accessing necessary device functionality or transferring user data can create platform lock-in. They may reduce competition and innovation and prevent citizens from selecting services that better meet their language, accessibility, privacy or functional needs.
Protecting meaningful choice would give practical effect to the Strategy’s commitments to human agency, digital inclusion, interoperability and citizens’ rights. It would also support Cyprus’s objective of avoiding excessive dependence on external platforms and economic models.
The proposal does not require access to every AI service offered globally. It establishes the narrower principle that lawful and technically compatible alternatives should not be excluded through unjustified commercial or technical restrictions. This would strengthen individual autonomy, fair competition and national digital resilience.
Establish an Authoritative National Address and Premises Register as a foundational national reference dataset.
The Strategy should require machine-readable address data that extends beyond building-level postal addresses. Every separately addressable unit or premises should have a persistent unique identifier linked to its building, entrance or access point, floor where available, and official geographic location.
A designated public authority should own and steward the official register. Municipalities, planning and land authorities, postal operators, utilities and telecom providers should contribute relevant premises, service-point and connection records for controlled validation and reconciliation. Their operational or customer databases should not automatically become the official source of truth.
The National Intelligent Digital API Fabric should provide secure, controlled access to this reference data for authorised public bodies and, where legally appropriate, regulated private-sector participants.
The register should identify physical buildings, entrances and addressable units only. It should not become a centralised register of residents, occupants, owners, utility customers or telecom subscribers. Any link to personal or account-holder information should remain separately governed and permitted only for a lawful, necessary and clearly defined purpose.
Justification: A common unit-level premises identifier would reduce reliance on inconsistent free-text addresses and fragmented organisational databases. It would support emergency response, postal and courier delivery, utility services, municipal administration, planning, property processes and citizen-facing digital services.
Utility and telecom providers hold valuable and frequently updated service-point and premises records. With appropriate privacy, security and legal safeguards, these records can help the public authority identify duplicate, incomplete or conflicting address information.
The capability would strengthen Digital Citizen 2.0 and Digital Company 2.0 by enabling authorised services to refer reliably to the correct premises when location information is necessary, without unnecessarily centralising personal or occupancy data.
Without a common addressable-unit identifier, automated and AI-enabled workflows will continue to require manual verification and may cause delays, failed service delivery or incorrect record matching. Implementation should be measured through national coverage, duplicate and conflict rates, update times, API availability, adoption by public bodies and correction-request resolution times.
The Strategy provides a strong foundation for trusted and responsible AI adoption. As implementation moves from governance principles to operational systems, continuous governance and identity security should be defined more explicitly.
Sections 3.13.3, Security and Threat Management, and 3.3.2, Control Framework:
Comment / Suggestion
The Strategy should establish continuous operational governance and identity security for human users, systems, workloads, APIs and AI agents, including other non-human actors. Implementation requirements should include continuous policy and access evaluation, delegated authority, least-privilege controls, rapid revocation, monitoring for control drift and complete auditability(end-to-end) across the full AI lifecycle. These requirements should be formalised through a national continuous operational governance standard, ensuring that AI systems, APIs and agents remain within approved identity, access, policy and accountability boundaries from design through operation, modification and decommissioning.
Justification
The Strategy anticipates interconnected government APIs, shared data services and AI agents operating across sensitive and regulated environments. Although it addresses access controls, monitoring and lifecycle governance, it does not explicitly define how non-human systems and AI agents will be identified, authorised and continuously controlled. AI systems, integrations, permissions and agent capabilities may change after deployment. Initial approval and periodic review alone may therefore be insufficient. Continuous governance would help ensure that security, access and compliance controls remain enforced and evidenced while systems are operating.
Including this requirement would strengthen accountability, cybersecurity and public trust, while allowing detailed technical standards and reference architectures to be developed during implementation.
Best regards,
Petros Nearchou
http://www.linkedin.com/in/petros-nearchou
Reading through the National AI Strategy 2032, the vision for making Cyprus a tech hub is clear, but there is a major elephant in the room: **AI isn’t just software. It runs on physical data centers that consume massive amounts of electricity and water.**
For an island like Cyprus, this is a huge risk if we don’t get the ground rules right from day one. We operate on an isolated grid, we face chronic water shortages, we deal with summer peak blackouts, and we have to decommission of conventional generation by 2029. Meanwhile, every spring we literally throw away clean solar energy because our grid can’t absorb it. Allowing unconstrained data center growth in this environment without strict boundaries will cause real problems for our basic infrastructure.
Here are the critical gaps in the current draft and what needs to be added:
### The Big Loopholes in the Strategy
1. **The “Where Feasible” Cop-Out**
The current draft talks about green energy using soft language like *”where feasible”*. In the real world, “where feasible” means optional. Private operators will always choose whatever is cheapest for their bottom line, pushing the burden of grid instability and water consumption onto the public.
2. **The Sovereign Procurement Loophole**
If we don’t enforce strict rules across *all* projects—including state-backed or “sovereign” builds—private developers will exploit it. They will build resource-heavy facilities under the excuse of “helping the government fulfill its capacity needs,” monopolize our power and water, and then sell that expensive compute back to the state for private profit.
### Non-Negotiable Rules to Add to the Strategy
If we are going to host compute infrastructure in Cyprus, the strategy must lay down clear, binding rules for **any** new facility (private, public, or public-private):
* **No “Sovereign” Exemptions:** The exact same environmental and grid rules must apply to every facility. No developer gets a free pass under the banner of “national strategic interest.”
* **Total Ban on Drinking Water for Cooling:** No evaporative cooling towers using municipal drinking water or groundwater. Cooling must be zero-potable-water—using closed-loop liquid cooling or coastal seawater heat exchange.
* **Mandatory On-Site Batteries (BESS):** Any facility over 1 MW must install battery storage and integrate with the TSO to act as a grid-support asset, helping feed power back during summer peak hours.
* **Real Green Energy & Smart Scheduling:** Replace “where feasible” with mandatory 100% renewable Power Purchase Agreements (PPAs). Force heavy, non-urgent AI workloads to run *only* during spring solar overproduction windows when we would otherwise dump excess clean energy.
* **Cap On-Island Compute to Inference Only:** Cyprus does not need power-hungry mega-factories for training massive base AI models. We should restrict local builds to efficient edge data centers for low-latency local services and government data, while offloading heavy AI model training to EU EuroHPC supercomputers abroad.
Placing these practical guardrails directly into the 2032 Strategy will give serious investors regulatory certainty while ensuring digital transformation doesn’t come at the expense of our power grid and water supply.
**Article / Sections:**
3.9.2 — Human Oversight and Accountability
3.9.5 — Responsible Deployment and Monitoring
3.9.6 — AI Social Contract Principles
Annex B — AI Use Case Lifecycle and Control Gates, particularly Control Gate 4
**Comment / Proposal**
The proposed National AI Strategy provides a strong and important foundation for positioning Cyprus as a trusted, sovereign and responsible AI jurisdiction.
Its principle that people must remain in control is correct. However, human control should not necessarily mean that a person must manually approve every routine AI-generated action.
Continuous human approval can become a bottleneck in speed, scale and consistency, while still remaining vulnerable to fatigue, overload and delayed intervention.
A stronger operational model is:
**Human-governed admissible boundaries, with machine-speed autonomy inside those boundaries.**
Accountable people and institutions should define the objectives, authority, operating context, protected consequences and conditions under which an AI system may act. The AI may then operate autonomously within that predefined space.
Where a proposed transition is unauthorised, unsupported, contextually invalid or outside the permitted boundary, it should be denied, held or escalated before reaching external consequence.
I therefore propose adding an explicit:
**Operational Pre-Consequence Admissibility Gate**
For high-impact, citizen-facing, regulated and critical-infrastructure AI applications, each material AI-originated transition should be independently evaluated at the latest trustworthy point before it affects a protected digital or physical system.
The control should:
* operate independently of the acting AI;
* verify authority, context and admissibility;
* prevent inadmissible transitions from reaching the protected consequence;
* bind the decision to the actual execution route;
* verify whether the intended consequence occurred or remained absent;
* produce tamper-evident and independently inspectable evidence;
* permit normal machine-speed operation within approved bounds;
* escalate only those exceptions requiring human judgement.
**Justification**
The Strategy already establishes strong lifecycle controls covering assessment, development, deployment readiness and periodic operational assurance.
These controls are necessary, but they do not explicitly require a live admissibility decision immediately before each material external consequence.
This distinction becomes increasingly important for autonomous and agentic AI systems capable of generating novel actions, combinations and operating states at machine speed.
Human oversight should therefore govern the boundary, remain responsible for its authorised modification and retain the ability to review, contest and override outcomes—without making continuous human approval the routine execution mechanism.
Cyprus should consider establishing a national technical testbed for pre-consequence AI control, beginning in shadow mode on a bounded public-sector or critical-infrastructure workflow.
NEST is a Cyprus-developed pre-consequence architecture from Bounded System Technology Ltd. Its public proof pack demonstrates an inadmissible transition being denied before backend consequence, together with signed and independently verifiable evidence.
I propose that NEST be considered for independent technical evaluation—not as a replacement for legal, institutional or human governance, but as a candidate mechanism for making human-governed operating boundaries technically enforceable.
This would allow Cyprus to test a practical interpretation of the Strategy’s central principle:
**People govern the boundary. AI operates at machine speed within it. Inadmissible consequences do not pass.**
Bounded System Technology Ltd – Cyprus
3.3.1.7 National AI Skills Observatory / Government AI Accelerator
1.3 Priority Sectors for Leadership
After carefully reviewing the document, I would like to propose reconsidering the institutional model of the AI Accelerator.
Rather than positioning the AI Accelerator as part of the Government Innovation Hub, I recommend establishing it as a separate, public, open, and independent national initiative. While the Government Innovation Hub should remain focused on public sector innovation and digital transformation, the AI Accelerator should serve a broader mission of advancing AI adoption, innovation, research, and commercialization across the entire national ecosystem.
Such a model would encourage broader participation and make it easier to attract leading AI talent through permanent positions, fixed-term contracts, fellowships, secondments, and project-based engagements. It would also strengthen collaboration between government, academia, startups, industry, investors, and international partners, creating a sustainable environment for AI innovation.
As part of the AI Accelerator, I recommend establishing an Open AI Institute to act as the national centre of excellence for artificial intelligence. The Institute would consolidate expertise, best practices, reusable AI assets, validated solutions, implementation guidance, and lessons learned into a shared national resource that could be leveraged by public institutions, businesses, researchers, and innovators. This would reduce duplication, accelerate AI adoption, and improve the quality and consistency of AI implementations across sectors.
1.3 Priority Sectors for Leadership / Entrepreneurship and Innovation
In addition, the AI Accelerator should include a dedicated unit responsible for developing the national AI innovation ecosystem. Its mandate should include supporting AI startups and scale-ups, facilitating public-private partnerships, attracting investment and talent, promoting international collaboration, and enabling the development and export of AI-enabled products and services.
An open and independent AI Accelerator would complement the Government Innovation Hub rather than duplicate its role, while creating a stronger foundation for innovation, economic growth, and the country’s long-term competitiveness in artificial intelligence.
Best regards,
Roman Medvedev
https://www.linkedin.com/in/romavm/
Beyond education, the government’s e‑consultation document presents a clear and confident direction for Cyprus’s National AI Strategy. It treats AI as a practical capability that the country must adopt with intention and discipline. The strategy explains why AI matters, where Cyprus can lead, and how the country can build sovereign capability while staying aligned with European standards.
The vision of Cyprus becoming a trusted AI hub in the Eastern Mediterranean is ambitious but believable. The document places strong emphasis on human‑centred design, responsible governance and transparent systems. These elements are essential for public trust, and they are woven throughout the strategy rather than mentioned as afterthoughts. The focus on sectors such as finance, tourism, shipping, healthcare and legal services shows a good understanding of where AI can deliver real economic value.
The strategy is honest about the gaps Cyprus faces. It highlights fragmented data, limited compute capacity and a shortage of specialised talent. What stands out is the way the document moves directly from problem to solution. It proposes national compute infrastructure, unified data governance, AI Officers in ministries, Centres of Excellence and national testbeds for validation. This gives the strategy a practical and grounded tone.
The implementation plan is structured and measurable. It sets out timelines, milestones and KPIs that make the strategy accountable. The expected outcomes are ambitious but realistic. Higher productivity, GDP uplift, more AI professionals and modernised sectors are all achievable if the plan is executed with consistency.
Overall, the document is thoughtful, practical and forward‑looking. It shows that Cyprus is approaching AI with seriousness and strategic intent. It deserves strong support.
Schools and Learning Cultures in Cyprus – response to AI
Cypriot schools have several strengths that give the system genuine potential for transformation. Educators demonstrate strong commitment to learners, and schools maintain warm, relational environments where students feel known, supported and connected. This relational quality is a cultural advantage: Cypriot learners tend to be expressive, social and engaged, which creates fertile ground for a learning culture built on curiosity, dialogue and shared meaning. The national appetite for modernisation, visible in digital initiatives, curriculum updates and professional development, shows that Cyprus is willing to evolve and align with European expectations for contemporary schooling.
These strengths form a solid foundation for a learning ecosystem where attention, agency and intellectual presence can flourish. Many schools are already experimenting with project-based learning, modernisation approaches and digital tools, signalling an early shift toward more participatory learning. There is also growing recognition that education must prepare students not only for examinations but for confident participation in a rapidly changing world. This awareness is an important cultural shift: it opens the door for schools to cultivate discernment, critical thinking and humane participation as core educational outcomes.
Signalling this trajectory, Cyprus now needs to move from individual initiatives to systemic coherence. Schools require a shared understanding of what a strong learning culture looks like: environments where students practise discernment, think with depth, collaborate meaningfully and engage with learning as a humane, relational process. This means aligning curriculum, pedagogy, assessment and school culture so that students experience learning as a coherent journey rather than a series of disconnected tasks. When these elements reinforce one another, learning becomes intentional rather than mechanical.
A second priority is leadership capacity. School leaders should be supported to shape culture, not only manage operations. Leadership development programmes can help principals and senior teams design intentional learning environments, steward change with clarity and build staff cultures that are reflective, collaborative and intellectually purposeful. When leaders understand learning culture deeply, reform becomes sustainable rather than compliance-driven.
Finally, Cyprus would benefit from a national framework that helps schools embed AI and digital tools in ways that strengthen human presence rather than replace it. Technology should support teachers in designing learning moments that are connected, thoughtful and alive – moments where students learn to think well, act with awareness and participate confidently in their world. AI becomes most powerful when it amplifies human discernment, not when it accelerates performance pressure.
Cyprus has the relational foundations, the cultural strengths and the willingness to modernise. With coherent learning cultures, intentional leadership and human-centred use of technology, the country can build an education system that is not only competitive but deeply humane – one where students grow into thoughtful, capable participants in their society.
Best regards,
Tassos Anastasiades